We're taking on new cases now · Weekdays, 9am–5:30pm Need it back quickly? Call 0800 6890668
MKDR Milton Keynes Data Recovery 0800 6890668 Get it diagnosed
MKDR / Common failures / Ransomware lockout

Cause of loss · ransomware

Ransomware data recovery, Milton Keynes. Get the files back. Pay them nothing.

Ransomware encrypts whatever it can reach. Then it hunts the fallbacks — backups, restore points — and invites you to buy your own work back. We go the other way: shadow copies it overlooked, originals abandoned in free space, snapshots, the shortcuts these strains take to stay fast. We don't pay, we don't negotiate, we don't open a channel to the gang. Not for any client.

No data back, no fee — most jobs Free diagnosis, one fixed quote Send it by post from anywhere in Buckinghamshire

Run the problem past an engineer
0800 6890668

What those symptoms actually mean.

No page for your town? Try the fault-finder →
On screenWhat's behind itFirst move
Filenames all end in something new — .akira, or a random string issued to your network aloneThe encryption run is over; Qilin issues a unique extension per victimPhotograph the screen, then pull the network cable
akira_readme.txt dropped into every folderThat's Akira's note — other builds leave powerranges.txt or fn.txtDon't move or delete the notes
README-RECOVER-.txtQilin's note; the name mirrors the extension you were givenSave all of them
RECOVER--FILES.txtHow the BlackCat/ALPHV strain names its notesThat's evidence — keep it
The desktop background swapped for a ransom messageThe lock screen now points you at a Tor addressSnap the screen before doing anything else
No shadow copies left — the logs show vssadmin delete shadowsRestore points were destroyed so you couldn't roll Windows backUseful — it narrows our search
Sending it by post: send it in on a tracked, insured service to our secure intake lab — the return postage is ours — or ring first and an engineer will talk you through packing it. Every posting step is set out on the enquiry page.

Who's hitting UK networks in 2025–26.

QilinThe busiest crew of 2025, with over a thousand victims named. One was Synnovis: its breach in June 2024 stopped NHS pathology work across London. No free decryptor exists.
AkiraCISA and the FBI flagged it as an immediate threat in a November 2025 advisory. The one free decryptor works on the 2023 build only; every later version remains uncracked.
After LockBit fellFebruary 2024's NCA-led operation crippled LockBit and released keys to some earlier victims. What has grown up in its place runs on a smaller scale.
Free decryptors: the truthWhere a genuine free tool exists, No More Ransom lists it. None exists for Akira as it now stands, nor for Qilin, RansomHub, Medusa or INC — and the “universal decryptors” touted online are neither.

How the recovery runs, stage by stage.

See the newest cases →
01

Logged in, checked at no charge Free

Every item gets its own case number on the day it lands here. An engineer traces the fault, gives you a plain assessment of what is realistically recoverable, and puts one fixed price in writing. The diagnosis is free, you are under no obligation, and chargeable work starts only when you say go.

No charge to diagnoseOne written quote, fixedNo commitment
02

Isolate first, keep every trace

Step one is isolation: anything infected comes off the network. Then every drive gets a full image, free space included — untouched originals frequently survive there. Notes, wallpapers, lock screens: nothing gets tidied away. That is your evidence.

Full forensic image of the driveUnused space imaged as well
03

Find what came through

A lot of strains copy before they lock: the duplicate gets encrypted, the original deleted. Deleted isn't gone — it sits in free space, and careful carving lifts it back. We also chase shadow copies the attack overlooked, NAS snapshots, large files scrambled in parts, and check whether a genuine free decryptor exists for your variant.

Binned originals carved outYour strain checked for a decryptor
04

New media, documented properly

Nothing recovered goes back onto a machine that was hit. It arrives on clean media instead, with a written record solid enough for an insurer or an ICO submission.

Always onto new mediaRecords the ICO will accept
05

Played back, checked, handed back

You get the full list of recovered files first, and nothing is charged until you approve it. Data goes back on fresh media, return postage paid, and the job stays open on our side until you confirm every file opens at your end.

