Ransomware recovery · Australia · answered 24/7 by a person

Hit by ransomware? Call before you pay.

Most ransomware never finishes the job. We built ScanCrypt, the free tool that measures how much of your data the attacker never reached and reads it back without their key.

Australian business incident response. The first hour decides how much can be saved, so call first and we will tell you what to touch and what to leave alone.

This service is for businesses and organisations. If ransomware has hit a personal computer or home NAS, report it via ReportCyber and check the free decryptors at No More Ransom. ScanCrypt itself is free for anyone to run.

What happens when you call

  1. 01Your call is answered, any hourIn business hours you reach our team directly. After hours an answering service takes your details and calls our team, and a responder calls you back. Either way we start with what has been hit, what is still spreading and what to touch first.
  2. 02The first hour: contain and preserveWe get the affected machines isolated and the surviving backups offline, and we keep the evidence, so the attacker stops moving before anything else happens.
  3. 03Then: measure what survivedScanCrypt gives one evidenced figure for how much of your data the ransomware never reached, before anyone talks about paying.

24/7

Answered by a person

< 1 hr

Containment starts

5.0 ★

Rated on Google

Hit right now?

Do this first. It changes what we can recover.

Do

  • Isolate affected machines (unplug the network cable or turn off Wi-Fi), but leave them powered on.
  • Keep the encrypted files and the ransom notes. They are often recoverable, and deleting them removes that option.
  • Take your backups offline before anything else can reach them.
  • Call us before you change anything. The first moves decide what can be saved.

Don't

  • Don't wipe, re-image or rebuild the affected machines yet.
  • Don't run removal or "cleanup" tools over the top of the evidence.
  • Don't pay the ransom yet. You may not need to, and payment carries its own obligations.

The same steps, on one printable page, for whoever is helping you: download the First-Response Guide (PDF).

Our tool, free to anyone

We built ScanCrypt because most ransomware never finishes the job.

Ransomware is in a race. Encrypting terabytes takes hours, so most strains scramble only part of each large file and then rename everything so it all looks equally lost. ScanCrypt measures exactly which bytes were encrypted and which were not, gives you one evidenced figure for a file or an entire share, and copies the surviving data back out.

No decryption key, no ransom, and no promise it cannot keep: it reports a measured percentage, never a guarantee. It came out of our own incident response work, where an Australian organisation had been told its data was gone. Most of it was not. So we packaged the technique and gave it away, including to IT providers who compete with us.

Get it now

Windows and macOS. One file, double-click, point it at the file or folder you want checked. No account, no upload.

Running it mid-incident and not sure what the readout means? Call 1300 004 766 and we will read it with you. Or read the story of how it was built.

Your VM won't mount. It reads the files out anyway.

Ransomware often wrecks the header of a virtual disk, so Hyper-V or VMware refuse to open it and the whole disk gets written off. ScanCrypt rebuilds the disk from the block map that survived and copies your files out with their names and folders intact. VHDX, VHD and VMDK.

One number for the whole share.

Point it at an encrypted share and get a single incident-wide figure, with a per-file breakdown as CSV or a standalone HTML report. That is the figure your insurer and your board will ask for.

Fast enough to use while you triage.

A 300 GB virtual disk is measured in seconds, because finding where the encryption stops does not mean reading the whole disk. Scan what matters first and have answers in the first hour.

Read-only, offline, open source.

It never writes to the file or disk it scans and proves it with a hash before and after. No account, no upload, no phone-home. Apache 2.0, every release built from public source with a checksum.

What it will not do, stated plainly

  • It is not decryption. It recovers the bytes that were never encrypted; the rest stays locked.
  • Recovery is most, not all. You get a measured figure, never a promise that every file opens.
  • Small files are usually encrypted end to end. The value is in the big ones: databases, VM disks, backups, media.

From a measurement to a working system

Why some ransomware-encrypted data comes back without paying.

A lot of modern , including the Makop/Phobos family behind .ndm448, is built to encrypt quickly. On a large file it scrambles only the front and leaves the rest of the data untouched. The file won't open, so it looks lost. Most of it usually isn't.

That is why big, structured files survive best. Databases, virtual disks and archives are laid out in fixed-size blocks with their own headers and IDs. When only the front is scrambled, the intact blocks deeper in the file can be found and put back in order. ScanCrypt does the measuring and the carving; the steps below are how we turn what it finds into something your business can run on again.

Map the damage

We measure how random each part of a file is: its entropy. Encrypted regions read as near-random; real data does not. That tells us how much of each file is genuinely encrypted, which is often only a small slice at the front.

