Open, and the first look is free · 9am–5:30pm, Mon to Fri Quicker to ring: 0800 6890668
RDR Reading Data Recovery 0800 6890668 Get it quoted
RDR / By symptom / Encrypted in a ransomware incident

The job · a network encrypted overnight

Ransomware data recovery in Reading. Hurry is careless; files return from what it missed. No ransom is paid.

Ransomware that encrypts a whole network overnight is working in a hurry, and hurry is careless. That carelessness is what we work with: a snapshot left on the NAS, a shadow copy that was never reached, deleted originals still sitting in unallocated space, a big file encrypted only in patches. Take the infected machines off the network, leave them powered, photograph the screens and ring. Work comes to this bench from Reading, Newbury, Theale, Didcot, Basingstoke and Slough; a single machine is £300 + VAT, a server, RAID set or NAS starts at £500 + VAT, and the figure is agreed in writing first. The data is our end of it. Nobody here speaks to the attackers.

Nothing recovered? On most jobs, nothing to pay The diagnosis is free; then one fixed figure in writing Parcels arrive from Newbury, Woodley and Theale

An engineer answers, and looking is free
0800 6890668

Match the symptom to the fault.

Different fault? Begin at the triage →
What you noticeWhat is likely wrongWhat happens next
Every filename now carries a suffix — .akira, or a string of characters unique to youThe encryption finished. Qilin gives every business it hits a different extensionPhotograph it, then unplug the network cable
akira_readme.txt in folder after folderAkira's note. Others use fn.txt or powerranges.txtDo not open any of them
README-RECOVER-.txtQilin once more — the note takes its name from whatever extension has been appliedKeep every copy of it
RECOVER--FILES.txtThis is how BlackCat/ALPHV labels its notesThis is evidence — keep it
A demand where the desktop wallpaper used to beThe talking is meant to happen over a Tor linkTake a photo of the entire screen
No shadow copies left, and vssadmin delete shadows sitting in the logRollback is over — Windows has nothing left to restore fromOddly, that helps us; it says where to begin
Packing and posting: pad it so nothing can move, put a cover value on the parcel that reflects what the files are worth to you, and send it tracked to the intake lab. Return postage is ours. Ring first if you would rather an engineer talked the packing through before the box is sealed. It is all set out on the packing and postage page.

The ransomware groups hitting UK networks in 2025–26.

QilinOne of the most prolific groups of 2025, and its public list of the organisations it has hit runs well past a thousand. Synnovis was one of them, and pathology services across London NHS trusts stopped for a time in June 2024. No free key exists.
AkiraIn November 2025 CISA and the FBI jointly described it as an active threat. Two builds have been broken — the 2023 one by Avast's decryptor, and a Linux/ESXi variant by a researcher's GPU brute-force tool in March 2025; the builds in circulation now resist both.
LockBitAn operation the NCA led in February 2024 disrupted LockBit, and keys went back to a number of the businesses it had encrypted. It did not end the group: LockBit has since returned and is active again.
Free decryptors that are realGenuine free tools appear in one catalogue and one only: No More Ransom. The only Akira tool in it dates from 2023 and does not open files encrypted by the later builds. Qilin, INC, RansomHub and Medusa are absent from it altogether. What is being advertised online as a “universal decryptor” is a sales page, nothing more.

From your parcel to your files coming back.

Jobs we have closed →
01

Logged the day it lands, and the look costs nothing Free

A case number goes on your device the day it reaches us, and an engineer then finds the real fault — free, and before anything else happens. You are told plainly what will come back and what will not, with one fixed figure in writing beside it. Nothing chargeable starts until you have read that and said yes.

The look costs you nothingA fixed price, in writingStill nothing to pay
02

Taken off the network, then copied as-is

Anything infected comes off the network before it is touched at all. Then each disk is imaged in full, unallocated space and everything, because the originals it deleted are usually still down there. Nothing gets tidied away: ransom notes, the changed wallpaper, the demand screen — every bit of it goes into the case file.

Every disk given a forensic imageUnallocated space and all
03

Recover what is left behind

Most strains never encrypt in place. The file is read, an encrypted copy is written alongside it, and the source is deleted — which takes away the pointer and nothing else. Those bytes stay on the disk until another file claims the room, so carving them back out whole is routine work. The other routes are pushed just as hard: shadow copies the run overlooked, snapshots on the NAS, large files encrypted in patches, and a published decryptor where one exists for the strain in front of us.

The deleted originals, carved outChecked against published keys
04

Fresh media, and a written record

Nothing is returned to equipment the attack touched. Your files come home on media bought in for the job, together with a written record of the work that will stand up in front of an insurer or the ICO.

New media, bought for the jobA report the ICO can use
05

The list first, then the bill, then the files

You see the file list first, then decide. Nothing is invoiced until you have said yes, and on most jobs there is no fee at all if the data does not come back. What we pull off goes onto media bought in for your job, and the postage home is ours. The case stays open on the bench until you tell us the files open on your own machine.