You sign off the file listCopied onto unused mediaReturn post is paid by us

What the imager checks first

  • vssadmin delete shadows /all /quiet — this is the opening move of nearly every strain, wiping the restore points Windows holds. Once it shows up in the log the playbook is no mystery, and we go looking elsewhere.
  • Copy-encrypt-delete leaves a gap — deleting the original doesn't erase it. It sits in free space until overwritten, and patient carving often returns it whole.
  • Strains built for speed cut corners — large files are locked only in sections, and the parts they skipped usually still open.
  • Policy is shifting — the Government announced in July 2025 that public bodies and critical national infrastructure will be barred from paying ransoms. The direction of travel is clear.

Saying no is now the norm: in June 2025 Sophos put the share of encrypted organisations getting data back at 97%, with payment involved in only 49% of cases. Coveware's Q3 2025 figure has payment at 23%, its lowest on record. In 2023 the British Library was asked for something near £600,000, said no, and rebuilt. Paying is not the dependable choice, and never the only one — just the noisiest.

Live incident? Who to tell

  • Report Fraud (formerly Action Fraud) — ring 0300 123 2040, the national line for cyber crime. It is answered at any hour while an attack is under way.
  • NCSC — take the incident to the National Cyber Security Centre and follow the ransomware guidance it publishes, in order.
  • ICO, inside 72 hours — if personal data has probably been swept up, UK GDPR wants the report without undue delay, with 72 hours as the hard ceiling.
  • No More Ransomnomoreransom.org is a Europol-backed archive and the only place a genuine free decryptor comes from. Check there before you believe anyone else.

We handle the data end: imaging the drives, pulling files back, rebuilding on clean hardware, and writing up the records an insurer or the ICO will want. Talking to attackers is not something we do, and not something we would advise.

Lately in the casebook.

MK · MKD-2026-4638CONFIRMED ✓

A Buckinghamshire builders' merchant, locked up overnight

This strain didn't encrypt in place. It copied each file, locked the copy, then deleted what it had copied — leaving the originals in free space for us to carve, plus a NAS snapshot they had missed. The firm traded again a week later. No payment, no contact.

Running inside the weekNothing paid to anyone

While it is still in your hands.

Worth doing

  • Get photos of every note and lock screen before you touch a thing
  • Unplug infected machines from the network, but leave the power on
  • Hold on to the logs — delete nothing
  • Tell Report Fraud and the NCSC; add the ICO inside 72 hours if personal data may be affected

Best avoided

  • Getting in touch with the gang, bargaining, or paying up
  • Putting backups back on hardware that hasn't been cleaned
  • Trusting a sales pitch for a 'universal decryptor'
  • Rebooting a locked NAS before its screen has been photographed

The questions we get asked most.

Should the ransom be paid?

No. UK policing bodies and the ICO say the same thing: don't pay. Your money funds the next attack, no payment guarantees the files come back, and the ICO has said outright that paying does nothing for your regulatory position. We will not handle a payment.

Is there a way back without paying the ransom?

Frequently, in full or in part. The ways in: backups, shadow copies the attack overlooked, originals left in free space by a copy-encrypt-delete strain, NAS snapshots — or a legitimate free decryptor if one exists for that variant.

Does a free decryptor exist for this variant?

Start with No More Ransom, the legitimate archive Europol helps run. Nothing decrypts Medusa, Qilin, RansomHub, INC, or current LockBit and Akira builds — anyone offering a decryptor is selling you recovery work, not a key.

Am I obliged to report it?

Report it to Report Fraud — formerly Action Fraud, on 0300 123 2040 — and, if you are a business, to the NCSC too. Where personal data has probably gone out of the door, UK GDPR gives 72 hours for telling the ICO.

Leave it switched off until it reaches us.

Switch a failing device on again and you lose a little more. Open a case before you do — the diagnosis is free, whatever it finds.

0800 6890668