An illustrative case explaining the route

Recovering a project file server after the shares were encrypted

An engineering and contracting office running several projects at once. Drawings, bills of quantities, quotations and payment applications all live on a single network share, reached by engineers from the office and from project sites over VPN. The daily backup is written to an external disk that stays plugged into the same server.

Construction & contracting

What was affected

  • A Windows file server holding the project shares.
  • The external disk attached to it, carrying the daily backup.
  • Office workstations opening the same share.
  • An archived mailbox exported to a file on the share.

What had been tried before it reached us

  • Restarting the server several times hoping the share would return.
  • Installing antivirus onto the server itself and running a full scan.
  • Renaming some file extensions by hand to try to open them.
  • Attaching a second external disk to copy off whatever could be saved.

The route

  1. 01

    Isolation before any read

    The server was taken off the network, workstations were stopped from reaching the share, and the external disk was disconnected and treated as a source rather than a destination.

  2. 02

    An image before analysis

    Images were taken of both the server and the external disk, and everything afterwards ran on those images rather than the originals.

  3. 03

    Reading the note and the extension

    The ransom note, the file extension and the timestamp of the first encrypted file were examined, and an encrypted sample was compared with an original found on an engineer's laptop that had been offline.

  4. 04

    Looking for a route other than decryption

    Storage snapshots, version history, and the temporary files design software leaves behind while working were all examined.

  5. 05

    Recovery into a clean environment

    What could be recovered went to a separate medium, and nothing was returned to the server before it was rebuilt.

The outcome

What came back

  • Drawings for the active projects, from an older snapshot on the storage unit.
  • Contracts and quotations, from a cloud sync folder that was offline at the time.
  • Part of the bills of quantities, from temporary files left by the design software.

What did not

  • The exported mail archive: it sat on the same share with no snapshot of its own.
  • The daily backup: the disk was attached, so it was encrypted along with everything else.
  • Three weeks of supplier correspondence preceding the last snapshot.

What would have changed the outcome

  • A copy that is offline, or that day-to-day operational accounts cannot modify.
  • Separating project-site accounts from the office shares.
  • A real restore test before critical handover milestones, not merely a successful backup job.

Isolate the device and keep the ransom note.

Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.