We are booking in new cases · Weekdays, 9am–5:30pm Urgent case? Call 0800 6890668
MHDR Maidenhead Data Recovery 0800 6890668 Send it in
MHDR / Common faults / Locked by ransomware

Loss caused by ransomware

Ransomware recovery, Maidenhead. There is nearly always more left than the note claims.

We recover from ransomware for Maidenhead businesses and households alike; we do not deal with the people who caused it, and that holds for every client. The work runs the other way from the ransom note: shadow copies the run missed, snapshots on a NAS, originals left behind in free space, and the corners these strains cut in order to encrypt a network before anyone notices. Encryption reaches a great deal, but rarely everything.

No fee unless the data comes back Diagnosis free, then a fixed quote Post it in from Windsor, Slough or anywhere else

Describe the fault to an engineer
0800 6890668

Ransomware notes and extensions, decoded.

None of these? Run the triage →
The signsThe likely causeStart here
Every filename has gained a new suffix: .akira, or a string generated for your network aloneThe encryption pass has finished; Qilin gives each victim its own extensionPhotograph it, then pull the power
akira_readme.txt left in every folderAkira's ransom note; other builds drop powerranges.txt or fn.txtLeave the notes where they are
README-RECOVER-.txtQilin's note, named after the extension your files were givenKeep every one
RECOVER--FILES.txtThe naming pattern used by BlackCat/ALPHVEvidence: hold on to it
The wallpaper replaced with a demand for moneyThe lock screen sends you to an address on TorPhotograph the screen before anything else
Shadow copies gone, with vssadmin delete shadows in the logsRestore points were wiped to stop you rolling Windows backHelpful: it narrows where we look
If you post it in: use a tracked, insured service addressed to our secure intake lab, and the return leg is paid at our end; if you would rather check the packing first, an engineer will go through it by phone. Each step is set out on the postage page.

The ransomware crews working UK networks in 2025–26.

QilinThe most prolific group of 2025, with more than a thousand named victims. Synnovis was one, and London's NHS pathology work stopped in June 2024 as a result. Nothing free decrypts it.
AkiraCISA and the FBI, in an advisory of November 2025, called it an immediate threat. The one free decryptor covers the 2023 build alone; every version released since remains unbroken.
After LockBit's fallThe NCA-led operation of February 2024 broke LockBit and returned keys to a number of earlier victims. What has filled the gap since operates at a smaller scale.
Free decryptors, honestlyIf a legitimate free tool exists, No More Ransom carries it. None does for Akira in its present form, and none for Medusa, Qilin, RansomHub or INC. The “universal decryptors” advertised online are neither free nor decryptors.

What happens between arrival and return.

The most recent cases →
01

Booked in, then assessed at no cost Free

Nothing becomes chargeable until you have said yes to it. Each item takes a case number of its own the moment it arrives, an engineer establishes what has actually failed, and you are given a candid view of which files stand a realistic chance of returning. The single quote that follows is fixed, written down, and costs nothing.

Diagnosis at no costOne fixed quote, in writingNothing signed
02

Isolate, and preserve everything

Infected machines come off the network before anything else happens. Every drive is then imaged in full, unallocated space included, since untouched originals frequently remain there. Nothing is tidied up: notes, wallpapers and lock screens are all part of the record.

A forensic image of every diskUnallocated space included
03

Recover what survived

Many strains work by duplication: the copy is encrypted and the original deleted, and a deleted file is only unreferenced, not removed. Until it is overwritten, patient carving lifts it back whole. Alongside that we look for shadow copies the run missed, snapshots on a NAS, large files encrypted only in sections, and any legitimate decryptor for your variant.

Deleted originals carved backYour variant checked for a key
04

Clean media, with a paper trail

Recovered files never return to hardware that was part of the incident. They come back on new media, with a written account thorough enough to put in front of an insurer or the ICO.

Returned on fresh mediaDocumentation for the ICO
05

Opened, verified, and sent home

Nothing is billed until you have seen the recovered file list in full and told us to go ahead. What comes back arrives on new media, with the return journey at our cost, and the case stays open at this end until you have opened every file yourself.