Nothing billed until you say yesNew media, bought for the jobPostage home is on us

What goes wrong most often

  • vssadmin delete shadows /all /quiet — present in most of these jobs, and it takes away the restore points Windows had been keeping. Found in a log, that line usually identifies the script that ran and points at the other machines worth examining.
  • The read-encrypt-delete pattern leaves a trail — the original is unlinked, not erased, and it stays put until the disk needs that space for something else. Carving usually brings it back whole.
  • Haste leaves holes — pressed for time, a strain will encrypt a large file only in part, and whatever it skipped over opens as it always did.
  • The law is moving one way only — a Government proposal published in July 2025 would bar public bodies, and the operators of essential national services, from paying anything at all. Private firms are widely expected to be next. Nobody is betting on the rules loosening.

Most organisations now say no. Coveware measured the payment rate at about a fifth in late 2025, and it has fallen since. A June 2025 Sophos survey put recovery at 97% among the organisations it asked — and 49% of those had paid, which leaves the other half getting their data back without a payment. Roughly £600,000 was what the British Library was asked for in 2023. It declined, and did the rebuilding work itself. Nothing is guaranteed by paying. It is one route out of several, and the only one whoever encrypted your files has an interest in you choosing.

An attack under way? Ring these

  • Report Fraud (the service formerly called Action Fraud) — the cyber-crime line is 0300 123 2040, and it is answered outside office hours while an incident is still running.
  • NCSC — the National Cyber Security Centre will take a report too, and the ransomware guidance it publishes is worth working through in sequence rather than dipping into.
  • ICO, inside 72 hours — under UK GDPR the countdown opens at the point you become aware that personal records may be caught in it, not when your investigation finishes. Seventy-two hours later it has run out. Treat it as fixed.
  • No More Ransomnomoreransom.org. Europol runs it alongside the security industry, and where a working free tool exists for your strain, that catalogue is where it turns up. Look there before you believe anybody selling you one.

The data is our part of it: disks imaged, everything recoverable recovered, the results handed back on hardware known to be clean, and the work documented in the form an insurer or the ICO will expect. The first look is free, and the figure is fixed in writing before anything chargeable begins. We open no line to whoever did this, and we would advise you against it too.

How one of these actually went.

RG · RDG-2026-1788ON FILE ✓

A Theale builders' merchant, and ransomware overnight

Nothing had been encrypted in place. The software opened each file, wrote a scrambled copy beside it and deleted the original — which left the real accounts sitting in free space, ready to be carved back out. What that missed was still in a NAS snapshot nobody had looked at. The merchant was invoicing again inside a week, with no ransom paid and no reply sent.

Taking orders again before the week was outNot one thing handed over to anyone

What helps, and what makes it worse.

First things to do

  • Photograph every ransom note and every demand screen
  • Unplug the network, not the power — infected machines stay switched on
  • Hold on to every log; erase nothing
  • Report Fraud, then the NCSC; where personal records are involved the ICO gets 72 hours' notice

What makes it worse

  • Contacting the attackers, negotiating with them, or paying
  • Restoring a backup onto a machine that is still infected
  • Trusting anyone who sells a 'universal decryptor'
  • Powering an encrypted NAS back up before it has been photographed

Answers before you commit to anything.

Would it be easier just to pay?

No, and we do not broker on anyone's behalf either. Three reasons, in the order that matters: a payment buys no obligation, so the key you get back may be partial or simply broken; the money underwrites whoever gets encrypted next; and the ICO has said outright that having paid earns you nothing once it starts assessing the breach. Police guidance points the same way.

Realistically, how much comes back?

A great deal, often — whole files in some cases, parts of files in others. The routes are these, and a job normally uses several: a free tool, where one genuinely exists for that strain; the deleted originals, still lying in unallocated space; a snapshot the NAS kept; a shadow copy the encryption run missed; and, easiest of all, a backup already in your possession.

Is there a free decryptor for this strain?

Check No More Ransom first. Europol stands behind the project, and it lists only tools that do what they say. Nothing is published today for Qilin, INC, RansomHub or Medusa, nor for the LockBit and Akira builds in circulation now. So a paid “universal key” for any of those strains is recovery labour with somebody else's name on the invoice.

Who needs to be notified?

Three places, depending. Report Fraud — the renamed Action Fraud — is the one for cyber crime, on 0300 123 2040. A business should log it with the NCSC too. And where personal records were among the encrypted files, UK GDPR puts a 72-hour limit on telling the ICO, counted from the point you realise.

Nothing gets worse while it sits switched off.

You pay nothing for the look. What comes back is a list — the files that opened, the ones that did not, and one fixed figure to finish the job. Leave it switched off until you have that in writing.

0800 6890668