Open, and taking cases in · 9am–5:30pm, weekdays In a hurry? Call 0800 6890668
CDR Cardiff Data Recovery 0800 6890668 Book it in
CDR / Common faults / Ransomware encryption

Ransomware has hit you

Ransomware data recovery in Cardiff. Rushed encryption leaves gaps; we pay no ransom.

Encrypting a whole network before morning means working fast, and fast work is sloppy work. That is our opening. A shadow copy the script walked past. A snapshot still sitting on the NAS. Originals deleted but not yet overwritten, waiting in free space. Large files locked in patches. Cases come to us from Cardiff, Newport and the valleys — and we deal with your data only, never with the people who encrypted it.

No files back, no fee on most jobs One fixed price, after a free diagnosis It comes to us by post from Barry, Pontypridd or Newport

Describe the symptoms to an engineer
0800 6890668

What each ransomware symptom is telling you.

Not listed here? Try the triage →
Warning signsWhat has gone wrongDo this now
Every file has picked up a new ending — .akira, or a random string issued just to youThe encryption finished. Qilin hands each victim its own extensionPhotograph it, then pull the power
akira_readme.txt in every folder you openAkira's ransom note. Other crews drop powerranges.txt or fn.txtLeave them exactly where they are
README-RECOVER-.txtQilin once more — your extension goes into the note's nameKeep every copy
RECOVER--FILES.txtThat naming belongs to BlackCat/ALPHVEvidence. Hold on to it
A demand where your wallpaper used to beIt sends you to a Tor address to start talkingGet a photo of the screen first
No shadow copies survive, and the log shows vssadmin delete shadowsThe restore points were wiped so Windows cannot roll backHelpful, oddly — it shows us where to look
Posting it to us: post it tracked and fully insured to the intake lab, and the journey back is on us; ring first if you would like an engineer to check how it is packed before you seal the box. Every stage is set out on the posting guide.

The crews hitting UK networks in 2025–26.

QilinThe most active crew of 2025, with more than a thousand victims listed publicly. Synnovis was one — NHS pathology across London stopped in June 2024. Nothing free will open it.
AkiraCISA and the FBI issued a joint advisory in November 2025 naming it a current threat. The one build anyone has cracked is 2023's — everything released since has held.
After LockBitThe NCA led the February 2024 operation that broke LockBit apart and returned keys to a number of victims. Whoever filled the gap since has been operating on a smaller scale.
Free keys, honestlyIf a real free tool has been released, No More Ransom will have it. For Akira as it stands there is none, and none for INC, RansomHub, Medusa or Qilin either. The “universal decryptors” on sale online are not tools and not keys.

From the parcel to your files coming back.

Cases we have logged →
01

A case number, and a diagnosis at no cost Free

The diagnosis costs you nothing. Every item that arrives is logged under a case number of its own, and an engineer works out what has actually failed — then tells you plainly which files can come back and which cannot. The price follows that: one fixed figure, in writing, and no work begins until you have read it and said go ahead.

Diagnosis at no chargeOne fixed figure in writingNothing owed yet
02

Off the network, and left as found

The first move is isolation: any infected machine comes off the network. Then every drive is copied end to end, free space included, since untouched originals are often still in there. Nothing is tidied away, either. Ransom notes, swapped wallpaper, lock screens: all of it belongs in the case file.

Forensic image of every diskUnallocated space included
03

Pull back what survived

A lot of strains never encrypt the file where it sits. They read it, write a locked duplicate and delete the first — and a deletion only takes away the pointer. Until something new needs that space, the original is still on the disk, and patient carving lifts it out intact. We chase the rest as well: shadow copies the run missed, NAS snapshots, big files it only part-locked, and a genuine decryptor if one exists for your strain.

Originals carved from free spaceYour strain matched against known keys
04

Fresh disks, and a paper trail

None of it returns to hardware the attack reached. Files come back on media bought new for the job, with a written account of the work solid enough for an insurer or the ICO.

Back on media bought newWritten up for the ICO
05

You approve it, then it goes back

Nothing is billed while you are still deciding. A complete listing of what came off the drive reaches you first, and the invoice only follows your yes. Files travel back on media bought new for the job, return postage ours, and we do not close it here until every one of them opens on the machine you will use.

