Data Recovery Case File · Ransomware & Encryption · The Backups in the Blast Radius
The ransomware reached the backups too: why connected copies share one blast radius — the honest limits against encryption stated plainly, and the recovery that ran beside it rather than through it
The report was one sentence with a business inside it. "Our server was infected with cryptolocker ransomware on Thursday, and they have encrypted all of the server files including the database we use — the NAS drive backups, and the external hard drive backups." Read that list again, because its shape is the lesson: the server, and the NAS backups, and the external backups — every copy the business kept, encrypted in the same event. That isn't bad luck compounding; it's a single architectural fact playing out: every copy was connected, so every copy was reachable. This page covers the blast-radius lesson properly, states the honest limits — what no laboratory can do against sound encryption without the key, said plainly as this archive always says it — and documents the productive work that remains: preservation, the vetted-decryptor check, and the recovery that runs beside the encryption, harvesting what the attack never touched.
| Media | Business server plus NAS backup device plus external backup drives — all encrypted in a single cryptolocker event, including the operational database |
| Reported situation | Ransomware infection on the server · encryption spread to all connected backup copies · database and file estate encrypted · recovery sought |
| Fault class | Ransomware encryption across the full connected estate — honest-limits case: encryption not breakable without the key; preservation, decryptor-check and beside-the-encryption recovery the legitimate roads |
| Equipment used | All devices imaged write-blocked with segmented hashing (Atola TaskForce 2) · vetted public-decryptor check for the identified strain · OSForensics carving of unallocated space and shadow remnants across the images · recovered-material verification; encrypted set preserved intact |
The decode: the blast radius, the honest limits, and the work beside them
Why the backups fell with the server: modern ransomware is built to do exactly what happened here — before or while encrypting, it enumerates everything the infected machine can reach: mapped drives, network shares, attached USB disks. A NAS mounted for nightly backups is, to the malware, just another writable share; an external drive left plugged in is just another letter. The backups weren't unlucky; they were connected, and connection is the whole criterion. This is the hard architectural lesson the incident teaches, and it's worth stating as doctrine: a backup that is always reachable from the machines it protects shares their blast radius, and will share their fate. Real resilience needs at least one copy that is offline or otherwise beyond reach — disconnected media rotated out, or versioned off-site storage the malware's credentials can't touch — precisely because the day it matters is the day everything reachable burns together.
The honest limits, stated as always: and now the sentence this archive publishes in every case of this genre, because it's true: properly implemented encryption cannot be broken without the key — by this laboratory or any other. No legitimate firm decrypts sound ransomware encryption on demand, and any outfit promising guaranteed decryption is either overcharging for a ransom negotiation or selling something that doesn't exist. What honesty leaves is still substantial, and it's the plan that ran here: preserve everything exactly as encrypted — because strains get broken, keys get seized and published, and a future decryptor is only useful against an intact encrypted estate; check the vetted public decryptors for the identified strain, since a meaningful number of families have free, legitimate cures already; and recover beside the encryption — because attacks are rarely as total as they look, and the drives' unallocated space, prior file versions, shadow remnants and pre-attack deletions often hold substantial material the encryption pass never touched.
The order of operations, for any business mid-incident: isolate first — infected machines off the network before anything else; preserve second — no wiping, no reinstalling, no "cleaning" the drives that now constitute both the evidence and the only possible substrate of future decryption; and only then recovery, on images, never originals.
On the bench
Every device — server drives, NAS members, external disks — was imaged write-blocked with segmented hashing on the Atola TaskForce 2, fixing the encrypted estate bit-for-bit as the attacker left it: the preservation on which any future decryptor depends. The strain was identified from its notes and artifacts and checked against the vetted public decryptors — the free-cure avenue this archive always runs first. And the beside-the-encryption harvest ran across the images in OSForensics: unallocated space carved for pre-attack file versions and remnants, shadow and prior-copy structures examined, the material the encryption pass never reached recovered and verified. The encrypted originals travelled to secure storage intact — a business's estate held ready for the day its strain is broken, alongside everything that never needed breaking at all.
The outcome
The estate preserved intact under hash, the decryptor avenue checked, and the recoverable-beside-the-encryption material carved, verified and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. The doctrine this incident writes in full: connected backups share the blast radius — the NAS and the external drives fell because they were reachable, and the copy that saves a business is the one nothing on the network can touch; encryption without the key is not breakable by anyone honest; and the legitimate work — preserve, check the cures, recover beside — is exactly what remains, done properly.
Ransomware got your files — and your backups too
Isolate the infected machines from the network first, and preserve everything: don't wipe, reinstall, or "clean" any drive — the encrypted data is both your evidence and the only substrate a future decryptor can work on, and strains do get broken. Be clear-eyed about promises: nobody legitimate can break sound encryption without the key, and guaranteed-decryption offers are ransom negotiation or fiction. The honest path is preservation under hash, a check of the vetted free decryptors for your strain, and recovery beside the encryption — unallocated space, shadow copies and prior versions often hold real material the attack never touched. Then rebuild the architecture around the lesson: one backup copy offline or beyond reach, always, because everything connected burns together.
Preserve first, promises never — call Edinburgh Data Recovery on 0131 202 0491; imaged under hash, decryptors checked, recovered beside the encryption — one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.