Data Recovery Case File · Honest Limits · The Ransom Refused

No payment, no pretence: a ransomware estate assessed on evidence — the strain examined, the reinstall's cost named, and everything recoverable brought back with the ledger open

His enquiry arrived two days after the discovery, angry and organised in equal measure. The scene: a home server "hacked — all my pictures, documents, videos and other files renamed to .gotcha files and encrypted. I tried renaming them back, but they don't open." The evidence, offered unprompted and invaluable: the attackers' note, plus a matched pair — one encrypted PDF and the same PDF unencrypted. The stance, in his own censored-for-print words: no backups, "but I do not want to pay those people." And the complication, reported with the same honesty: "I already reinstalled the server to make sure any malware is gone" — with the intrusion route self-diagnosed correctly as a remote-access convenience left open to the internet. This page honours the refusal, works the evidence, and prices the reinstall truthfully — because ransomware is the genre where honest limits matter most, and where anyone promising everything back is selling something.

SystemHome server — full personal estate (photos, documents, video) encrypted and renamed by an intruder; ransom note retained; no backups
Owner's actionsRename-back attempted (harmless, unsuccessful) · note and encrypted/original sample pair preserved — exemplary · server reinstalled and secured before recovery was considered — the costly step · payment refused on principle
Fault classCriminal encryption over a partially overwritten estate — outcome bounded by the strain's strength and the reinstall's writes
Equipment usedStrain identification from note and sample pair · decryption-feasibility analysis against known weaknesses · forensic imaging · remnant and prior-version recovery bounded by the reinstall · itemised ledger

The honest decode: where hope actually lives after ransomware — and what the reinstall spent

The refusal, endorsed first and without hedging: not paying is the right call — payment funds the next attack, buys no guarantee (decryption tools from criminals fail routinely), and marks the payer as someone who pays. His instinct gets this archive's full co-signature. Where recovery genuinely comes from, in order: first, the strain itself — ransomware families vary enormously in competence, and a subset carry implementation flaws or have had their keys recovered and published by researchers; identifying the exact strain is therefore the first real work, and his preserved note plus his matched encrypted/original pair are precisely the inputs that make identification and analysis possible — the pair especially, since comparing the same file in both states exposes how the encryption behaves. Preserving both was the single best thing anyone did in this case. Second, what the encryption never reached or the disks still remember — prior versions, shadow copies, deleted originals from before the attack, files the process missed: the archaeological layer that routinely yields real material. Which is where the reinstall gets its honest bill: wiping and reinstalling the server was an understandable security instinct and a recovery catastrophe in slow motion — the reinstall wrote across the very disks holding that archaeological layer, permanently claiming an unknowable share of the shadow copies and remnants that would otherwise have been this case's richest seam. The standing doctrine, printed in bold for the next reader: after ransomware, power down and image first; rebuild the system on new disks, never over the evidence. Security and recovery both matter — in that order they coexist; in his order, one paid for the other.

The recovery — evidence-led, bounded, and delivered with its ledger

The work ran in the honest sequence the genre demands. The strain was identified from the note and the sample pair, and its encryption analysed against the body of known weaknesses and published research — the assessment reported to him plainly before any figure was quoted: what the analysis supported, what it didn't, and what that meant file by file. The disks were forensically imaged as they now stood, and the archaeological layer worked to its post-reinstall boundary: surviving prior versions, unclaimed remnants, and untouched files recovered, catalogued, and verified — real material, honestly bounded by the territory the rebuild had spent. The delivery paired every recovered file with the document this genre owes its victims: an itemised ledger — recovered, partially recovered, beyond reach — with causes attached, so the estate's final shape was known rather than wondered about. And the report closed with the two referrals every such case deserves: the crime reported to the national fraud authorities with the preserved note as evidence, and the server's new security posture — his own hardening, reviewed and endorsed — standing between him and a sequel.

Outcome

A recovery measured in truth: the strain examined on real evidence, everything reachable brought back and verified, the losses named with their causes — and the refusal to pay vindicated as both principle and strategy. The filings, for the worst day this archive covers: preserve the note and a sample pair (his best move — it powers everything); never wipe or reinstall before imaging (his costliest — rebuild on new disks instead); attempt no DIY decryption or renaming beyond one harmless test; report the crime; and refuse the payment, always. And the prevention his intrusion route teaches: remote-access conveniences exposed to the internet are how home servers fall — close them, or gate them properly. The attackers encrypted everything and demanded tribute. They got a police report, a hardened server, and a victim who paid nothing — and lost, in the end, less than they'd counted on.

Ransomware on your files

Power the machine down and stop — do not pay, do not reinstall, do not run cleaners or decryptors over the disks; the recoverable layer lives in remnants and prior versions that every write destroys. Preserve the ransom note and, if you have one, any file that exists in both encrypted and original form — the pair is analytical gold. Image first, rebuild on new disks second, report the crime always. Then expect honesty: strain-dependent feasibility, an itemised ledger, and no promises that outrun the evidence.

Encrypted, extorted, and not paying?
Right answer — call Belfast Data Recovery on 028 9002 0144 before anything writes to those disks; bring the note and a sample pair.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

Call us — 028 9002 0144
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
028 9002 0144