You approve the list firstReturned on fresh mediaThe return post is ours

What tends to show up first

  • vssadmin delete shadows /all /quiet — almost every strain opens with this, clearing the restore points Windows keeps for itself. Seeing it in a log tells us which playbook is in use and where else to start looking.
  • Copy, encrypt, delete leaves a gap — the original is unlinked rather than destroyed, and it waits in unallocated space until something claims it. Carving often returns it intact.
  • Speed forces compromises — a strain in a hurry encrypts large files in sections only, and the sections it skipped generally still open.
  • The rules are moving — in July 2025 the Government set out a ban on ransom payments by public bodies and critical national infrastructure. Whatever follows for private firms, the direction is not in doubt.

Refusal is now the majority position: Sophos reported in June 2025 that 97% of encrypted organisations got their data back, with a payment involved in 49% of cases. Coveware's Q3 2025 figure puts payment at 23%, the lowest it has recorded. The British Library, asked for roughly £600,000 in 2023, declined and rebuilt instead. Payment buys no certainty and is not the only road back; it is simply the most audible.

Under attack? Who to inform

  • Report Fraud (formerly Action Fraud) — the national reporting line for cyber crime is 0300 123 2040, staffed around the clock while an attack is still running.
  • NCSC — raise it with the National Cyber Security Centre as well, then work through the ransomware guidance it publishes, step by step.
  • ICO, within 72 hours — where personal data has plausibly been caught by the attack, the notification clock under UK GDPR starts immediately and stops at 72 hours.
  • No More Ransomnomoreransom.org is the Europol-supported archive, and the one place a legitimate free decryptor is published. Look there before trusting any other offer.

Our part is the data: imaging the drives, retrieving what can be retrieved, rebuilding onto hardware that is known to be clean, and documenting all of it for an insurer or the ICO. Negotiation with the people responsible is neither offered nor recommended.

From the casebook, lately.

MH · MHD-2026-6638ON RECORD ✓

A builders' merchant in Buckinghamshire, locked overnight

Nothing was encrypted where it lay. Each file was copied, the copy locked and the original deleted, so what mattered was still in free space waiting to be carved, and a NAS snapshot they had overlooked filled the gaps. Trading resumed inside the week, nothing paid and no one answered.

Running inside the weekNothing paid out at all

Before it comes to the lab.

Do these now

  • Take a photograph of each note and every lock screen first
  • Take infected machines off the network while leaving them powered
  • Keep every log, and delete nothing
  • Tell Report Fraud, then the NCSC; where personal data may be involved, the ICO inside 72 hours

Things best not done

  • Contacting the attackers, negotiating, or paying them
  • Restoring backups onto machines that were never cleaned
  • Believing anyone selling a 'universal decryptor'
  • Restarting a locked NAS before the screen is photographed

The questions that arise most often.

Is paying ever advisable?

No. British policing and the ICO are aligned on this: do not pay. The money underwrites the following attack, nothing about a payment obliges anyone to return your files, and the ICO has stated plainly that paying will not improve how a case is viewed. We do not process payments to attackers.

Can the files come back without a payment?

Often they can, whole or in part. The routes are backups, shadow copies the run failed to remove, NAS snapshots, originals left in free space by a strain that copies before it encrypts, and sometimes a genuine free decryptor for that build.

Could a free decryptor already exist for it?

Begin at No More Ransom, the genuine archive Europol supports. Nothing at present opens Qilin, Medusa, RansomHub, INC, or the current LockBit and Akira builds, so anyone advertising a key for those is selling recovery labour under another name.

Does it have to be reported?

Yes. Report Fraud, formerly Action Fraud, takes it on 0300 123 2040, and a business should raise it with the NCSC as well. If personal data has more likely than not left the building, UK GDPR allows 72 hours to notify the ICO.

Switched off, it keeps every chance it has.

Each further power-up asks more of a drive that has already begun to fail. Open the case first and let the free diagnosis tell you what is left.

0800 6890668