Open, and logging new jobs · weekdays, 9am–5:30pm Phone is quicker: 0800 6890668
HDR Hull Data Recovery 0800 6890668 Price it up
HDR / Faults we see / A ransomware attack

Your files are encrypted

Hull ransomware recovery. Rushed encryption leaves gaps, and the files come from them. No ransom is paid.

Locking a whole network overnight is a rush job, and rush jobs are untidy. That untidiness is where the files come from. A shadow copy the script never reached. A snapshot left on the NAS. Deleted originals still sitting in free space. A big file encrypted only in parts. Work reaches us from Hull, the East Riding and North Lincolnshire. We handle the data. We do not talk to whoever did this.

Most jobs: nothing back, nothing to pay Free to look at, then one fixed price Parcels come in from Beverley, Grimsby and Skegness

An engineer will take the details
0800 6890668

Putting a name to the symptom.

Nothing similar? Go to the triage →
The symptomsWhat the fault isWhat to try
Filenames now carry an extra ending: .akira, or a string of characters issued to you aloneEncryption ran to the end. Qilin issues a different extension per victimPhotograph it. Pull the network lead
akira_readme.txt sitting in every folderAkira's own note. Other crews use fn.txt or powerranges.txtLeave every one of them alone
README-RECOVER-.txtQilin again — the note is named after your extensionKeep them all
RECOVER--FILES.txtBlackCat/ALPHV names its notes that wayThat is evidence. Keep it
The desktop wallpaper replaced by a demandNegotiation is meant to happen over a Tor linkTake a picture of the screen
Shadow copies all gone, with vssadmin delete shadows in the logThat kills any rollback — Windows has nothing to restore fromUseful to us, oddly: it tells us where to start
Sending it to us: pack it well, insure it for the full value and send it tracked to the Leeds intake lab. Return postage is ours. If you want an engineer to look over the packing before you tape the box shut, ring first. The detail is in the sending page.

The ransomware crews attacking UK networks in 2025–26.

QilinNamed in more attacks than any other group in 2025, with a public victim list running past a thousand. Synnovis was one, and NHS pathology in London stopped in June 2024. No free key exists.
AkiraCISA and the FBI put out a joint advisory in November 2025 calling it a live threat. The 2023 build was broken, and in 2025 a researcher showed a 2024 Linux variant could be cracked by brute force — but there is no general decryptor for the builds in circulation.
Post-LockBitLockBit was broken up by an NCA-led operation in February 2024, which handed keys back to some victims. What has moved into the gap since works on a smaller scale.
The free decryptorsIf a free tool is genuine, No More Ransom will be carrying it. Nothing exists for Akira at the moment, nor for Qilin, Medusa, RansomHub or INC. Anything sold online as a “universal decryptor” is neither a tool nor a key.

From the box arriving to the files going back.

Jobs we have logged →
01

A case number first, then a free diagnosis Free

Each item that arrives gets a case number the day it lands. An engineer looks at it and finds the real fault, and that costs you nothing. You are told in plain terms which files can come off the drive and which cannot. A price follows — one figure, written down. No work starts until you have seen it and agreed to it.

The diagnosis is freeOne price, put in writingNothing to pay yet
02

Isolated first, then copied as found

Anything infected comes off the network before we touch it. Every disk is then imaged in full, free space and all, because the untouched originals are usually still sitting there. We tidy nothing up. Ransom notes, the changed wallpaper, the lock screen — that all goes in the case file.

A forensic image of each diskIncluding unallocated space
03

Lift out what is left

Most strains do not encrypt a file in place. They read it, write an encrypted copy alongside, then delete the source — and a delete takes away the pointer, nothing else. The bytes stay on the disk until something else claims the space, so carving them back out, whole, is ordinary work. The other routes get the same attention: shadow copies the run skipped, snapshots on the NAS, large files locked only in part, and a real decryptor where one exists for that strain.

Deleted originals carved outChecked against the published keys
04

New media, and a written record

Nothing goes back onto kit the attack touched. Your files return on media bought in for the job, with a write-up of the work that will stand up to an insurer or the ICO.

