Filenames ending in something nobody has seen before, and a text file in every directory explaining where to send money. The disks underneath are in perfect working order. What has changed is the content of the files, which has been put through a cipher held open by somebody else. That makes this a media job on healthy hardware, billed at £300 + VAT for a workstation disk and from £500 + VAT for an array. It is not investigation work and it never carries the investigation figure.
Looking at a drive hit by ransomware costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: £300 + VAT where one disk was caught, from £500 + VAT where an array was.
Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.
Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.
What most people see first. The documents are still where they were and roughly the size they were, with a suffix appended and a text file dropped alongside them. The hardware has nothing wrong with it. What changed is that the contents went through a cipher whose key sits with somebody else.
Read it, photograph it and keep a copy. Between the wording, the extension and the internal structure of one encrypted file, the strain can be identified, and the strain decides what is possible. Establishing which family this is comes first and it is part of the free examination.
Almost every family removes Windows shadow copies as its opening move, because that is the cheapest route back and they know it. A deleted snapshot has not been overwritten, only unlinked, and on a computer nobody has used since, what is left of it can often be carved back out of free space.
Plenty of strains encrypt the head of a file and leave the rest, purely for speed. On video, archives, databases and large documents that leaves a great deal of usable material sitting behind the encrypted opening, and rebuilding those files around it is among the most productive routes on this page.
Some attacks do not encrypt in place at all. They read the file, write an encrypted version alongside it and delete the original, which is an entirely different situation. Where nothing has since been written over them, those originals return by perfectly ordinary means, so working out which of the two patterns occurred comes early.
An external disk attached at the moment the attack ran is encrypted along with everything else, which is the whole argument against a permanently connected drive being a backup. It is recovered on the same terms as the machine, £300 + VAT for a single disk, and it is not investigation work.
A share mapped on an infected computer is treated exactly like a folder on its own disk, and units published straight onto the internet are hit in their own right besides. Where the compromised account could not delete snapshots, those live. NAS and array work opens at £500 + VAT.
Where the attacker reached the host rather than the machines on it, whole virtual disks are encrypted as single enormous files. That sometimes works in your favour, because a partially encrypted file that size may still hold long readable stretches, and the virtual disk can be rebuilt around them.
The instinct is to leave it alone until somebody who knows about computers can look at it, and that instinct is expensive. A run in progress is still working down the folder tree while everybody waits, so the correct action is the immediate one, taken by whoever is standing nearest.
Some strains work slowly, or wait until the backup rotation has turned over, so the discovery and the event are a long way apart. That makes the position harder, because the backups have cycled and the machine has been used since. It does not make it hopeless and it is worth assessing.
This happens often enough to warrant its own line. What the money buys is an undertaking, not working software, and more than one family hands over a tool that wrecks whatever it is aimed at. Where one has already run, stop there and tell us, since its output changes what is still retrievable.
For a number of older strains the keys were published, seized or the encryption was implemented badly enough to be defeated. That gets tested before anything else on every job, since where it holds the work turns short and inexpensive. It is not the usual outcome, and ruling it in or out is free.
A database file is held open and written to constantly, so an attack partway through leaves something that is neither whole nor entirely sealed. Logs from the engine, and earlier whole copies of the file lying in free space, are each worth pursuing, and one or the other regularly yields something that opens.
Backup software writing to a share or an attached disk loses its archives along with everything else. Copies kept on something unplugged between runs come through the whole event untouched, which is the argument for offline media in a single sentence, generally learned the expensive way.
Wiping and reinstalling to get somebody working again is understandable, and it removes a large share of the recoverable material at the same time. If the old disk is still in a drawer, leave it there and do not press it back into service. If it has already gone back to work, what survives depends on how long and how heavily.
Removing the malware unlocks nothing, and occasionally it takes with it the very component that was holding key material in memory. Where a scanner has been through the machine or quarantined anything, mention it, because it alters where there is any point looking.
Exposed remote access is the usual way in for the strains that target small firms, and knowing it was the route matters for putting things back safely. Establishing that properly is a separate forensic engagement at £800 + VAT with a report, and it is not part of the recovery.
