Data Recovery Case File · Security & Integrity · The Quarantined Drive
Don't plug it in — check it: verifying an external drive after a ransomware incident, and the write-blocked triage that answers the question safely
This enquiry asked for something this archive sees far too rarely, and it deserves its page for that alone. His workplace's server was hit by ransomware, and the IT response was appropriately ruthless: every laptop condemned — "even if the laptop itself hadn't yet been encrypted." His own machine fell in that category: never encrypted, but resident on the infected network, and at the time — his final week in the role — he'd been transferring his own files onto a personal external drive. Which left the drive holding a question mark he refused to resolve by gambling: were the transferred files corrupted? Could the drive be carrying the infection? "Please could I have a quote for someone to check my external hard drive for any issues, and recover the data if necessary." That instinct — verify before you connect — is the whole page.
| Situation | Workplace ransomware incident; blanket condemnation of network-attached machines · personal external drive last connected to an uninfected-but-networked laptop during file transfers |
| The request | Professional verification of the drive before any further use — infection check, integrity check, recovery only if needed |
| Service class | Write-blocked ransomware triage: encryption-signature scan, malware sweep, per-file integrity verification, clean-copy delivery |
| Equipment used | Atola Insight Forensic (write-blocked imaging) · encryption-artefact and entropy analysis · isolated malware scanning · verified extraction to fresh media |
Why IT condemned everything — and what checking a drive actually involves
The blanket condemnation first, because it deserves defending: modern ransomware doesn't stay where it lands — it moves laterally through a network, touching shares, planting itself on machines it hasn't yet encrypted, and often waiting; "not encrypted" therefore means "not encrypted yet," and an IT team writing off every network-resident machine is practising the only arithmetic that reliably ends an incident. The same logic reaches his drive: storage attached to a networked machine during an active incident inherits the question mark — it may carry infected executables copied unknowingly, files the malware touched or truncated mid-transfer, or nothing at all — and the one way to find out that risks nothing is the way he chose. The triage itself runs in an order built on a single principle: the drive is treated as hostile until proven otherwise, and nothing it holds executes anywhere. It is imaged first, write-blocked, on forensic equipment — the drive physically unable to be written to, its contents lifted as inert data; the image is then examined in isolation: an encryption-signature sweep (ransomware leaves unmistakable artefacts — renamed extensions, ransom notes, and the mathematical fingerprint of encrypted content, which is measurably distinguishable from ordinary files); a malware scan of every executable and document across multiple engines, offline; and a per-file integrity pass — documents parsed, archives opened, images rendered — catching the incident's quieter casualty class, files truncated or damaged when transfers met the emergency shutdown. The verdict that emerges is evidence, not reassurance.
The verdict — and the clean copy
His drive's examination returned the good version, itemised rather than assumed: no encryption artefacts anywhere — no renamed populations, no notes, no high-entropy signatures beyond ordinary compressed media; no active malware in the executable and document sweep; and the integrity pass confirming the transferred files opened and parsed cleanly, with a small handful from the final interrupted session flagged as truncated — the shutdown's honest fingerprint, listed by name so nothing failed silently later. Delivery followed the service's standing rule even on a clean verdict: the verified files went to him on fresh media as a clean copy, the original drive returned labelled for retirement-or-reformat rather than trust — because a drive that lived through an incident keeps its question mark in principle, and fresh media costs less than residual doubt. The report he received was written to be forwardable: findings, method, and the file-level ledger, suitable for his own records or anyone else's peace of mind.
Outcome
A clean bill of health, earned by evidence — and the doctrine his rare good instinct puts on the record for every future incident-adjacent drive owner. After any ransomware event, storage that touched the environment gets verified before it touches anything else: plugging an unchecked drive into a home machine to "see if the files are okay" is exactly how incidents get a second act, and the safe look is the write-blocked one. Interrupted transfers are the incident's quiet damage class — expect a truncated tail on whatever was moving when the plug was pulled, and want it itemised. And honour the ruthless IT response rather than resenting it: blanket condemnation is what competence looks like mid-incident. He asked the careful question in a week with every reason to cut corners. The careful answer cost one assessment — and nothing else, which was the entire point.
Drives that touched a ransomware incident
Don't plug them into anything — not to check, not "just quickly." Label the drive, note which machine it was attached to and when, and get a write-blocked verification: encryption sweep, malware scan, integrity check, clean copy out. Expect some truncated files from interrupted transfers and ask for them listed. Treat the original drive as retire-or-reformat regardless of verdict, and keep the report — a documented clean bill is worth having in every direction.
Verify before you connect — call Belfast Data Recovery on 028 9002 0144 for write-blocked triage and a clean copy.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.