Taking in new cases now · 9am–5:30pm, weekdays In a rush? Ring 0800 6890668
BHDR Birmingham Data Recovery 0800 6890668 Get it seen
BHDR / Faults we see / Files held to ransom

Ransomware has locked it

Ransomware recovery for Birmingham. Locked is not lost, and no ransom is paid.

An attack that has to lock a whole network overnight cuts corners, and those corners are where our work starts. Shadow copies the script never reached. Snapshots sitting on a NAS. Deleted originals still readable in unallocated space. Big files locked only in places. Jobs reach us from all over Birmingham and the West Midlands; we recover data, and we hold no conversation with whoever did it, for any client.

Nothing recovered, nothing to pay Diagnosed free, then one fixed price From Walsall, Dudley or Coventry, it travels by post

Tell an engineer what it is doing
0800 6890668

Reading the ransomware symptoms, one by one.

No match here? Run the triage →
SymptomsWhat is behind itWhat to do
Files now end in something they did not before — .akira, or a random string unique to your siteThe run has completed. Qilin issues a different extension to every victimTake a photo, then cut the power
akira_readme.txt sitting in each folderThat is Akira's note. Others leave powerranges.txt or fn.txtDo not move or delete them
README-RECOVER-.txtQilin again — the note takes the name of your extensionKeep the lot
RECOVER--FILES.txtBlackCat/ALPHV names its notes this wayThat is evidence. Keep it
Your desktop background swapped for a demandIt points you at a Tor address to open talksPhotograph that screen before you touch it
No shadow copies left, and vssadmin delete shadows in the logRestore points cleared so Windows cannot be wound backUseful. It tells us where to dig
Sending it by post: send it tracked and fully insured to our intake lab, and we cover the postage coming back; if you want the packing checked before it goes, an engineer will talk it through with you. Every step is written out on the posting page.

The names behind UK attacks in 2025–26.

QilinBusiest crew of 2025 — over a thousand victims named publicly. Synnovis was among them, and NHS pathology across London halted in June 2024. No free tool touches it.
AkiraAn advisory from CISA and the FBI in November 2025 flagged it as an immediate threat. Only the 2023 build has a free decryptor; nothing published since that has been broken.
What LockBit leftAn NCA-led takedown in February 2024 dismantled LockBit and handed keys back to some of its victims. The groups that moved into the space work on a smaller scale.
Free decryptors, plainlyWhere a genuine free tool exists, it will be on No More Ransom. There is none for Akira as it stands today, and nothing for INC, RansomHub, Medusa or Qilin. Those “universal decryptors” sold online are neither one thing nor the other.

From arrival to the files going home.

Recent jobs on record →
01

Case opened, and the diagnosis costs nothing Free

Every item gets a case number of its own the day it lands. An engineer then works out what has actually failed and tells you plainly which files have a real chance of coming back and which do not. Only then does a price follow: one figure, fixed, in writing, and it costs you nothing to see it. Nothing is charged until you say yes.

The diagnosis is freeOne price, put in writingNothing agreed
02

Off the network, nothing touched

Step one is unplugging: anything infected leaves the network. After that each drive is imaged end to end, unallocated space and all, because clean originals are often still lying in it. We clear nothing away either — the notes, the wallpaper and the lock screen all belong in the file.

Every disk imaged forensicallyUnallocated space read too
03

Lift out what remains

Plenty of strains do not encrypt in place. They copy the file, lock the copy and delete the first one — and deleting a file only removes the pointer to it. The data stays put until something writes over it, and careful carving brings it back whole. We also chase shadow copies the run skipped, snapshots on a NAS, big files locked only in parts, and any real decryptor for your variant.

Originals lifted from free spaceYour strain checked against keys
04

New disks, and a written record

Nothing goes back onto kit that was caught up in the incident. Your files arrive on media bought new, together with an account of the work detailed enough for an insurer or the ICO.

Your data on new mediaA write-up for the ICO
05

Approved by you, then posted back

No invoice is raised until the full list of recovered files has sat in front of you and you have said go ahead. Your data comes back on media we buy new, posted at our expense, and the job is not closed here until every file has opened on your own machine.

