Blog

Ransomware Hit: First 24 Hours and What Is Recoverable

How to Protect Your Data from Ransomware | TeraDrive

Ransomware turns every file into a locked box and leaves a note. The first day decides how much comes back. Most of what makes a case unrecoverable happens after the attack, not during it: machines wiped and reinstalled before anyone preserved evidence, backups overwritten by a well-meaning restore, a NAS reset to factory to get it working again. This guide is the order of operations we would follow, written for a small business, an office, or a home network with a NAS.

The first ten minutes
  1. Disconnect from the network. Unplug the cable, turn off Wi-Fi, and pull the NAS and any external drives off the network. Ransomware spreads, and it looks for backups.
  2. Power off anything still encrypting. A machine grinding through files with the disk light on is still doing damage. Pull the plug.
  3. Leave finished machines on but isolated if you have anyone doing forensics. Memory can hold the strain’s details and, on some older families, the key.
  4. Do not wipe, reinstall, or reset anything yet. Evidence and recoverable data live on those disks.
  5. Photograph the ransom note and write down the file extension the encrypted files now carry.

Identify what you are dealing with

The note, the new file extension, and one encrypted sample identify the family in most cases. Free identification services run by security researchers accept a sample and a note and tell you the name, whether a decryptor exists, and what the strain is known to do. Knowing the family answers the first question your insurer, your lawyer, and your recovery lab will ask.

What is recoverable, honestly

Where the data might still beHow often it worksNotes
Files the attack never reachedVery commonEncryption takes time and the attacker was interrupted, or skipped file types and folders
Offline or versioned backupsThe single best outcomeCloud backups with version history, rotated external drives, tape. Backups that were connected during the attack are usually encrypted too
NAS snapshotsCommon on Synology, QNAP, TrueNASOnly if the attacker did not get admin access and delete them. Do not reset the NAS
Volume shadow copies on WindowsOccasionallyMost modern strains delete them first. Worth checking, not worth counting on
Partially encrypted large filesCommon with fast strainsMany strains encrypt only the first part of large files to save time. Databases, virtual machines, video, and mailboxes can often be rebuilt
Deleted originalsSometimes on hard drives, rarely on SSDsSome strains copy, encrypt, then delete. The original blocks may still exist on a hard drive. On an SSD, TRIM usually erases them within hours
A published decryptorFor a minority of familiesOlder or poorly written strains have keys or flaws public. New strains rarely do
Fully encrypted files, modern strain, no backupNot recoverableThis is the honest answer, and it is the case for the portion of files that meet all three conditions

What a data recovery lab does

  1. Forensic imaging first. Every affected drive is imaged read-only before anything is attempted, so nothing done afterwards can lose more.
  2. Family identification from the note and samples, and a check for known decryptors and flaws.
  3. Carving the originals. On hard drives, deleted originals are recovered from the image where the strain deleted rather than overwrote.
  4. Rebuilding partially encrypted files. Database files, mailboxes, virtual disks, and media with only their headers encrypted are reconstructed from the intact remainder.
  5. Backup and snapshot recovery from NAS units and backup drives that were damaged, reset, or partly encrypted themselves.
  6. A written report of what was recovered and how, which insurers and privacy regulators ask for.

This is the work behind our ransomware data recovery service. Where the attack hit a server or NAS array, the RAID and server recovery process applies underneath it.

Mistakes that make it permanent

  • Restoring a backup over the encrypted drive before the drive was imaged. The backup may be incomplete, and the originals underneath are now gone.
  • Resetting a NAS to factory to get it back online. This deletes the snapshots that were the best recovery route.
  • Reinstalling Windows on the infected machine. It destroys the deleted originals and the evidence.
  • Running a decryptor from an untrusted source. Some are a second infection.
  • Reconnecting cleaned machines to a network that still has an infected one on it.

Reporting and insurance in Canada

Report the attack to the Canadian Centre for Cyber Security and to police through the RCMP’s cybercrime channels. If customer or employee personal information was on the affected systems, federal and BC privacy law may require you to notify the people affected and the relevant Privacy Commissioner. Cyber insurance policies require notice within days and usually dictate which vendors you can use, so read the policy before engaging anyone, including us.

After recovery: closing the door

  • Find how they got in before rebuilding. Remote desktop exposed to the internet, a reused password, and an unpatched VPN or NAS are the usual three.
  • Rebuild from clean installs, not from the images of infected machines.
  • Move backups offline or to versioned storage that the network cannot delete, and test a restore.
  • Turn on multi-factor authentication for every remote login, including the NAS admin account.

Frequently asked questions

Can data be recovered after a ransomware attack without paying?

Often, partly, and sometimes fully. Files the attack did not reach, backups that were offline or versioned, shadow copies that were not deleted, partially encrypted large files, and strains with a published decryptor are all recoverable. What cannot be recovered is a fully encrypted file from a modern strain with no decryptor and no backup. The free evaluation tells you which of those you have.

Should I turn the computer off?

If it is still encrypting, yes, pull the power to stop it. If encryption has finished, leave it on but disconnected from the network, because memory can hold evidence and sometimes keys. Either way, disconnect the network cable or Wi-Fi first.

Should I pay the ransom?

We do not negotiate or pay on anyone’s behalf, and we recommend against it. Payment funds the next attack, a working decryptor is not guaranteed, and paying often marks you as a repeat target. Exhaust the recovery routes first. Where a business decides to pay, that is a decision for its lawyers and insurer, not a recovery lab.

My NAS was hit. Is that different?

NAS units are a favourite target because they are reachable from the internet and hold everything. The good news is that many NAS file systems keep snapshots the attacker did not delete, and the drives themselves are often untouched below the file system. Power the NAS off, do not reset or reinitialize it, and bring the whole unit in.

Can you tell which ransomware it is?

Yes. The ransom note, the extension added to files, and a sample encrypted file identify the family in most cases. That tells us whether a decryptor exists, how the strain encrypts, and what it typically deletes, which shapes the recovery plan.

Do I need to report it?

In Canada, report it to the Canadian Centre for Cyber Security and to local police through the RCMP’s reporting channels. If you hold personal information about customers, privacy law may require notifying the affected people and the Privacy Commissioner. Your cyber insurer will require notice within a set time, so read the policy on day one.

Hit by ransomware?

Isolate, power down what is still encrypting, and call before anyone wipes or resets. Confidential evaluation of what can come back, no data no fee.

Ransomware RecoveryContact Us