The lab is taking new cases · 9am–5:30pm, Mon–Fri In a hurry? Call 0800 6890668
SDR Southampton Data Recovery 0800 6890668 Open a case
SDR / How it broke / Ransomware incident

Cause of loss · ransomware

We restore. We don't bargain.

Ransomware scrambles every file it can touch and wrecks whatever would have saved you — then charges you to undo its own work. Our line does not move: we pull data from backups, surviving shadows, free space and the shortcuts these strains take, and we never pay, bargain with or contact attackers for anyone.

Most jobs: no data back, no charge Free diagnosis & quote in writing Postal intake across all of Hampshire

Speak to an engineer about it
0800 6890668

What those signs actually mean.

Not listed? Try the triage →
On screenWhat that tells youFirst step
Every file now carries an added extension (.akira, or a random one unique to you)The encryptor has already run — Qilin issues a fresh extension to each targetPhoto first, then unplug it
Every folder holds an akira_readme.txtThe Akira note — also seen as powerranges.txt or fn.txtKeep the notes in place
README-RECOVER-.txtThe Qilin note, named from the extension assigned to youRetain them all
RECOVER--FILES.txtNote format from the BlackCat/ALPHV lineIt's evidence, not junk
Your wallpaper swapped for a set of demandsExtortion styled as a lock screen, with a Tor addressCapture the screen, then restart
No shadow copies, and vssadmin delete shadows loggedThe intruder killed off Windows' restore points so you could not roll backIt points our search elsewhere
Sending it in: send your device by tracked, fully insured post to our secure intake lab — return postage is free — or ring us first and we'll talk you through packing it. Postage details sit on the contact page.

Strains hitting UK machines, 2025–26.

Qilin2025's busiest operation — more than a thousand victims named, among them Synnovis, whose June 2024 breach halted NHS pathology across London. Nothing free will decrypt it.
AkiraCISA and the FBI put out an advisory in November 2025 calling it an imminent threat. Only the 2023-era build has a free decryptor; nothing released since does.
After LockBitFebruary 2024 brought a takedown led by the NCA that ended LockBit's grip and released keys to some earlier victims — the groups that followed run on a smaller footing.
The truth about free decryptorsEvery genuine free tool sits on No More Ransom. Nothing there covers Qilin, Medusa, INC, RansomHub or today's Akira — and the paid “universal decryptors” pushed online are neither.

How the recovery runs, step by step.

Browse recent cases →
01

Logged in, checked at no cost Free

As soon as it lands with us, your device gets its own case number. An engineer works out the fault, says what can genuinely be pulled off, then puts one fixed price in writing — no charge for diagnosis, no obligation, and no chargeable work until you approve it.

No-cost diagnosisQuote fixed in writingNo commitment
02

Seal off, keep intact

Affected machines come off the network and are imaged end to end, free space included, since usable originals often sit there. Notes, wallpapers and lock screens are kept intact — they are evidence.

Whole-disk forensic imagesUnused space imaged as well
03

Chase what survived

Many strains duplicate a file, encrypt the copy and delete the original — stranding it in free space, where careful carving reaches it. We check surviving shadow copies, part-scrambled large files, NAS snapshots, and whether a genuine free decryptor exists for that strain.

Originals carved from free spaceStrain-specific decryptor check
04

Clean rebuild and paperwork

Whatever we get back goes onto fresh media, never onto the machines that were breached, and it arrives with paperwork you can put behind an ICO notification and an insurance claim.

Only onto fresh mediaDocumentation fit for the ICO
05

Checked, returned, signed off

You sign off a complete list of the recovered files first; only then does the recovery fee fall due. Everything returns on fresh media, postage paid, and the job stays open until you confirm the files open at your end.

Sign-off on the file listFresh media suppliedReturn postage on us

First checks on the bench

  • vssadmin delete shadows /all /quiet — nearly every strain opens with this, destroying the restore points Windows keeps. Spot it in the log and you know the playbook; we then look elsewhere.
  • Copy, encrypt, delete leaves survivors — when the encryption hits a duplicate and the source is deleted, that source lingers in free space, and patient carving pulls it out.
  • Partial encryption skips ground — strains built for speed scramble only sections of a large file, so what they stepped over can still be readable.
  • UK policy is shifting — the Government confirmed in July 2025 that it will outlaw ransom payments made by public bodies and critical national infrastructure. The direction is set.

What the numbers say about refusing: Sophos found in June 2025 that 97% of organisations whose files were encrypted did get their data back, though only 49% paid; in Coveware's caseload the share paying fell to a record low of 23% by Q3 2025. The British Library turned down a demand of roughly £600,000 in 2023 and rebuilt instead. Paying is neither necessary nor dependable — just the loudest button on the screen.

Under attack? Who to tell

  • Report Fraud (once Action Fraud) — 0300 123 2040, the UK's central line for cyber crime, answered day or night during a live attack.
  • NCSC — log the attack with the National Cyber Security Centre and work through its ransomware advice.
  • ICO, inside 72 hours — if personal data is probably at risk, UK GDPR demands notice without undue delay, and never beyond 72 hours.
  • No More Ransomnomoreransom.org, operated with Europol, is the one genuine home of free decryptors. Look there before you believe anyone else.

Where we come in: the data side — imaging, recovery, a clean rebuild, and the paperwork your insurer and ICO notification will want. We don't negotiate, and we'd never advise it.

Out of the casebook.

EX · SDR-2026-0638CONFIRMED ✓

Overnight encryption at a Hampshire builders' merchant

This variant duplicated each file, locked the duplicate and wiped what it had copied from — which left the real files sitting in free space, ready to carve, next to a NAS snapshot the intruder overlooked. The business was trading again within seven days. No ransom, no contact.

Back within the weekNothing handed over

While it's still with you.

Do

  • Get a photo of each note and lock screen before anything is moved
  • Get infected machines off the network — cable out, power left on
  • Save the logs and wipe nothing for now
  • Notify Report Fraud and the NCSC, plus the ICO inside 72 hours where personal data may be affected

Avoid

  • Paying, bargaining or messaging the criminals
  • Putting backups back onto systems that have not been cleaned
  • Trusting sites that sell 'universal decryptors'
  • Rebooting a locked NAS before its screen is photographed

Bench questions, straight answers.

Should the ransom be paid?

No. British law enforcement and the ICO both advise against paying: it bankrolls the next attack, buys no guarantee that your files return, and the ICO has stated openly that paying will not lessen your regulatory exposure. We will not help arrange a payment of any kind.

Can the encrypted files come back without paying?

Frequently, in part or in full — via backups, shadow copies that survived, originals abandoned in free space by copy-encrypt-delete variants, NAS snapshots, or a free decryptor if one truly exists for that variant.

Does my strain have a free decryptor?

Start with No More Ransom, the genuine repository operated alongside Europol. No decryptor exists for Qilin, Medusa, INC, RansomHub, or the current builds of Akira and LockBit; anyone offering one is selling you a recovery service rather than a key.

Am I obliged to report it?

A business should report it to Report Fraud (once Action Fraud, 0300 123 2040) and to the NCSC — and where personal data is probably exposed, tell the ICO inside 72 hours, as UK GDPR requires.

Whatever has gone wrong, keep it switched off.

Powering a damaged device up again costs you data. Start a case first; diagnosis is free whatever you decide.

0800 6890668