Case studies
Ransomware response case studies
Response records organized by industry and ransomware family, covering the incident background, what we did and what was recovered, so you can gauge what is realistic in a similar situation.
Entries marked as illustrative are composed from typical scenarios to explain our approach. They do not describe a specific customer incident.
Manufacturing Ransomware Response and Recovery2 cases
Industry solution- AkiraCase study
Akira encrypts an ESXi cluster at a manufacturing group
After entering through a VPN account, the attacker powered off VMs and encrypted their VMDK files, taking MES and office systems down together. Key VMs were recovered from storage-layer remnants and partial disk repair.
- MalloxCase study
Mallox encrypts SQL Server and an ERP database at a manufacturing company
A shared SQL Server instance running production and finance data was encrypted by Mallox and the ERP client stopped working. Core data was recovered through file-level repair and log extraction, and the exposed 1433 port was closed.
Healthcare Ransomware Response and Recovery3 cases
Industry solution- InterlockCase study
Interlock encrypts a county hospital's systems after a domain takeover
Staff were lured by a ClickFix-style fake verification page into running a command; after taking domain admin the operators pushed the Interlock encryptor estate-wide via GPO, hitting HIS, LIS, EMR and the file servers at once. A clean domain was built in an isolated segment before clinical systems were restored in batches.
- RhysidaCase study
Rhysida encrypts a specialty hospital's PACS and HIS servers
A hospital's PACS imaging server, its attached NAS imaging volume and the HIS application server were encrypted by Rhysida over a holiday night, with .rhysida appended and the operators threatening to publish patient images. Build analysis showed the free decryptor applied to part of the file set; the remaining images came from modality caches and an offline drive, HIS was restored from an offline dump, and no ransom was paid.
- PhobosCase study
Phobos encrypts the Oracle database behind a hospital HIS
Phobos encrypted the Oracle data files behind a hospital HIS, halting outpatient registration and billing. The instance was rebuilt from archive logs and unencrypted data files, prioritizing outpatient modules.
Government and Public Sector Ransomware Response1 cases
Industry solutionEducation and Research Ransomware Response1 cases
Industry solutionFinancial Services Ransomware Response and Recovery2 cases
Industry solution- LynxCase study
Lynx encrypts a leasing company's Oracle ledger and threatens to leak contracts
A leasing company's core accounting Oracle database and regulatory reporting system were encrypted by Lynx, with datafiles, control files and local archived logs all carrying the .LYNX extension while the attacker threatened to publish customer contracts. Measuring the encrypted proportion, restoring the previous night's full backup and rolling archived logs forward returned the books before the reporting deadline.
- Crysis / DharmaCase study
Crysis/Dharma encrypts an insurance agency's OA and file servers
Brute-forced RDP let a Crysis/Dharma .cezar-family variant encrypt an insurance agency's OA and file servers, hitting scanned contracts and customer records. Attachments came back from NAS snapshots, mailboxes and local copies, with the OA database rolled back from an off-site backup.
Retail and E-commerce Ransomware Response3 cases
Industry solution- BrzCryptCase study
BrzCrypt encrypts an e-commerce agency's ERP database and NAS share
A SQL Server instance shared by two ERP account sets, together with a mapped NAS share, was encrypted by BrzCrypt and order processing stopped. NAS snapshot rollback plus page-level extraction restored the core data, and the exposed 3389 port was closed.
- SorryCase study
Sorry encrypts a cross-border e-commerce operator's cPanel servers
Sorry encrypted several cPanel / WHM servers through an authentication bypass, taking down site files and MySQL for more than a dozen storefronts with no public decryptor available. The cluster was rebuilt from offsite backups, a read replica at a second cloud provider, primary-side binlogs, CDN static copies and ERP order data.
- GlobeImposterCase study
GlobeImposter encrypts a retail chain's POS and member databases
GlobeImposter encrypted the head-office SQL Server holding store transaction and member data with an .Ares666 extension, leaving dozens of stores unable to settle sales. Page-level repair plus replayed POS local caches restored the data, and the backup architecture was rebuilt.
Logistics and Supply Chain Ransomware Response1 cases
Industry solutionConstruction and Real Estate Ransomware Response1 cases
Industry solutionGaming & Interactive Entertainment2 cases
Industry solution- QilinCase study
Qilin encrypts a game studio's ESXi version control and build environment
Qilin encrypted a studio's Perforce/GitLab repositories, build machines, internal test servers and art asset servers across three ESXi hosts, deleting VM snapshots and exfiltrating unreleased art and design documents. Recovery combined storage-layer snapshots, VMDK structure repair and developers' local working copies, followed by an exposure assessment and management-plane hardening.
- WeaxorCase study
Weaxor encrypts a game operator's account database
Weaxor encrypted the MS SQL Server holding a mobile game's account and recharge order databases, blocking player logins and payment callbacks. Page-level file repair and transaction log replay restored the data, and the exposed 1433 port was closed.
Blockchain & Crypto2 cases
Industry solution- MedusaCase study
Medusa encrypts a digital asset platform's operations database
Medusa encrypted the SQL Server backend and file server of a digital asset service provider, appending .MEDUSA, while its leak site ran a countdown threatening to publish KYC material. Cold wallets stayed offline and untouched; core data was recovered through page-level repair and log merging, with exposure scoping delivered in parallel.
- INC RansomCase study
INC Ransom encrypts a blockchain firm's ESXi cluster and explorer index database
Hosted chain nodes, validator proxies, the block explorer's PostgreSQL index and the development estate all ran on one ESXi cluster, which INC Ransom's Linux/ESXi encryptor shut down and encrypted. On-chain assets were untouched; recovery centred on resyncing nodes from the chains and restoring the index from immutable offsite backups, with a full audit of signing key custody.