Ransomware encrypts your files and demands payment to unlock them. It hits home computers, business PCs, servers and NAS units, including the QNAP DeadBolt and Qlocker attacks.

How we help
- Contain the attack: isolate affected machines and stop it spreading
- Find what survived: backups, shadow copies, NAS snapshots, cloud version history and unencrypted copies
- Image the affected drives before anything else changes, so no evidence or data is lost
- Rebuild affected computers cleanly and restore your data
- Close the way in: passwords, remote access, updates and backups
An honest note on decryption
Modern ransomware usually can't be decrypted without the attacker's key. Free decryptors exist for some older strains, and we check for them, but we won't promise to decrypt files. What we can do is recover everything that survives and make sure you are protected next time.
Do this now
- Unplug the network cable and turn off Wi-Fi on affected devices. Don't switch them off.
- Disconnect backup drives so they aren't encrypted too.
- Photograph the ransom note.
- Don't pay, and don't contact the attackers.
Report it. In England, Wales and Northern Ireland, report cyber crime and fraud to Report Fraud (the service that replaced Action Fraud) at reportfraud.police.uk or on 0300 123 2040. A business under a live cyber attack can call that number 24 hours a day. In Scotland, call Police Scotland on 101.
Get help
Call 020 7237 6805 or walk in to Unit 1, 80 Willow Walk, London SE1 5SY, Monday to Saturday, 9am to 6pm. For businesses we can also work on site or remotely.