An illustrative case explaining the route
Selling continued and stock stopped when the central server was encrypted
A small retail chain with several branches and an online store. Tills run locally in each branch and sync their transactions to a central server holding stock, orders and customer data. When the central server was encrypted, the tills kept selling — but with no correct balance and no link to online orders.
Retail & e-commerce
What was affected
- The central server: stock, orders and customer data.
- The online store database on the same server.
- A folder holding product images and descriptions.
- Daily reconciliation reports between branches.
What had been tried before it reached us
- Carrying on selling for two full days without syncing, hoping for a quick fix.
- Reinstalling the stock system onto the same server.
- Downloading a decryption tool from a search result and running it directly on the server.
The route
- 01
Stopping the sync first
Branch syncing was halted immediately, because carrying on was writing new transactions over data that might still be recoverable.
- 02
Separating the online store
The store database was isolated from the affected server, and any path that could carry encryption to the hosting was cut.
- 03
Looking where orders live, not at the server
Orders leave a trace in more than one place: the store database, confirmation emails, payment gateway records, and courier exports.
- 04
Rebuilding the balance rather than restoring it
Stock was not restored from a copy but rebuilt from movements documented elsewhere, then compared against a physical count.
- 05
Handover onto a clean medium
Data was delivered into a new environment, and the old server was not brought back up.
The outcome
What came back
- Orders and customer data from the online store database at the hosting provider.
- Product images and descriptions from a cloud sync folder.
- Branch transactions up to the last successful sync.
What did not
- Stock balance for the two days of selling without sync — rebuilt approximately by manual count.
- Branch reconciliation reports for the same period.
- Part of the movement history for a rare line with no trace outside the server.
What would have changed the outcome
- A written procedure: what branches do when the centre goes down, and when they stop selling.
- Separating the online store database from the stock server.
- A daily offline copy of the stock database specifically.
Next step
Start free assessmentIsolate the device and keep the ransom note.
Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.