The file list is yours to approveBack on media bought newThe postage back is on us

What we usually find first

  • vssadmin delete shadows /all /quiet — hardly a strain leaves this one out, and it clears the restore points Windows had put aside. Find it in a log and we have a fair idea whose script did this, and where else is worth a look.
  • Copy, lock, delete leaves leftovers — the original is unlinked rather than erased, and it waits in free space until the disk needs the room. Carving normally brings it back intact.
  • Speed costs them completeness — in a rush a strain locks only sections of a large file, and the sections it skipped usually open as normal.
  • The law is catching up — a July 2025 Government proposal would stop public bodies paying at all, and critical national infrastructure with them. Private firms may well follow; nobody is guessing about the direction.

Most victims now refuse: of the organisations Sophos surveyed in June 2025, 97% saw their data come back, and 49% of them had paid. Coveware logged its lowest payment rate yet in Q3 2025 — 23%. The British Library, facing a demand near £600,000 in 2023, turned it down and rebuilt from nothing. Money buys no certainty, and it was never the sole route through — only the route being sold to you.

Mid-attack? Ring these

  • Report Fraud (formerly Action Fraud) — cyber crime is reported to 0300 123 2040, and while an incident is in progress somebody answers it whatever the hour.
  • NCSC — report it to the National Cyber Security Centre as well, and work through its ransomware guidance step by step instead of jumping ahead.
  • ICO, within 72 hours — where personal data was probably caught up, the UK GDPR clock starts the moment you become aware and expires three days later. Do not leave it.
  • No More Ransomnomoreransom.org has Europol behind it, and a real free decryptor is only ever published there. Look there before you trust anyone else's offer.

The data is our end of it: imaging the disks, getting back what can be got back, rebuilding on hardware we know is clean, and writing the job up in the form an insurer or the ICO expects. We open no channel to the people who did this, and we would advise nobody else to.

Straight out of the casebook.

CF · CDF-2026-0638LOGGED ✓

Ransomware overnight at a Monmouthshire builders' merchant

The ransomware never encrypted anything in place. It read each file, wrote a locked copy and deleted the original — so what mattered was still sitting in free space, and could be carved back out. A NAS snapshot nobody had thought of covered the rest. They were trading again inside the week, without paying a penny or answering the note.

Trading again inside a weekNothing went to anyone

Before you send it off.

Start with these

  • Take photos of every note and every locked screen
  • Isolate any infected machine from the network without shutting it down
  • Keep every log, and delete nothing
  • Ring Report Fraud, then the NCSC — and where personal data is involved, the ICO inside 72 hours

What to avoid

  • Contacting the attackers, bargaining with them, or paying
  • Restoring backups onto machines that have not been cleaned
  • Believing anyone selling a 'universal decryptor'
  • Restarting a locked NAS before it has been photographed

What we get asked, week in, week out.

What if we simply paid?

No — and we will not arrange it for you. Both UK policing and the ICO tell you not to. The money funds the next victim's attack, nobody is obliged to send a key that actually works, and the ICO has said plainly that paying counts for nothing when a breach is assessed. Sending money to criminals is not something we do.

What are the odds of getting files back anyway?

Often good, whole or in part. The sources we work from: backups you already hold, a shadow copy the attack failed to clear, snapshots kept on a NAS, deleted originals lying untouched in free space, and occasionally a legitimate free decryptor released for that exact build.

Is there a free tool for our strain?

Start at No More Ransom — Europol supports it, and its list is the honest one. Right now nothing works against Qilin, Medusa, RansomHub or INC, and nothing against current Akira or LockBit builds. If someone is charging you for a key to any of those, what they are actually selling is recovery work.

Who needs to be told?

Report Fraud takes it on 0300 123 2040 — the old Action Fraud number — and any business ought to loop in the NCSC too. Should personal data have gone with it, UK GDPR gives you 72 hours to notify the ICO.

An unplugged drive keeps whatever it still holds.

A failing drive has only so many starts left in it. Spend none of them. Keep the power off, and the free diagnosis will tell you what is still readable.

0800 6890668