forumNew topic

Our systems were encrypted by ransomware — can I get our files back without paying the ransom?

OOya O***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
two-branch business
Joined
Dec 2024
Message
113
#1

We're a 25-employee wholesale building materials distributor based in Riyadh. When we came into the office Sunday morning, we found our accounting server, shared file storage, and 8 employee PCs completely locked up. All file extensions had been changed, and a text file demanding 80,000 SAR in crypto was left on the desktops.

Our sysadmin immediately pulled the plugs on the servers. We have an external backup drive from two weeks ago, but since we don't know how long the attackers were inside the network, we aren't sure if that backup is infected too. Our operations are at a complete standstill right now because sales invoices and customer ledger accounts are locked.

We definitely do not want to pay the ransom. There's zero guarantee they'll even provide the decryptor, and we don't want to take on the legal risks either. At this stage, is it technically possible to recover our files without paying, and where should we start?

RRıdvan K***MemberCommunity member
Joined
Oct 2024
Message
77
Most Helpful#2

Short answer: Yes there is a chance of recovering your files without paying the ransom, but it directly depends on the specific ransomware strain the encryption algorithm used, and the integrity of your backups. Before contacting the attackers you need to carry out professional digital forensics steps methodically without causing further damage to the systems.

Here is the roadmap you should follow to recover your files: 1) First create a forensic copy—meaning a bit-level image—of every affected drive, and completely isolate the original devices from the network. Never attempt recovery or decryption on the original drive; an improper action could permanently corrupt the data. 2) Identify the exact name and version of the ransomware strain. Upload a sample encrypted file along with the ransom note to global open-source decryption platforms co-maintained by public cybersecurity authorities. If the malware is a known older variant or one that suffers from flawed key management, you can restore the data using free, official decryptors. 3) Mount your two-week-old external backup in a completely isolated test environment with no internet access. Determine the attacker's initial breach date through forensic log analysis. If the backup is clean, restore that data onto a fresh, clean OS install. 4) Plan to manually reconcile the two weeks of missing data using email archives, bank statements, and secondary cloud records.

RRecep S***MemberCommunity member
Joined
May 2025
Message
342
#3

Watch out for brokers out there claiming they can fix it without paying the ransom. Some of them are just opportunists who turn around, pay a lower ransom behind your back, and pocket a markup. Stick with an independent digital forensics specialist.

Correction: I misremembered the figure, it was a bit lower.

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
#4

Attackers usually wipe shadow copies, but sometimes the process fails midway. Once you've imaged the drive, make sure to run file recovery tools on the image to scan for leftover shadow copies or deleted temp database files.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#5

Pulling the plug on the servers was a good first move, but shutting down without taking a memory dump might mean losing volatile encryption keys. If any machines are still running, don't turn them off—just unplug the network cable.

YYağmur C***VeteranCommunity member
Joined
May 2023
Message
395
#6

We dealt with a similar incident last year and they wanted 50,000 SAR. We refused to pay. We restored from a two-week-old backup and spent 4 days re-entering all the invoices one by one using bank statements and e-faturas. Our total downtime cost ended up being roughly a third of the ransom demand.

EErcan A***Member
Job title
QA Tester
Sector
Catering
Organization type
medium-sized business
Joined
Dec 2023
Message
5
#7

Even if you pay the ransom, there's zero guarantee the files will actually decrypt. A lot of times the keys they give you end up corrupting large files like databases, so you end up out of pocket and out of luck.

LLale Ç***New member
Job title
System support specialist
Sector
Tourism
Organization type
chain store
Joined
Jun 2026
Message
161
#8

Stick to these three rules: 1) Do not plug that external drive into any machine on the current network. 2) Do not reach out to the contact addresses in the ransom note; don't let them know the system is active. 3) Do not run any antivirus or cleanup tools before taking a forensic image.

HHasan Ö***MemberCommunity member
Joined
Dec 2024
Message
39
#9

sorry to hear that then hook the backup drive up to a clean pc in read-only mode and check it out if you're lucky you can get away with just losing two weeks of data.

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#10

Under Saudi cybersecurity regulations, I would also recommend checking your legal reporting obligations to national cybersecurity authorities in the event of a potential customer data breach.

HHakan Y***New member
Job title
Human Resources Specialist
Sector
Advertising and promotion
Organization type
early-stage startup
Joined
Sep 2026
Message
4
#11

You're right. The real issue isn't the number, but what it's based on.

SSerdar K***Veteran
Job title
Growth marketing
Joined
May 2023
Message
264
#12

Thanks for writing this, that's the right way. Most incidents start with a leaked password, not a vulnerability.

The biggest time-waster for us was not knowing who had the final say. Good luck with that.

UUğur D***Member
Job title
Data entry clerk
Sector
Healthcare services
Organization type
sole proprietorship
Joined
Jan 2022
Message
2
#13

I went through the same thing two years ago. Start with a small trial; don't commit to everything at once.

People defend habits, not processes. Resistance comes from there. If you post the result here, it will help others too.

YYasemin Ö***MemberCommunity member
Joined
Apr 2023
Message
20
#14

I agree.

FFatih Z***Member
Job title
Software developer
Sector
Glass
Organization type
regional distributor
Joined
Nov 2025
Message
187
#15

Noted, thanks. When making decisions, write down the worst-case scenario too, not just the best.

NNecati B***Expert
Job title
Logistics planning
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Feb 2026
Message
31
#16

Let me clarify the technical side. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Solutions that work at a small scale collapse when you grow; I learned this late.

ZZerrin Y***Expert
Job title
Logistics planning
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Jan 2023
Message
65
#17

Let's separate the concepts they're getting mixed up. btw most time waste accumulates in tasks waiting for approval.

BBurcu A***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
workshop
Joined
Jun 2024
Message
49
#18

I'd appreciate it if you shared the outcome. If you scold false alarms, nobody will report again.

BBeren B***MemberCommunity member
Joined
Oct 2023
Message
114
#19

My questions are cleared up, thanks.

UUğur Y***VeteranCommunity member
Joined
Oct 2024
Message
3
#20

the opposite happened to me, that's why I'm writing. i mean taking measures without an inventory leaves doors you haven't seen open.

if I were you, I'd go this route.

Reply