Find the intact data

We locate the untouched data blocks by their signatures and internal identifiers, the fixed-size structures that databases, disks and archives are built from.

Carve and reassemble

We pull out the surviving blocks and rebuild them in the right order using their own internal IDs, working around the parts that were scrambled.

Rebuild into something usable

For a database, we reassemble the recovered structures into a fresh, sound database on a clean server.

Validate and reconcile

We check the rebuilt data against known-good references (row counts, record samples, schema) and keep what is confirmed clearly separate from anything uncertain.

The honest result

Done well, this recovers part, and sometimes the large majority, of the records without the attacker's key. It works best exactly where the damage hurts most: large, business-critical databases and virtual disks.

The limits, stated plainly

It depends on the strain using partial encryption; some encrypt everything. Small files that are encrypted end to end recover less reliably than large ones. Recovery is case dependent, never guaranteed, and always validated and signed off before it goes back into production.

Recent recoveries

In 2026 an Australian business came to us with Akira across two ESXi hosts and a SAN, about 20 virtual machines including Active Directory and Exchange, and a SonicWall as the way in. ScanCrypt read all of it back and nobody paid a ransom. Every incident is different, and we can usually say within hours what looks recoverable in yours. How Akira recoveries work →

Earlier, in an engagement for an Australian organisation, every conventional option had failed. The offline tape backups were corrupted, the on-site backups were encrypted, and the shadow copies were gone. Using partial-encryption recovery, we rebuilt the organisation's critical business database, millions of records across more than a thousand tables, without paying the ransom. That engagement is where ScanCrypt came from.

Outcomes described are specific engagements. No recovery is guaranteed.

Read the full technical whitepaper→
★★★★★
“IronSights provided exceptional support during a mission-critical ransomware incident. From the outset, their team was personable, calm and highly professional, while also being incredibly skilled and relentless in their approach. They treated every decision with the level of care and precision the situation demanded, worked through the technical detail thoroughly, and never took shortcuts. Their ability to balance urgency with discipline gave us real confidence during an extremely difficult time. I have worked with many technology providers over the years, but I have never been as impressed by a company as I was with IronSights. I would strongly recommend them to any organisation needing serious cybersecurity expertise, particularly when the stakes are high.”
AndrewVerified Google review, ransomware incident
“We engaged IronSights to help us with an Akira ransomware incident that impacted one of our clients. They were great to work with and jumped in quickly to help us investigate what had happened and get the client back up and running. Ryan and the team worked well alongside our engineers and kept things moving during a pretty stressful incident. Would definitely recommend them to other MSPs needing an extra set of hands or specialist help with ransomware recovery.”

Brett

Director

Managed Service Provider

“Not all heroes wear a cape. These guys dropped what they were doing and were on the next flight to not only save our butt but crucially recover forensic IT info about our ransomware attack and help us get back up. We can’t praise Ryan and team highly enough for their 6 star effort.”

Stephen

Systems Admin

Private College

Where recovery comes from

The order we work through, before anyone talks about paying.

Paying is the last resort, not the first. We work down this list, and partial-encryption recovery is often where it ends.

  1. 1Clean, verified backups held offline or as immutable copies.
  2. 2Volume shadow copies or snapshots, if they weren't deleted in the attack.
  3. 3Partial-encryption recovery with ScanCrypt, the method above, and often the one that saves the day when the backups are gone.
  4. 4A public decryptor, on the rare occasion keys leak or the strain has a known flaw.
  5. 5Rebuilding from source systems where the data still exists elsewhere.

How it runs once you call

Contain, investigate, recover, report. In that order.

Recovery only holds if the attacker is out and stays out. So the data work sits inside a full incident response, with the evidence and the paperwork your insurer and the OAIC will ask for.

Contain

Isolation of affected systems and accounts within the first hour. Surviving backups taken offline. Evidence kept.

Investigate

Entry point, attacker timeline, what was accessed or taken, and whether they are still inside. Data-theft claims are checked, not assumed.

Recover

Backups are verified before anyone trusts them. ScanCrypt measures what survived and pulls it back. Nothing goes back online until it has been checked clean.

Report

Full timeline and root cause within five business days of containment, structured for the OAIC, your insurer and your board.

Fortify clients have incident response included. Everyone else can engage us on demand, subject to capacity, or arrange an IR retainer now so the terms are agreed before you need them at 2am.

Know your strain

The strains hitting Australian businesses right now.

