Blog & news

Blog — Data Recovery and Cybersecurity

Technical analyses, prevention tips and data recovery news from the experts at SOS Data Recovery, Swiss laboratory since 2006.

Cybersecurity & prevention
In-depth technical analyses
Expert practical advice
Free diagnosis Estimate your recovery
Free diagnosis Quote within 3 hours Your data stays in Switzerland
Ransomware: can you recover your data without paying?

Ransomware: can you recover your data without paying?

  • May 18, 2026
  • Author : Stéphane Chapuis
  • Updated on:

You can often recover data after a ransomware attack without paying the ransom, because ransomware encrypts files, it does not erase them: they remain on the disk, unreadable without the key. Several doors open before the one marked payment: backups you thought were lost, the system's snapshots, files that are only partially encrypted, or volumes the attackers deleted without overwriting the data. A recovery laboratory can often save some of it, sometimes all of it, without ever contacting the criminals. Directly decrypting a recent strain, on the other hand, is mathematically out of reach as long as the keys have not leaked.

The first move is not up for debate: the moment you notice that files are being encrypted, shut the machine down immediately, even if it means pulling the plug. What follows explains what can be recovered, what cannot, and how to avoid making things worse.

What ransomware really does

Ransomware is malicious software that encrypts the files of a system to make them inaccessible, then demands a ransom in exchange for the decryption key. It all begins with an intrusion, most often a phishing email whose attachment installs the program. It does not show itself right away: it runs quietly in the background and encrypts, one by one, the contents of your important files, the ones that hold value for you as much as for a blackmailer. PDF and Word documents, databases, mailboxes: everything goes.

Before or during encryption, the program carries out a decisive step. It identifies the machine as a new target and generates codes, tokens, which it sends to a remote server. These tokens contain the keys, among other things, and form a unique identifier of the attack. It is this identifier that the attackers will ask for if you contact them: without it, they do not know which key matches you. We have already seen a single machine carry several identifiers and several keys, up to three: each key must then be negotiated separately if you hope to decrypt everything.

To make the attack visible and give its instructions, the program finally drops companion files, the notorious ransom note. These files are anything but trivial for a specialist: they are known signatures, which make it possible to identify precisely the ransomware strain used, and which contain the identifier of the attack.

Technically, the encryption almost always relies on a proven combination: a fast symmetric algorithm such as AES (often 256-bit) to scramble the files, and an asymmetric algorithm such as RSA (2048-bit or more) to protect the AES key. It is this pairing that makes the attack so hard to undo.

Can you decrypt without paying?

Here is the question everyone asks, and the honest answer comes down to three cases.

SituationDirect decryption?
Recent, well-designed ransomwareNo: keys too large, decades of brute-force computation
Older ransomware (shared keys, implementation flaw)Sometimes: decryptors exist
Keys seized by the police or published by repentant attackersYes: free decryptors (No More Ransom project)

By brute force: no. On a recent, properly designed ransomware, trying to guess the key is an illusion. The keys are so large that it would take decades of computation to find a single one. Direct decryption is not an option.

On older ransomware: sometimes. The first generations were built differently, sometimes with keys shared across all victims or with faulty implementations. For several of them, decryption solutions exist.

When the keys have been recovered: yes. It happens that federal police forces seize the attackers' servers, or that repentant criminals publish the whole of their keys. Organisations, including the European No More Ransom project, then collect these keys and turn them into free decryption programs. This is where the companion files regain their full value: they contain the identifier that makes it possible to find the right key.

In short, there are two favourable windows: either the strain is old and a decryptor exists, or the attack is old enough for the keys to have been discovered since. Faced with a recent ransomware whose keys have not leaked, direct decryption remains out of reach. But, and this is the whole point of what follows, decryption is not the only path to your data.

What a laboratory recovers when you think everything is lost

A cybersecurity company offering "ransomware recovery" does, in reality, fairly limited work: it relies on existing backups when there are any (a backup NAS, a Veeam, tapes), restores them, and if nothing works, it talks with the client to negotiate the ransom. A data recovery laboratory goes much further.

Because the attackers often make an exploitable mistake. To neutralise the backups, they delete RAID systems, wipe volumes, destroy configurations, but they do not necessarily overwrite all the data on top. We can then rebuild the deleted RAID and recover the backups it contained, an advanced recovery operation that has nothing to do with the mere restoration of an intact backup.

Our arsenal does not stop there. We exploit the system's snapshots (Windows Shadow Copies) when they have not been deleted. We recover temporary files, intermediate versions, and forgotten data on media the ransomware did not touch.

There is even the case of partially encrypted files. Encrypting an entire file takes time, especially a large one: a video, an Outlook PST mailbox file of several gigabytes. To move fast and hit as many files as possible, some ransomware encrypts only the beginning of each one, for instance the first thousand sectors. The file becomes unusable by the software that created it, but everything else is intact. Depending on the format, we can sometimes read this unencrypted part and extract data usable by the client, even with the beginning lost. It is case by case, but it is often a genuine lead.

The mistakes that make it worse, and the moves that save the day

The most frequent mistake, we see it come back time and again: restoring the backups directly onto the affected server. You reinstall the server from scratch, push the backup onto it, and the job seems done. Except that this overwrites the original disks. If the backup turns out to be faulty, incomplete, or itself encrypted, you have just overwritten data that was perhaps still recoverable. You have destroyed your last chance without knowing it.

That is why the rule, as with any recovery, is to freeze the state before acting. Here is how to proceed:

  1. Shut the machine down immediately. The encryption is running in the background; every extra minute means more files encrypted. Do not hesitate to pull the plug to go faster. Isolate the machine from the network as well, to prevent it spreading.
  2. Reinstall nothing, restore nothing onto the original disks.
  3. Turn to a specialised laboratory. We systematically begin with a bit-for-bit safety copy, then we work read-only, on the copies: the ransomware is no longer running, and nothing is written back onto your original disks. Only from that point do we seek to recover.

