Taking work now — the first look is freeNAS drives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
NDRNAS Data Recovery 0800 6890668 Price my job
NDR / Every kind of NAS / NAS hit by ransomware

Deadbolt · Qlocker · eCh0raix · SynoLocker · Checkmate

A NAS hit by ransomware. What the attacker encrypted, what it deleted, and what it never reached.

Ransomware on a NAS arrives through the internet-facing services the makers shipped switched on, and it works file by file: Qlocker moved QNAP owners' files into password-protected 7-Zip archives from 19 April 2021; Deadbolt encrypted files on thousands of QNAP units from January 2022 and on Asustor units the following month; eCh0raix has done the same on QNAP and Synology since 2019. None of them touches the array, and that is the point. The volume is intact; the files on it have been replaced. What comes back is what the attacker could not reach or did not finish: snapshots taken before the attack, the originals it deleted after encrypting, the tails of large files it only partly encrypted, and files on volumes it never saw. What does not come back is a Deadbolt-encrypted file without the key, and we say which is which at the free look. A set is £500 + VAT upwards, fixed in writing, 5–10 days at the bench.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Power it down. Label each drive with its bay number. Do not rebuild, repair, initialise, reinstall or reset. A rebuild reads every sector of every surviving drive, and on a set with a second weak member it finishes what the first failure began. Nothing on the drives gets worse while the unit is off.

Ransomware symptoms, and what each means.

Not listed? Describe it on the form →
Packing it and posting it: power the unit down, write the bay number on each drive with a marker before it comes out, and send every drive from the set, including any SSD cache. Each drive travels in an anti-static bag inside its own padding, in a box with nothing able to move; the unit itself comes too if it holds an encryption key or a proprietary layout, and its power supply with it. Insure the parcel for what the files are worth rather than the price of the drives, and use a tracked service. The posting address is not printed anywhere on this site; it arrives by email in reply to the form, with a booking sheet to print; the sheet inside the parcel is what matches it to your enquiry when it is opened. Or hand the sealed parcel in at the nearest of ten drop-off points, your name on the outside and the sheet inside; say where you are on the form and it comes by email. We pay the postage home either way. The whole of it is written up on the guide to packing and posting.

How it is laid out, and what fails.

DeadboltEncrypts files in place with a per-victim key and rewrites the login page. Censys counted 4,988 infected QNAP units on 26 January 2022 and 7,783 in a July 2022 surge; Asustor was hit from February 2022. Without the key the encrypted files stay encrypted; the snapshots and the deleted originals do not.
QlockerFrom 19 April 2021, through a hard-coded credential in QNAP's HBS 3, it moved files into password-protected 7-Zip archives and deleted the originals. Deleted originals on an ext4 volume are often carvable until overwritten, which is why the unit must be left alone.
eCh0raix and SynoLockereCh0raix has brute-forced QNAP and Synology units since 2019 and encrypts file by file. SynoLocker hit DSM 4.3 and earlier in August 2014, and Synology said at the time it could not decrypt the files. In both cases the recoverable material is what was not encrypted.
What the array does not knowRansomware works through the file system. The mdadm arrays, the LVM map and the snapshots beneath the volume are untouched, and Btrfs or ZFS snapshots taken before the attack are the cleanest copy that exists.

What you see, and what it means.

Describe yours to us →
What you see The usual reason for it Where that leaves you
Ransom note on the login pageDeadboltUnplug the network; snapshots and deleted originals assessed
7z archives everywhereQlockerOriginals carved from the volume image
.encrypt files and a READMEeCh0raixSnapshots and untouched volumes recovered
Unit reset or reinstalled after the attackSnapshots and deleted originals overwrittenLess comes back; told honestly
Snapshot Replication or Hyper Backup on the unitA copy the attacker may not have reachedRecovered from the images

From the box arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on the parcel and a number on every drive the day it is opened, and an engineer settles what has actually happened before anything spins. The unit is examined on its own; each drive is assessed on our own equipment, never in a NAS that will try to rebuild. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo rebuilds, no repairs, no resets
02

The unit, and the drives, apart

The box and the disks are two different jobs. The unit is tested separately, because a dead power supply, a failed board or a bricked boot flash leaves the drives untouched more often than not. Each drive is then read on the bench: the ones that answer at full speed, and the weak or failed ones in clean air where they need head work. On units that hold an encryption key or a layout of their own, the unit is part of the data and is kept with it.

Unit and disks assessed separatelyFailing members to the clean bench
03

Every member imaged, once

The array is reconstructed from the images and the volume examined read-only. Snapshots taken before the attack are mounted from the image and copied out; deleted originals are carved from the free space; partly encrypted files are assessed for what survives; untouched volumes are copied whole. Nothing is decrypted, because nothing can be without the key, and nothing is attempted on the originals.

Every drive, including the cacheWeak areas last
04

The set put back together, from the images

Order, chunk size, parity rotation and the reshape point are read from the drives' own metadata and the array is reassembled in software: mdadm and LVM under SHR, X-RAID and QTS pools; a ZFS pool imported read-only; Drobo's BeyondRAID zones reconstructed. The file system, Btrfs, ext4, XFS or ZFS, is repaired on the virtual volume, and encrypted volumes are unlocked there with the key you supply. Never on the originals.

Rebuilt in software, from imagesThe file system repaired on the virtual volume
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job5–10 days at the bench

What arrives most often

  • Pull the network cable, not the power. A running attack should be stopped; a unit that is still encrypting should be powered down after the cable is out.
  • Do not update, reset or reinstall. Every one of them writes to the volume, and the deleted originals live in the free space that writing reuses.
  • Snapshots are the answer more often than not. Btrfs and ZFS snapshots taken before the attack sit beneath the volume, untouched by anything that worked through the file system.
  • We do not negotiate, decrypt or pay. What comes back is what the attacker did not reach, and the free look says honestly how much that is.

One job, followed all the way through.

UK · NDR-2026-0530JOB LOGGED ✓

A QNAP TS-453D in RAID 5 hit by Deadbolt, with snapshots on and a business that did not know it had them

The network cable came out the moment the ransom page appeared, and the unit was powered down. All four drives were imaged, the pool reassembled from the images, and a Btrfs-style snapshot from two days before the attack found on the volume. It was mounted from the image and copied out whole; the encrypted files were left where they were.

98% of the share recovered from the snapshot6 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Pull the network cable, then power down
  • Note the ransom note's family and the file extension
  • Tell us whether snapshots or a backup task were configured
  • Send every drive, labelled, and the unit

What sets us back

  • Updating the firmware after the attack
  • Factory resetting or reinstalling
  • Rolling back or deleting snapshots yourself
  • Paying, at least before the free look says what survives

Questions answered before you commit.

Can you decrypt Deadbolt files?

No. Not without the key, and neither can anyone else that we know of. What we recover is what the attacker did not reach: snapshots, deleted originals, partly encrypted files, untouched volumes. The free look says how much that is before any charge.

Qlocker put my files in 7z archives. Are the originals gone?

Often not. Qlocker deleted them after archiving, and deleted files on an ext4 volume survive in the free space until overwritten. Leave the unit alone and send it.

Should I pay the ransom?

That is your decision, and we do not take part in it. Have the free look first; if the snapshots hold what you need, the question goes away.

What does it cost?

A set is £500 + VAT upwards after the free look, fixed in writing; four bays or more from £1,250 + VAT. On most jobs no data means no bill.

How long does it take?

5–10 days at the bench.

Pull the cable. Then send the set.

Snapshots, deleted originals and untouched volumes are assessed from the images, read-only. The first look is free and says honestly what is there.

0800 6890668