forumNew topic

Servers locked by ransomware, company demanding 500k lira — our backups were outdated

HHilal Ç***New member
Job title
IT manager
Sector
Construction
Organization type
workshop
Joined
Aug 2026
Message
292

Doki · Interface design · 2025

#1

IT called Monday morning: 'Servers locked, hacker message popped up, they want 500k lira'. I said 'restore from backup'. IT says 'backup is 2 weeks old, and part of it is missing too'.

Pressure from management: 'get the system running in three days'. Will paying the ransom get our data back? Is there any guarantee we'll get data back if we pay?

Should I have called the police, or should I now? The manager is asking if I reported it to the higher-ups. We're totally confused.

OOrhan K***MemberCommunity member
Joined
May 2023
Message
83
Most Helpful#2

USOM advice for ransomware: do not pay the hacker under any circumstances. Statistically, payers might get data back; but there's an equal chance files are corrupted.

Recovery process: 1) Isolate infected machines from the network, 2) Restore from backup (even if 2 weeks old, better than nothing), 3) Account for remaining data loss, 4) Notify USOM, 5) File a complaint with the police cyber crime unit.

Three-day target: Two weeks of data loss + 3 days of software fixes = 1 week. It's achievable.

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#3

don't pay the ransom, it gets worse after. screenshot the hacker message open a police report. restore from backup, then just tell the manager 'this is what we have'

KKaanMember
Job title
Product Manager
Joined
May 2024
Message
96
#4

Backup is 2 weeks old, but how much data actually changed in those 2 weeks? Can business continue at 70%?

MMert Ö***Member
Job title
Fuel station
Organization type
early-stage startup
Joined
Nov 2023
Message
64
#5

Stop arguing about paying the ransom. Look: install security software (immediately) restore from backup (in parallel), file police report (online 15 mins). Do all three simultaneously.

HHasan K***Member
Job title
Software developer
Sector
Jewelry
Organization type
workshop
Joined
Sep 2025
Message
212
#6

Depends on the ransomware type: some allow recovery key access, some give fake keys. Find out the attack type on your servers (WannaCry, Conti, etc.), check if USOM has a decryption tool.

SSena Y***Veteran
Job title
Store Manager
Sector
Chemistry
Organization type
20-person company
Joined
Feb 2026
Message
10

Doki · Mobile app · 2023

#7

paying 500k lira and not getting data back — most expensive market there is. restore from backup, get used to reset data don't pay the hacker it costs more in the long run

EElif V***Member
Job title
Quality control inspector
Sector
Machinery manufacturing
Organization type
20-person company
Joined
Nov 2025
Message
40
#8

timely topic.

RReyhan K***MemberCommunity member
Joined
Jun 2025
Message
1
#9

I've been dealing with this for a long time. honestly everyone rushing into ransomware recovery gets stuck at the same point.

Good luck with that.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#10

The answer above hits the nail on the head. Most incidents start with a leaked password not a vulnerability.

If you have questions, write them; I'll answer as best I can.

EErcan C***MemberCommunity member
Joined
Sep 2024
Message
345
#11

Saved.

ZZafer B***Member
Job title
Customer service representative
Sector
Insurance
Organization type
chain store
Joined
Nov 2023
Message
34
#12

Thanks, that was the answer I was looking for.

CCaner Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
two-branch business
Joined
Jan 2024
Message
155
#13

I have a question. Don't rely on a single measure; go layer by layer.

SSultan Y***Member
Job title
Customer Relations Manager
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Apr 2025
Message
9
#14

We need to take it step by step. Just because everyone does it doesn't mean it's right.

I'm also curious if anyone does it differently.

ZZehra G***Member
Job title
Operations director
Sector
Catering
Organization type
boutique agency
Joined
Feb 2024
Message
162
#15

this thread is archived.

PPerihan K***Member
Job title
Product Manager
Sector
Catering
Organization type
20-person company
Joined
Feb 2024
Message
220

Doki · Corporate website · 2024

#16

The most overlooked point about ransomware recovery is this: Start with a small trial; don't commit to everything at once.

If I were you, I'd go this route.

SSerkan A***Member
Job title
Chief Technology Officer
Sector
Cosmetics
Organization type
medium-sized business
Joined
Jan 2022
Message
13
#17

I'm writing this so you don't make the same mistake. Most incidents start with a leaked password not a vulnerability.

NNecati D***MemberCommunity member
Joined
Oct 2023
Message
251
#18

The discussion got scattered, let me summarize. When we decide without measuring, we always end up in the same place.

Good luck with that.

AAhmet M***MemberCommunity member
Joined
Jan 2024
Message
27
#19

I'm a small business, let me explain from my side. If you don't write this down from the start it leads to arguments later.

RRamazan A***MemberCommunity member
Joined
Feb 2023
Message
34
#20

We need to take it step by step. Don't hesitate to ask; those who don't ask always pay more.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. Hope this helps.

Reply