One compromised account with wide rights reaches every server and every desk in the place, and that is what an overnight domain attack looks like the next morning. The hardware still sets the price: £300 + VAT per single disk, £500 + VAT and upwards per array, whatever the machine count comes to.
Files encrypted locally are synchronised to the service and overwrite the good copies held there. Most services keep version history for a period, and restoring from it is usually faster and cheaper than anything done on a bench. That gets checked before anybody is asked to pay for a recovery.
Two problems stacked. A copy is taken first, on the same terms any dying disk would get, and the sealed files are dealt with on that copy. The mechanical half is billed as physical work with half the figure up front, because mechanical failure is one of the four exclusions. Attack recovery on its own is not one of them.
Current groups copy first and encrypt second, which is why there are two threats rather than one: publish, and withhold. Pinning down what actually went out of the door is investigation work at £800 + VAT with a report, and it is a separate instruction from putting the files back.
An independent account of what happened is a standard requirement on a claim, and it is quoted as an investigation on its own terms. Retrieving the files is recovery, priced by the hardware. Two services, and they should not turn up on one invoice dressed as a single one.
The same problem at a domestic scale and it gets the same answer. One drive is £300 + VAT, the examination is free, and what comes back depends on the strain and on what has happened since. There is no cheaper category for households and no dearer one either.
A format wipes the index and leaves the contents lying where they were, sealed or not. Where the attack had deleted originals rather than encrypting in place, formatting over the top raises the difficulty without closing the door. Stop using that disk from now on.
There is a trade in companies who take a fee, pay the ransom on the customer's behalf without saying so, and present the result as their own engineering. It is worth knowing about in advance rather than discovering afterwards. Where a strain cannot be beaten, that is said here plainly and at no charge.
Where the machine lost power or was switched off partway through, a proportion of the files were never reached. Working out which ones is quick, and it regularly returns a substantial part of the data before any harder work is begun at all.
Working copies, autosave folders, print spools, thumbnail databases and application caches often sit in places the attack never visited. They rarely add up to everything. On a document-heavy machine they add up to a great deal more than most people would guess.
An offline copy that is three months stale still does most of the work, and the sensible instruction is then to go after what has changed since rather than the whole disk. That is a smaller job, and it is quoted as a smaller job rather than inflated into something nobody needs.
Some of what arrives is theatre: a note dropped on the desktop, a locked screen, files renamed and otherwise untouched. It is checked before anything else, because where that is what happened the files are simply there and the answer is short, cheap and rather satisfying.
When a current family has built its encryption properly, the key stays with the people who wrote it and no bench anywhere gets past that. Where that is the finding, it arrives during the free examination and costs nothing, rather than a fortnight and an invoice later.
The first decision is whether the process is still running, and the safe assumption is that it is. Cutting power stops it mid-file, which loses one document and saves the rest, whereas a clean shutdown gives it time to finish the job. After that, resist the urge to tidy up. Three habits do real damage in the hours afterwards. Reinstalling Windows to get a usable machine writes over the free space where the survivors are hiding. Antivirus and cleanup tools quarantine the encrypted files along with the malware, and quarantine is a folder people then empty. Decryptors downloaded from search results are, more often than not, either a second piece of malware or a program that mangles what it touches. Keep the note, photograph the screen, and set aside one encrypted file together with an untouched copy of the same document if such a thing exists anywhere — an old email attachment will do. That pair identifies the family faster than anything else, and the family determines whether there is a route back at all. Anything connected at the time comes too: the external drive on the desk, the members out of the array, the network box.
Nobody here attacks the cipher, because properly written encryption does not give way to effort or equipment. The work is finding what the attack skipped and repairing what it half-finished, and speed is the attacker's weakness. Encrypting terabytes properly takes longer than an intruder can afford, so many families process only the opening megabytes of each file, which leaves databases, video, archives and long documents readable behind a spoilt header and rebuildable. Others work by copying a file, encrypting the copy and deleting the original, and a deleted original on a spinning disk is exactly the job this trade has done for thirty years. Shadow copies are usually the first casualty, but deletion is not erasure and the remains turn up in free space on a machine that has been left switched off. Then there are the corners nothing reached: autosave folders, temporary directories, print spools, mail caches, the copy of the spreadsheet somebody had open on a laptop at home. And for a handful of older families the keys were published after arrests or after a flaw was found in the implementation, which turns a bad week into an afternoon. That check is free and it goes first.