Copied onto new mediaA write-up for the ICO
05

You sign it off, then it comes back

You are not billed while you are still thinking. The list of what came off the drive goes to you first, and the invoice waits on your word. Files go home on media bought in for the job, with the postage back on us. We keep the job open until you have opened them on your own machine.

You approve the listing firstCopied onto new mediaReturn postage at our cost

What turns up most often

  • vssadmin delete shadows /all /quiet — you will find this in most attacks; it removes the restore points Windows was holding. Spot it in a log and we can usually tell which script was used, and which other machines are worth checking.
  • Read, encrypt, delete leaves a residue — the source file is unlinked, not wiped, and it stays in free space until the disk wants the room back. Carving usually returns it whole.
  • Haste leaves gaps — pushed for time, a strain will encrypt only part of a large file, and whatever it passed over opens as normal.
  • The rules are tightening — a Government proposal from July 2025 would bar public bodies from paying, and critical national infrastructure with them. Private business may be next. The direction of travel is not in doubt.

Refusing is now the norm: in the Sophos survey of June 2025, 97% of organisations got their data back, while 49% had paid to do it. Coveware recorded its lowest ever payment rate in Q3 2025, at 23%. The British Library was hit for close to £600,000 in 2023, would not pay, and rebuilt. Payment buys no guarantee, and it was never the only route out — just the one being offered by the people who locked you out.

Under attack? Ring these

  • Report Fraud (was Action Fraud) — the number for cyber crime is 0300 123 2040, and while an attack is live it is answered at any hour.
  • NCSC — the National Cyber Security Centre should get a report too, and its ransomware guidance is worth following in order, not in pieces.
  • ICO, inside 72 hours — the UK GDPR deadline runs from the moment you realise personal data may have gone, and three days later it is up. Do not sit on that one.
  • No More Ransomnomoreransom.org, backed by Europol, is the one place a genuine free decryptor ever appears. Look there before you believe any other offer.

Our part is the data: imaging the disks, recovering what can be recovered, putting it back on hardware known to be clean, and documenting the job the way an insurer or the ICO will want it. We do not open a line to the attackers, and we would tell you not to either.

One case from the casebook.

HU · HUL-2026-0638LOGGED ✓

A builders' merchant in North Lincolnshire, hit by ransomware overnight

Nothing was locked in place. Each file was read, a locked copy written, the original deleted — so the material that mattered still lay in free space, and could be carved out again. The rest sat in a NAS snapshot no one had thought to look at. The business was trading inside the week, with no money paid and the note left unanswered.

Trading again in under a weekNothing paid to anyone

Before you box it up.

Do these first

  • Photograph every ransom note and every locked screen
  • Disconnect anything infected from the network, and leave it powered on
  • Keep all the logs. Delete nothing
  • Report Fraud first, then the NCSC — and if personal data went with it, the ICO has to know inside 72 hours

What not to do

  • Getting in touch with the attackers, negotiating, or paying up
  • Restoring a backup to a machine that is still dirty
  • Trusting anyone who offers you a 'universal decryptor'
  • Powering a locked NAS back up before it is photographed

Asked most weeks, answered here.

Should we just pay it?

We say no, and we will not act as a go-between. Police guidance and the ICO both advise against it. A payment pays for the next attack on somebody else. No criminal is bound to hand over a working key. And the ICO has stated that paying will not count in your favour when a breach is assessed.

Realistically, how much of it comes back?

Often most of it, in full or in part. Five sources do the work: a backup you already hold; a shadow copy the script did not reach; a snapshot still sitting on the NAS; deleted originals lying in free space; and occasionally a genuine free decryptor published for that build.

Does a free decryptor exist for ours?

No More Ransom is the place to look. Europol is behind it and its list does not oversell. As things stand there is nothing for Qilin, Medusa, RansomHub or INC, and nothing for the current Akira or LockBit builds. Anyone charging you for a key to one of those is selling you recovery work under another name.

Who must be notified?

Cyber crime goes to Report Fraud on 0300 123 2040, which was Action Fraud until the rename. A business should tell the NCSC as well. If personal data was caught up in it, the UK GDPR deadline for telling the ICO is 72 hours.

A drive left switched off loses nothing more.

Leave it switched off. A failing drive has a limited number of starts in it, and each one spends a little more. The free diagnosis will say which files can be read.

0800 6890668