Victim Q&A · Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
Short answer
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
Key points
- The initial conversation and first read on the family are free; whether and how a full recoverability assessment is charged is stated and confirmed with you before it starts.
- No phone quotes: assessment first, then a written quotation covering scope, deliverables and expected timing, and work begins after confirmation.
- Cost follows effort: service type, data volume and system count, recovery difficulty, remote or on site, and time requirements.
- Timing comes in stages: hours for a first family read, one to several business days for full assessment, one to several days for a single file server, several days to a week or two for a whole virtualization platform.
- Corporate settlement with invoices; no cryptocurrency, no ransom payment service, and findings are never withheld as leverage.
- Be wary of quotes given without seeing the environment, promises of 100% decryption, deposits before samples are examined, personal-account or crypto-only payment, and prices tied to the ransom.
In this order
What to do now
Contain first, then ask for quotes
Before shopping for quotes, follow what to do after a ransomware attack: isolate without powering off, rebooting or reinstalling, and pause automated backup and sync jobs that could overwrite data. The earlier containment happens, the larger the recoverable scope usually is - and the more predictable cost and timing become.
Prepare the ransom note and two or three encrypted samples
Ordinary files with no sensitive content are enough. Without them there is no way to establish the family and version or check for a public decryptor - the first input into any estimate of cost and time. You can also start with the identification tool.
Describe the affected scope
Host count and system types (file servers, databases, virtualization, NAS, endpoints), approximate data volume, which backups and snapshots survive, and what has been done since discovery: reboots, antivirus cleanup, recovery software, any contact with the attackers. The more accurate this is, the faster assessment goes.
Set business priorities and time requirements
Which systems must come back first, whether staged return is acceptable, and whether overnight work with parallel staffing is needed. Time requirements are themselves a cost factor, so stating them early avoids changes later. For databases, see database encrypted by ransomware.
Confirm how the work will be done
Whether remote access is possible, whether the environment is classified or fully air-gapped, and whether physical media are damaged. Whether an on-site visit is needed, and how it divides with remote work, is settled during assessment - not added later.
Decide on the written assessment and quotation
Check scope, deliverables, expected timing and acceptance criteria, then confirm before work starts. At no point do you have to pay before learning the family identification.
Avoid making it worse
Do not
- Do not keep rebooting servers, starting the database service or running recovery software just to get a price. Every write can shrink the recoverable scope and make later repair slower and more expensive.
- Do not hand the original disks to several providers to try their luck while you compare prices. Comparison needs only the note, samples and a description of the environment; keep the originals read-only.
- Do not pay a deposit or good-faith fee before the provider has even examined samples, and do not accept full payment as a condition for learning the family identification.
- Do not use a service whose price moves with the ransom, whose timing depends on the other side replying, or that takes only personal accounts or cryptocurrency - it is very likely paying the ransom for you.
- Do not skip verification to hit a date and put unverified data straight back into production.
- Do not choose on price alone. If the quotation does not define scope, deliverables and acceptance, there is nothing to hold on to when extra charges appear.
What determines the cost of ransomware decryption?
A quote given before we understand the environment is meaningless, so we do not quote over the phone. "Ransomware decryption" can mean files on a few office PCs or an entire virtualization platform, and those are not the same order of magnitude. These are the main drivers of cost and duration:
| Factor | Effect on cost | Effect on time |
|---|---|---|
| Family, version and whether decryption is possible | With a matching public decryptor, effort centres on version checks and bulk verification; without one, backups, repair or remnant extraction add substantial work | Fastest when a tool applies; file-by-file repair is slowest |
| Host count and data volume | One file server and a whole virtualization platform are different orders of magnitude | Read-only imaging, copying and verification all scale with volume |
| Database repair complexity | Page-level repair, log replay and cross-system reconciliation take a lot of checking | Usually several days; longer for very large instances |
| Virtual machine disks | Large disks need encryption coverage mapped before partitions and file systems are rebuilt | Several days to a week or two for multiple VMs |
| State of backups and snapshots | A clean backup or snapshot is the shortest path | Roll back to the snapshot, then fill in later changes |
| Remote or on site | Damaged media, classified or air-gapped environments and on-site evidence preservation require a visit | Remote work usually reaches substantive response faster |
| Time requirements | Overnight work and parallel staffing add effort | Can shorten recovery of critical systems |
| Forensics and hardening scope | A forensic report and hardening are separate pieces of work | Several business days for a report when evidence is complete; days to weeks for hardening |
Two further points. First, whether decryption is possible depends on the family and version, not on how much you pay. Free tools collected by No More Ransom and similar projects cover specific builds of some families only; for most mainstream families there is no way to break the encryption unless keys are exposed, and the budget goes on backup restoration and data repair instead. Second, the encryption method shapes repair effort. SentinelLabs research from September 2022 documented BlackCat, PLAY, Black Basta and others advertising or using intermittent encryption - encrypting only part of each file for speed. That leaves room to repair large files, but coverage has to be mapped by entropy analysis first, and mapping large databases and virtual disks takes time in itself.