Your say-so on the file listYour data on new mediaWe cover the postage back

What the first look turns up

  • vssadmin delete shadows /all /quiet — practically no strain skips it, and it takes out the restore points Windows had been keeping. Spot that in a log and we know roughly whose script this is, and which other places are worth opening.
  • Copy, lock, delete leaves a hole — the first file is unlinked, not wiped, and it sits in unallocated space until the drive needs the room. Carving usually pulls it back whole.
  • Haste costs them coverage — under time pressure a strain locks only slices of a big file, and the slices it left alone tend to open fine.
  • The law is shifting — in July 2025 the Government set out plans to stop payments by public bodies, and by critical national infrastructure, altogether. Private firms may follow; the direction of travel is clear.

Saying no is now the normal answer: in June 2025 Sophos put recovery at 97% of encrypted organisations, with a ransom involved in 49% of those cases. Coveware's Q3 2025 number has payment down to 23%, its lowest ever. The British Library was asked for about £600,000 in 2023, refused, and rebuilt from the ground up. Paying guarantees nothing, and it has never been the only way out — only the loudest.

Still running? Who to call

  • Report Fraud (was Action Fraud) — cyber crime is reported nationally on 0300 123 2040, and the line is answered day and night while an incident is live.
  • NCSC — tell the National Cyber Security Centre too, and follow its published ransomware guidance in order rather than skipping ahead.
  • ICO, inside 72 hours — if personal data was likely swept up, the UK GDPR clock begins the moment you know and it runs out three days later. Do not sit on it.
  • No More Ransomnomoreransom.org is run with Europol's backing and is the only place a genuine free decryptor gets released. Check it before you believe anybody else's offer.

What we handle is the data: taking images of the disks, pulling back whatever can be pulled back, restoring onto hardware proven clean, and writing the whole thing up for an insurer or the ICO. Talking to the attackers is something we neither do nor advise.

Recent pages of the casebook.

BH · BHD-2026-8638RECORDED ✓

By morning a Worcestershire builders' merchant was locked

Not one file was encrypted where it sat. Each was copied, the copy locked, the original deleted — so what mattered still lay in free space, ready to carve back, and a NAS snapshot nobody had remembered covered the rest. They were trading again within the week, no ransom paid and no reply sent.

Running inside seven daysNothing paid to anyone

Before the parcel goes.

Do this first

  • Photograph every ransom note and each locked screen
  • Pull infected machines off the network but leave them switched on
  • Hold every log; delete nothing at all
  • Call Report Fraud, then the NCSC; if personal data is caught up in it, the ICO within 72 hours

What not to do

  • Opening a line to the attackers, haggling, or paying up
  • Putting backups back onto machines nobody has cleaned
  • Trusting a seller who offers a 'universal decryptor'
  • Rebooting a locked NAS before you have photographed it

The questions that come up every week.

Should we just pay them?

No, and we will not do it on your behalf. UK policing and the ICO both advise flatly against it. A payment bankrolls whoever gets hit next, obliges nobody to hand over a key that works, and the ICO has stated outright that it counts for nothing in how a breach is judged. Moving money to criminals is not a service we offer.

Can we get the data back without paying?

Frequently yes, in full or in part. What we work from: your own backups, any shadow copy the attack overlooked, snapshots held on a NAS, deleted originals still sitting in unallocated space, and now and then a real free decryptor published for that particular build.

Has anyone released a free key for this?

Check No More Ransom first — Europol backs it, and it is the honest list. As things stand there is no working tool for Qilin, Medusa, RansomHub or INC, nor for today's Akira and LockBit builds. Anyone selling you a key for one of those is selling something else.

Do we have to tell anyone?

Yes. The line for it is Report Fraud, once called Action Fraud, on 0300 123 2040; any business should also flag it to the NCSC. Where personal data was probably taken, UK GDPR gives you 72 hours to get a notification to the ICO.

Nothing more is lost while the power stays off.

Every extra power-up takes something off a drive that is already going. Leave it switched off and let the free diagnosis say what still reads.

0800 6890668