Media pricing applies because the media is the problem. One workstation disk is £300 + VAT. A server, a NAS or any other array is from £500 + VAT and rises with how many members there are, since the volume has to be put back together before a single file can be examined. Examination is free, closes two working days after the equipment is logged in, and answers three questions: which family, whether snapshots or deleted originals survived, and whether there is a genuine route back. No fix, no fee applies here in the ordinary way — the exclusion list runs to electronic and mechanical failure, chip-level work, DVR jobs and forensic instructions, and none of those describes an encrypted file on a working disk. The second job is separate and legitimate: an organisation that has to tell a regulator, an insurer or a board how the intruder got in and what left the building beforehand needs an investigation with a written report, and that is £800 + VAT. It belongs on its own line. Recovery quoted at the investigation rate is a billing decision rather than a technical one.
Nothing on this bench attacks the cipher, because a correctly built one does not give way to effort or to money. What it does instead is find the material the attack never reached, rebuild the files it only half touched, recover the originals it deleted, and identify the strains where a genuine route back exists.
Wording, appended extension and the internal shape of one sealed sample are enough between them to name the family, and the family fixes the ceiling on the whole job. Published keys and weak implementations are found in the first hours rather than after a hopeful week.
Volume shadow copies the attack unlinked, snapshots on a NAS, snapshots the file system took for itself — all carved back out of free ground, provided nobody has used the machine since. Unlinking is not overwriting, and this route alone finishes a fair share of these jobs.
Where a strain sealed the first portion of each file and moved on, large documents, archives, databases and video are reconstructed around the encrypted opening. On a media-heavy machine that alone recovers a substantial share of what was lost.
Where the sealed version was written alongside and the original merely unlinked, standard file recovery gets the originals back. It is among the more rewarding routes on this bench, and it is the reason a machine should be stopped rather than left to run.
There is nothing useful to examine on a set that is still in pieces, so a sealed NAS or array goes back together from copies of its members before any of the routes above are tried at all. Multi-disk work runs from £500 + VAT upwards by member count.
Every device is imaged on write-blocked ports and all the work happens on the copies, on equipment kept off the network. That protects whatever survived, and it keeps the original intact in case a decryptor for that family is published later, which for some of them eventually happens.
The hardware sets this price, exactly as it does on any other media job. A single sealed disk out of a desk machine is £300 + VAT. A server, a NAS or an array opens at £500 + VAT and rises with the member count, because every disk is copied before the volume can be put back. It is not forensic work, it is never quoted at the investigation figure, and a firm that presents it as forensic should be asked why. Ransomware is not on the no fix, no fee exclusion list either; that list runs to electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and encrypted files sitting on healthy hardware are none of the four. Two working days after the device is logged in, the free examination closes, having named the strain, said whether snapshots or deleted originals came through, and said whether a genuine route back exists. Where there is none, that costs you nothing to find out. An organisation that also wants the route in traced, and an account of what was carried out, is asking for a second instruction: an investigation at £800 + VAT ending in a written report.
Power the machine down before anything else, at the socket if that is faster, and leave it down. Anything still encrypting is still eating files by the minute. After that: no reinstalling, no formatting, no decryptor bought from anyone, and nothing described as a cleaner pointed at the disk. Every one of those takes away material that would otherwise have come home. Take a photograph of the note and set aside one sealed file, with its original name if you can remember it. Those two together name the strain. Then send the storage: the bare drive out of a workstation, a laptop or a Mac rather than the machine itself; from a server or an array, a photograph of the chassis front and then the member disks alone with bay numbers written on them; a NAS travels whole with its drives still in it. Post it tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford, OX4 4GP, or bring it in, since Coventry to the door is about fifty-five miles down the M40 and takes roughly an hour. Drop-offs are taken Monday to Friday, 9:00am to 5:30pm. There is no counter in Coventry and nothing is collected. Ring 0800 689 0668 and say if the business has stopped, because that moves the job up the list.
Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.
Looking at it costs nothing, one written figure follows, and the band governing this page is £300 + VAT where one disk was caught, from £500 + VAT where an array was.