How is a quote produced, and is assessment charged?
Our process has three stages, each explained before it starts:
- Initial read (free). Send the ransom note text and the appended extension and we tell you which family it is likely to be, whether a public decryptor exists, which recovery paths are worth checking, and what to do and avoid right now.
- Full recoverability assessment. This needs access to the environment, read-only imaging, and trial repairs and path validation on copies. Whether and how it is charged depends on the scope of work; we state that clearly and get your confirmation before starting, and never do the work first and discuss it afterwards.
- Written quotation and implementation. After assessment we issue a written quotation stating scope, deliverables and expected timing, and work starts only once both sides confirm. Changes in scope are handled through a written change order.
The assessment explains what can be recovered, what cannot, and why. Where the conclusion is that data is unrecoverable, we do not continue with recovery work that has no substantive prospect of success.
Whichever provider you use, check these items on the quotation:
- Scope: which hosts and systems, to what degree, and whether forensics and hardening are included.
- Deliverables: a recovered-data manifest, verification checklist, operation log, forensic report.
- Timing: ranges by stage, not a vague "as soon as possible".
- Acceptance: what counts as recovery complete, and how confirmed losses are listed.
- Payment milestones and method: corporate settlement and whether invoices are issued.
Our payment milestones, methods and invoicing follow the contract or quotation and are settled through corporate channels. We do not accept cryptocurrency and provide no form of ransom payment. Family identification and assessment findings are never withheld as leverage: you decide whether to engage us after you know what can be recovered, roughly how long it will take and roughly what it will cost. The full stage-by-stage description is on our process page.
How long does recovery take, and where does the time go?
It breaks down by stage, and actual timing depends on data volume, environment complexity and the state of backups:
| Stage | What happens | Typical range |
|---|---|---|
| Intake and containment guidance | Establish the affected scope and issue containment steps such as isolation without reboots | Intake runs 24/7 and we respond quickly |
| Initial family and version identification | Identify the family from the note and samples and check for a public decryptor | Usually hours, depending on how quickly samples arrive |
| Full recoverability assessment | Read-only imaging, encryption coverage mapping, backup and snapshot checks, trial repairs | One to several business days; longer for large or complex environments |
| Recovery: single file server | Decryption, repair or restoration on copies | One to several days |
| Recovery: file-level database repair | Page-level repair, log replay, table-by-table reconciliation | Several days; longer for very large instances |
| Recovery: multiple VMs or a whole virtualization platform | Disk mapping, rebuilds and staged restoration | Several days to a week or two |
| Verification and acceptance | Sampled file-open checks, database consistency checks, business acceptance | Never skipped to hit a date |
| Forensics and hardening (as needed) | Forensic report; hardening in phases by scope | Several business days for a report when evidence is complete; days to weeks for hardening |
The time goes to three places. First, moving data: every repair happens on copies, and imaging and copying terabytes takes time in its own right. Second, repair and extraction: intermittently encrypted large files are mapped and then extracted segment by segment, and databases are reconciled table by table. Third, verification: putting unverified data into production typically causes longer downtime and harder-to-fix inconsistencies, so we do not cut this step.
What speeds recovery up: early containment; the note and samples ready; usable backups or snapshots (66% of organisations whose data was encrypted recovered from backups in Sophos's 2026 survey); quick business decisions on priority, bringing production and finance systems back first and secondary data in later batches; remote access ready and a contact who can make decisions.
What slows it down: repeated reboots and reinstalls that close off recovery paths; missing logs that make it impossible to confirm whether encryption is still spreading; backups encrypted as well; and restored systems reconnected to production before the entry point is closed, only to be encrypted again. For the order of work on servers see what to do when a server is hit, and if backups were destroyed too see backups deleted or encrypted.
Low-price lures, upfront deposits, ransom brokers: what to avoid when getting quotes
Victims usually look for help when they are most rushed and least informed, which is exactly when sales scripts work best. Be cautious about the following:
- A quote without looking at the environment, or a fixed price over the phone. Without samples, a family or data volumes, any figure is only there to get you on board; watch for extra charges later for "added difficulty" or "databases cost extra".
- Promises of 100% decryption or guaranteed recovery. Whether decryption is possible depends on the family and version, and no provider can guarantee it. If someone claims to crack the newest builds of families with no public tool, ask exactly how.