To pay or not: the honest decision

Our position is clear: we advise against paying. Paying directly funds crime, and offers no guarantee of recovering anything at all. But we are clear-eyed. When the survival of a company and its jobs is at stake, one has to weigh things up. It is a little like a bank robbery: no one asks the staff to refuse to hand over the money at the cost of their lives. You give in, and in doing so, you indirectly fund the crime. Everyone decides according to their situation.

If negotiation becomes inevitable, two principles reduce the risks.

First, never negotiate yourself. As soon as an attacked company makes contact with the attackers, they investigate it, carry out OSINT (open-source intelligence), assess its size and its financial means, and adjust the ransom accordingly. Instead, entrust the discussion to a specialised third-party firm. It seems paradoxical, but an intermediary who negotiates regularly often obtains a better deal: the attackers run a business and care about their reputation, because a dissatisfied client is a client who will never pay again.

Second, demand proof. Before any payment, ask for the decryption of a few files to check that the attackers really hold the key. Choose files with no value to anyone, neither to you nor to them: certainly not the annual budget or the accounts, but harmless documents. If they send them back to you decrypted, you have proof that they hold the key. Because it happens that they have lost it, notably after their servers are shut down. Never pay without this guarantee.

Blackmail by disclosure: ransomware has changed its face

Blocking access to the data is no longer the only lever. Modern ransomware plays on three fronts.

The first remains blocking by encryption, the one everyone knows. But a second has taken hold: the exfiltration of the data coupled with a threat of disclosure. The attackers copy your data onto their servers and threaten to publish it if you do not pay. It is no longer "you can no longer access your data", but "we will make your data public". This shift has a precise cause: as companies equipped themselves with off-site and disconnected backups, they no longer needed to pay to recover their files. So the attackers changed their weapon.

The third front goes further still, among certain groups that take the time to analyse what they have stolen: the threat to sell or disclose confidential information to competitors, or even to the tax authorities. Always the same logic of blackmail, pushed to the extreme.

A word on the amount, because it is not set at random. The attackers look for your banking information in the stolen files (balance sheets, accounting PDFs) and calibrate the ransom on your cash position, often around 30 to 50% of cash flow. The goal is not to sink you, but to extract the maximum from you without pushing you into closure, because a dead company does not pay.

Your legal obligations in Switzerland

Beyond the technical side, a ransomware incident entails obligations, and they differ according to your profile.

If you are an operator of critical infrastructure (energy, drinking water, transport, certain cantonal or communal authorities), you must report the cyberattack to the Federal Office for Cybersecurity (FOCS) within 24 hours of its detection, with 14 days to complete the file. This obligation has been in force since 1 April 2025 and targets in particular attacks that threaten the operation of the infrastructure, lead to a data leak or come with extortion.

For an ordinary company holding personal data, it is the new Data Protection Act (nFADP) that applies. Its Article 24 requires notifying the Federal Data Protection and Information Commissioner (FDPIC), as soon as possible, of any breach presenting a high risk to the data subjects. There is no fixed deadline like the GDPR's 72 hours, but intentional omission can cost up to 250,000 francs in fines. If your clients' data has been exfiltrated and threatened with disclosure, you will generally have to inform them.

In all cases, file a complaint, and check whether your insurance includes cyber cover: more and more policies offer it.

The only safeguard that holds: the offline backup

No laboratory, however well equipped, replaces a good backup. And here again, there is backup and backup. A RAID or a NAS connected to the network is not safe: it is precisely what the attackers set out to destroy first. The only truly reliable protection is an offline, immutable and off-site backup, physically disconnected from the system it protects. It, and it alone, turns a ransomware attack into a mere setback rather than a catastrophe.

Frequently asked questions

Does ransomware erase the data?

No. Ransomware encrypts files to make them unreadable, but the data remains physically present on the disk. That is what leaves possibilities of recovery: backups, snapshots, partially encrypted files or volumes deleted but not overwritten.

Can ransomware be decrypted without paying the ransom?

Directly, only in certain cases: older, vulnerable ransomware, or strains whose keys have been seized by the police or published (No More Ransom project). On a recent, well-designed ransomware, brute force is impossible. On the other hand, the data can often be recovered by other routes, without decrypting.

What should you do immediately in a ransomware attack?

Shut the machine down on the spot, pulling the plug if necessary, and isolate it from the network: the encryption is running in the background and every minute worsens the damage. Reinstall nothing, restore no backup onto the affected disks, and entrust the medium to a specialised laboratory.

Should you pay the ransom?

We advise against paying: it funds crime and offers no guarantee. If the survival of the company demands it, never negotiate yourself (the attackers investigate you to adjust the ransom), go through a specialised third party, and demand proof of decryption on worthless files before any payment.

Can a laboratory recover my data after a ransomware attack?

Often, yes, without going through the attackers: rebuilding of deleted but not overwritten RAIDs, snapshots (Shadow Copies), temporary files, forgotten backups, files that are only partially encrypted. The laboratory works on a bit-for-bit, read-only copy, without ever overwriting the original disks.

What are the legal obligations in Switzerland after a cyberattack?

Operators of critical infrastructure must report the attack to the Federal Office for Cybersecurity (FOCS) within 24 hours, since 1 April 2025. Other companies holding personal data must, under the nFADP, notify the FDPIC as soon as possible of any high-risk breach, and inform the data subjects if their data has been exfiltrated.

Available 24/7

Data emergency? We respond immediately.

In the event of critical data loss or a server failure, our on-call team responds urgently, including weekends and public holidays.