Independent testing. We may earn a commission when you buy through links on this site. Learn more

Ransomware: What to Try Before You Consider Paying

Free decryptors exist for many families, snapshots survive more often than assumed, and many strains delete the originals rather than encrypting in place — which makes them recoverable.

Ransomware is a data loss problem with a countdown timer attached, and the timer is designed to stop you thinking clearly. There is more to try than most victims realise, and several of the options disappear if you take the obvious first steps in the wrong order.

The first hour

  1. Disconnect from the network. Unplug the cable, turn off Wi-Fi. Encryption spreads to network shares, NAS boxes and connected cloud folders. Stopping the spread protects what is not yet lost.
  2. Do not reboot. Some families keep keys in memory, and some leave recoverable artefacts that a reboot clears. A running infected machine is worth more to a responder than a rebooted one.
  3. Photograph the ransom note with your phone, including the file extension used on encrypted files. This identifies the family, which determines whether a free decryptor exists.
  4. Disconnect backup drives. If a backup drive is attached, it is being encrypted too.
  5. Do not delete the encrypted files. If a decryptor is released later, you need them. People clean up in frustration and remove the only thing a future fix could work on.

Identify the family before anything else

This determines everything that follows. The No More Ransom project, run by Europol with a number of security vendors, maintains free decryptors for a substantial list of families and will identify yours from a sample file and the ransom note.

It is genuinely free, and it is the single highest-value thing to try. Where a decryptor exists, the problem is solved without paying anyone. Do this before buying software, before contacting the attackers, and before writing anything off.

Shadow copies and snapshots

Windows keeps Volume Shadow Copies for System Restore, and macOS keeps Time Machine local snapshots. Most ransomware deletes these deliberately, which is why the advice is often dismissed — but “most” is not “all”, and the check takes minutes.

On Windows, right-click a folder and look at Previous Versions, or check whether System Restore points survive. On macOS, tmutil listlocalsnapshots / lists local snapshots. On a NAS, check for filesystem snapshots — and note that snapshots on a properly configured NAS are frequently immutable, which is exactly the scenario they exist for.

Where recovery software genuinely helps

This part is not widely understood, and it is the most useful thing in this article.

Many ransomware families do not encrypt a file in place. They read the original, write an encrypted copy as a new file, then delete the original. From the file system’s point of view that is an ordinary deletion — which means the original may still be sitting in unallocated space, exactly like any other deleted file.

So a recovery scan is worth running. Not on the encrypted files, which are genuinely encrypted, but on the free space where the deleted originals may remain.

The rules are the same as any recovery, with more urgency:

  • Stop using the machine. Every write reduces what survives.
  • Image the drive first. Create a sector-level copy with an appropriate disk-imaging utility, then scan the copy and preserve the original device.
  • Scan the image, not the machine.

Success varies enormously by ransomware family, storage type and how long the machine continued writing data. SSDs with active TRIM are especially difficult, while a spinning disk that was disconnected quickly may retain more deleted originals. EaseUS Data Recovery Wizard and MiniTool Power Data Recovery both let you scan and inspect results before deciding whether a paid recovery is worthwhile.

On paying

We are not going to advise you either way, because it is a decision about your business, your obligations and your risk, and anyone offering a confident universal answer is not thinking about your situation.

What we will say factually: payment does not guarantee a working decryptor; in some jurisdictions payments to sanctioned entities carry legal consequences; and if you have cyber insurance or a regulatory reporting duty, involve those people before making any decision. Report the incident to your national cybercrime body regardless, because that reporting is part of how decryptors eventually get built.

Afterwards, properly

Do not restore onto the infected machine. Rebuild from clean media, then restore data. Restoring onto a compromised system reinfects the restore, and this happens to people twice.

Change passwords from a different, clean device, prioritising email and anything reused. Assume credentials on the machine were taken, because increasingly they are — modern ransomware often exfiltrates before encrypting.

The only real defence

  • Keep one backup copy offline or immutable. An always-connected external drive is not a ransomware backup, it is a second victim.
  • Enable snapshots with retention on any NAS, and make them immutable if the unit supports it.
  • Test a restore. Discovering your backup does not restore during an incident is the worst possible timing.
  • Keep versioned cloud storage, which usually allows rolling back to pre-encryption versions.

If it is happening right now: disconnect the network, do not reboot, photograph the note, and check No More Ransom before you do anything else.


Recovery tools to check after a ransomware incident

These are paid-product links from active UrRecover affiliate relationships. Use the free scan or preview first where available, compare what each tool actually finds, and do not buy if the files you need are not visible.

Start with a scan and preview

Only scan a disk image or disconnected copy. A scan cannot decrypt encrypted files, but it may find deleted originals that were left in unallocated space.

Try EaseUS Data Recovery WizardTry MiniTool Power Data Recovery

Affiliate disclosure: UrRecover may earn a commission if you purchase through these links, at no additional cost to you.

Recovery results depend on the device, the failure and whether new data has overwritten the missing files. Save recovered files to a different drive. For physical damage, unusual noises or an unstable RAID, stop and consult a professional recovery laboratory.

Recovering from shadow copies and older versions

Before anything else: do not pay, and do not overwrite the encrypted files. Some ransomware misses shadow copies and older file versions entirely, and those are recoverable with ordinary tools. EaseUS will scan for previous versions without touching the encrypted originals.

Written by BV

BV founded UrRecover after losing a memory card full of wedding photos and discovering that most "best data recovery software" rankings were ordered by commission rate rather than results. He now buys the licences, breaks the drives, and publishes what actually got the files back.

Independent recovery guidanceReview safe first steps before choosing software
Read safety guide