- A deposit or good-faith fee before samples have been examined, or full payment before the family identification is disclosed. Identification needs only the note and a few samples, so there is no reason to make it conditional on payment. If an assessment stage is chargeable, its scope and deliverables should be set out in writing beforehand.
- Payment only to a personal account or in cryptocurrency. Legitimate providers settle through corporate accounts and issue invoices.
- A price that moves with the ransom and timing that depends on the other side replying. These are hallmarks of a ransom broker: a decryption service on the surface that in fact contacts the attackers, pays the ransom and adds a margin. In ProPublica's 2019 investigation, the US firm MonsterCloud quoted one client US$25,000 where the ransom was about US$7,000, and China's Ministry of Public Security warned in September 2026 against trusting online decryption tools or decryption agents to avoid being defrauded twice. The risks are the same as paying the ransom yourself; how to tell the difference is covered in should we pay the ransom.
One more trap is easy to miss: giving the original disks to several providers to try while you compare prices. Every attempt on the original can write data and overwrite remnants, until nobody can repair it. Comparing providers is fine - but give them only the note, samples and a description of the environment, and keep the original disks read-only.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- First response
What should we do when a server is hit by ransomware?
Isolate first and do not reboot: cut the affected server off at the switch or in the cloud security group, but leave it running. Then snapshot or image the system and data disks, keep the ransom note and encrypted samples, and check read-only whether shadow copies, cloud snapshots and backups survived. If several servers are down, set a restore order by business dependency, and bring nothing back online until the entry point is closed and every credential has been changed. What can be recovered depends on the family, the encryption mode and the backups.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
Related solutions
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related services
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
FAQ
Follow-up questions
Can you at least give a rough price range?
No, and not to be evasive. An attack affecting a few PCs and one affecting an entire virtualization platform are different orders of magnitude, and whether usable backups exist, whether the database can be repaired and whether a site visit is needed all change the answer substantially. A figure given before we understand the environment is either wrong or just bait. Instead, the initial conversation and first read on the family are free, and after assessment you receive a written quotation, so you decide knowing what can be recovered, roughly how long it will take and roughly what it will cost.
If the assessment finds the data cannot be recovered, do we still pay?
The initial conversation and first read on the family are free. A full recoverability assessment involves access to the environment, read-only imaging and trial repairs; whether and how it is charged is made clear and confirmed with you before it starts, never afterwards. Whatever the conclusion, we explain what can be recovered, what cannot and why, and where data is unrecoverable we do not continue with recovery work that has no substantive prospect of success.
Why do some firms quote very low and promise same-day decryption?
Same-day decryption is only realistic when a matching public decryptor exists and data volumes are modest. A same-day promise for a family with no public tool means either a quote made without examining samples, or a provider that actually contacts the attackers and pays - in which case timing depends on their reply and the price includes the ransom. Ask three things: what method will be used; whether it can be demonstrated on files you choose, including large files and databases; and whether the contract states that no contact will be made with, and no payment made to, the attackers.
How does payment work - is full payment required up front?
Payment milestones, methods and invoicing follow the contract or quotation, settled through corporate channels with invoices issued. We do not accept cryptocurrency and provide no ransom payment or purchase service. Family identification and assessment findings are never withheld as leverage, so there is no pay-first-then-hear-the-result arrangement.
Does an incident at night or at the weekend change the response or the cost?
Intake runs 24/7, including nights and holidays. On cost, what changes the effort is the time requirement itself: if overnight work and parallel staffing are needed to bring core systems back fast, the workload rises accordingly, and that is set out and confirmed with you at the assessment and quotation stage. If the business can accept staged recovery at a normal pace, that extra effort is not needed.
Can the most critical systems be restored first and the rest later?
Yes, and we recommend it. Recovery is prioritised by business importance: production and finance systems first, secondary data and historical archives afterwards, so core operations resume sooner - though every batch is verified before handover. Do not reconnect restored systems to production until credentials are rotated and security checks are done; with the entry point still open, the time and money spent can be wasted. See why ransomware keeps coming back and our hardening service.
Sources
- 文件加密、索要赎金!勒索病毒来了,这份企业防护指南请收好(2026-09-04,「不要轻信网上解密工具、解密代理,谨防二次被骗」)— 公安部网安局 / 中国新闻网
- The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers(2019-05-15,MonsterCloud 报价 2.5 万美元、对应赎金约 7,000 美元)— ProPublica
- Decryption Tools(免费解密工具只覆盖部分家族的特定版本)— No More Ransom
- Crimeware Trends: Ransomware Developers Turn to Intermittent Encryption to Evade Detection(2022-09-08)— SentinelLabs
- The State of Ransomware 2026(数据被加密的组织 66% 通过备份恢复)— Sophos
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated