An illustrative case explaining the route

Selling continued and stock stopped when the central server was encrypted

A small retail chain with several branches and an online store. Tills run locally in each branch and sync their transactions to a central server holding stock, orders and customer data. When the central server was encrypted, the tills kept selling — but with no correct balance and no link to online orders.

Retail & e-commerce

What was affected

  • The central server: stock, orders and customer data.
  • The online store database on the same server.
  • A folder holding product images and descriptions.
  • Daily reconciliation reports between branches.

What had been tried before it reached us

  • Carrying on selling for two full days without syncing, hoping for a quick fix.
  • Reinstalling the stock system onto the same server.
  • Downloading a decryption tool from a search result and running it directly on the server.

The route

  1. 01

    Stopping the sync first

    Branch syncing was halted immediately, because carrying on was writing new transactions over data that might still be recoverable.

  2. 02

    Separating the online store

    The store database was isolated from the affected server, and any path that could carry encryption to the hosting was cut.

  3. 03

    Looking where orders live, not at the server

    Orders leave a trace in more than one place: the store database, confirmation emails, payment gateway records, and courier exports.

  4. 04

    Rebuilding the balance rather than restoring it

    Stock was not restored from a copy but rebuilt from movements documented elsewhere, then compared against a physical count.

  5. 05

    Handover onto a clean medium

    Data was delivered into a new environment, and the old server was not brought back up.

The outcome

What came back

  • Orders and customer data from the online store database at the hosting provider.
  • Product images and descriptions from a cloud sync folder.
  • Branch transactions up to the last successful sync.

What did not

  • Stock balance for the two days of selling without sync — rebuilt approximately by manual count.
  • Branch reconciliation reports for the same period.
  • Part of the movement history for a rare line with no trace outside the server.

What would have changed the outcome

  • A written procedure: what branches do when the centre goes down, and when they stop selling.
  • Separating the online store database from the stock server.
  • A daily offline copy of the stock database specifically.

Isolate the device and keep the ransom note.

Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.