The extension on your files usually names the strain, and the strain shapes the recovery. Strain-specific guides for the operations most active against Australia, including the .ndm448 (Makop/Phobos) family covered in depth on this page:

Want to see which groups are hitting Australian organisations right now? Our Australian data breach tracker is a running, human-reviewed list of active ransomware and extortion cases.

Nothing encrypted, just a threat to publish? That is a different job, with no files to recover and a different clock running: data theft extortion response.

Before you decide anything

Paying, evidence and reporting, for Australian businesses.

Preserve, then contain

Disconnect affected machines from the network but keep them on. Hold on to encrypted files, ransom notes and logs. They are evidence, and they are often recoverable. Take backups offline and check whether they are intact before you trust them.

Don't make it worse

Don't rush to pay: our guide to the payment decision covers what paying does and does not get you. Don't run cleanup tools or restore over the top of the evidence. And don't assume the ransom note is telling the truth. Data-theft claims are frequently a bluff, and should be assessed rather than accepted.

Your obligations in Australia

If personal information was accessed, the Notifiable Data Breaches scheme may require you to assess and notify the OAIC. If you pay a ransom, the Cyber Security Act 2024 requires a separate payment report within 72 hours. Report the incident to the ASD's ACSC via ReportCyber. This is general guidance, not legal advice, so get your own counsel.

Common questions

Ransomware recovery, answered.

Files encrypted right now? Call 1300 004 766.

  1. Can you recover files encrypted by ransomware without paying?

    Often, yes, where the only partially encrypts files. Many strains scramble the front of large files and leave the rest intact, so the untouched data can be located and rebuilt without the attacker's key. It depends on the strain and the files involved, so it is a recovery effort rather than a guarantee.

  2. What is ScanCrypt, and is it really free?

    ScanCrypt is the tool we built for our own recoveries and then gave away. It measures exactly which bytes of a file were encrypted and which were not, gives you one evidenced figure for a file or a whole share, and copies the surviving data back out, including files from virtual disks that will no longer mount. It is free, Apache 2.0 licensed, read-only and fully offline, with no account and no upload. Download it at scancrypt.org.

  3. Will ScanCrypt decrypt my files?

    No, and nothing else will either unless a key has been published for your strain. ScanCrypt does something different: it finds the parts of your files the never got to and copies those out, which on a large database or virtual disk is often most of the file. Small files that were encrypted end to end come back with nothing.

  4. Can our IT provider run ScanCrypt instead of calling you?

    Yes, and we encourage it. Download one file, run it, and point it at the file or folder you want checked. If the readout is unclear, or the figure is good but you are not sure how to get from a measurement to a working system, call us and we will work through it with you.

  5. Do you recover personal or home computers?

    Our recovery service is built for businesses and organisations. If has hit your personal computer or home NAS, report it through ReportCyber at cyber.gov.au and check nomoreransom.org for free decryptors before considering any payment. ScanCrypt itself is free for anyone to run.

  6. What is a .ndm448 file, and can it be recovered?

    A file with the .ndm448 extension has been encrypted by a variant of the Makop/Phobos family (Microsoft detection Ransom:Win32/Phobos.PB!MTB). Because that family encrypts for speed, large .ndm448 files, especially databases, are frequently good candidates for partial-encryption recovery.

  7. Should I pay the ransom?

    Not before you have to. Payment funds the offender, carries no guarantee your data comes back, and may be unnecessary if the data is recoverable. In Australia, paying also triggers a separate reporting obligation. Let us measure what can be recovered first.

  8. Are my backups safe to restore after ransomware?

    Check before you trust them. Attackers routinely encrypt or delete backups they can reach. Take backups offline, confirm they are intact and clean, and restore into a known-good environment rather than over the top of a compromised one.

  9. Do I have to report a ransomware attack in Australia?

    Possibly. If personal information was accessed you may need to assess and notify the and affected people under the . Unauthorised access can be enough. If you pay a ransom, the Cyber Security Act 2024 requires a separate payment report. This is general guidance, not legal advice; seek your own counsel.

  10. How long does ransomware recovery take?

    It varies with the size and state of the data. Initial containment and assessment happen straight away; rebuilding a large database is measured in days, not minutes. We give you a realistic picture early, and we separate what is confirmed recovered from what is still being reconciled.

The IronSights incident response team in Australia

Answered 24/7

Speak to the people who built the tool.

If your files are encrypted right now, call us. The sooner we preserve what's there, the more we can bring back. Answered by a person any hour, and our Australian responders take it from there.