Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Victim Q&A · Ransom & cost

How much does ransomware decryption cost, and how long does recovery take?

Short answer

There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.

Key points

  • The initial conversation and first read on the family are free; whether and how a full recoverability assessment is charged is stated and confirmed with you before it starts.
  • No phone quotes: assessment first, then a written quotation covering scope, deliverables and expected timing, and work begins after confirmation.
  • Cost follows effort: service type, data volume and system count, recovery difficulty, remote or on site, and time requirements.
  • Timing comes in stages: hours for a first family read, one to several business days for full assessment, one to several days for a single file server, several days to a week or two for a whole virtualization platform.
  • Corporate settlement with invoices; no cryptocurrency, no ransom payment service, and findings are never withheld as leverage.
  • Be wary of quotes given without seeing the environment, promises of 100% decryption, deposits before samples are examined, personal-account or crypto-only payment, and prices tied to the ransom.

In this order

What to do now

  1. Contain first, then ask for quotes

    Before shopping for quotes, follow what to do after a ransomware attack: isolate without powering off, rebooting or reinstalling, and pause automated backup and sync jobs that could overwrite data. The earlier containment happens, the larger the recoverable scope usually is - and the more predictable cost and timing become.

  2. Prepare the ransom note and two or three encrypted samples

    Ordinary files with no sensitive content are enough. Without them there is no way to establish the family and version or check for a public decryptor - the first input into any estimate of cost and time. You can also start with the identification tool.

  3. Describe the affected scope

    Host count and system types (file servers, databases, virtualization, NAS, endpoints), approximate data volume, which backups and snapshots survive, and what has been done since discovery: reboots, antivirus cleanup, recovery software, any contact with the attackers. The more accurate this is, the faster assessment goes.

  4. Set business priorities and time requirements

    Which systems must come back first, whether staged return is acceptable, and whether overnight work with parallel staffing is needed. Time requirements are themselves a cost factor, so stating them early avoids changes later. For databases, see database encrypted by ransomware.

  5. Confirm how the work will be done

    Whether remote access is possible, whether the environment is classified or fully air-gapped, and whether physical media are damaged. Whether an on-site visit is needed, and how it divides with remote work, is settled during assessment - not added later.

  6. Decide on the written assessment and quotation

    Check scope, deliverables, expected timing and acceptance criteria, then confirm before work starts. At no point do you have to pay before learning the family identification.

Avoid making it worse

Do not

  • Do not keep rebooting servers, starting the database service or running recovery software just to get a price. Every write can shrink the recoverable scope and make later repair slower and more expensive.
  • Do not hand the original disks to several providers to try their luck while you compare prices. Comparison needs only the note, samples and a description of the environment; keep the originals read-only.
  • Do not pay a deposit or good-faith fee before the provider has even examined samples, and do not accept full payment as a condition for learning the family identification.
  • Do not use a service whose price moves with the ransom, whose timing depends on the other side replying, or that takes only personal accounts or cryptocurrency - it is very likely paying the ransom for you.
  • Do not skip verification to hit a date and put unverified data straight back into production.
  • Do not choose on price alone. If the quotation does not define scope, deliverables and acceptance, there is nothing to hold on to when extra charges appear.

What determines the cost of ransomware decryption?

A quote given before we understand the environment is meaningless, so we do not quote over the phone. "Ransomware decryption" can mean files on a few office PCs or an entire virtualization platform, and those are not the same order of magnitude. These are the main drivers of cost and duration:

FactorEffect on costEffect on time
Family, version and whether decryption is possibleWith a matching public decryptor, effort centres on version checks and bulk verification; without one, backups, repair or remnant extraction add substantial workFastest when a tool applies; file-by-file repair is slowest
Host count and data volumeOne file server and a whole virtualization platform are different orders of magnitudeRead-only imaging, copying and verification all scale with volume
Database repair complexityPage-level repair, log replay and cross-system reconciliation take a lot of checkingUsually several days; longer for very large instances
Virtual machine disksLarge disks need encryption coverage mapped before partitions and file systems are rebuiltSeveral days to a week or two for multiple VMs
State of backups and snapshotsA clean backup or snapshot is the shortest pathRoll back to the snapshot, then fill in later changes
Remote or on siteDamaged media, classified or air-gapped environments and on-site evidence preservation require a visitRemote work usually reaches substantive response faster
Time requirementsOvernight work and parallel staffing add effortCan shorten recovery of critical systems
Forensics and hardening scopeA forensic report and hardening are separate pieces of workSeveral business days for a report when evidence is complete; days to weeks for hardening

Two further points. First, whether decryption is possible depends on the family and version, not on how much you pay. Free tools collected by No More Ransom and similar projects cover specific builds of some families only; for most mainstream families there is no way to break the encryption unless keys are exposed, and the budget goes on backup restoration and data repair instead. Second, the encryption method shapes repair effort. SentinelLabs research from September 2022 documented BlackCat, PLAY, Black Basta and others advertising or using intermittent encryption - encrypting only part of each file for speed. That leaves room to repair large files, but coverage has to be mapped by entropy analysis first, and mapping large databases and virtual disks takes time in itself.

How is a quote produced, and is assessment charged?

Our process has three stages, each explained before it starts:

  1. Initial read (free). Send the ransom note text and the appended extension and we tell you which family it is likely to be, whether a public decryptor exists, which recovery paths are worth checking, and what to do and avoid right now.
  2. Full recoverability assessment. This needs access to the environment, read-only imaging, and trial repairs and path validation on copies. Whether and how it is charged depends on the scope of work; we state that clearly and get your confirmation before starting, and never do the work first and discuss it afterwards.
  3. Written quotation and implementation. After assessment we issue a written quotation stating scope, deliverables and expected timing, and work starts only once both sides confirm. Changes in scope are handled through a written change order.

The assessment explains what can be recovered, what cannot, and why. Where the conclusion is that data is unrecoverable, we do not continue with recovery work that has no substantive prospect of success.

Whichever provider you use, check these items on the quotation:

  • Scope: which hosts and systems, to what degree, and whether forensics and hardening are included.
  • Deliverables: a recovered-data manifest, verification checklist, operation log, forensic report.
  • Timing: ranges by stage, not a vague "as soon as possible".
  • Acceptance: what counts as recovery complete, and how confirmed losses are listed.
  • Payment milestones and method: corporate settlement and whether invoices are issued.

Our payment milestones, methods and invoicing follow the contract or quotation and are settled through corporate channels. We do not accept cryptocurrency and provide no form of ransom payment. Family identification and assessment findings are never withheld as leverage: you decide whether to engage us after you know what can be recovered, roughly how long it will take and roughly what it will cost. The full stage-by-stage description is on our process page.

How long does recovery take, and where does the time go?

It breaks down by stage, and actual timing depends on data volume, environment complexity and the state of backups:

StageWhat happensTypical range
Intake and containment guidanceEstablish the affected scope and issue containment steps such as isolation without rebootsIntake runs 24/7 and we respond quickly
Initial family and version identificationIdentify the family from the note and samples and check for a public decryptorUsually hours, depending on how quickly samples arrive
Full recoverability assessmentRead-only imaging, encryption coverage mapping, backup and snapshot checks, trial repairsOne to several business days; longer for large or complex environments
Recovery: single file serverDecryption, repair or restoration on copiesOne to several days
Recovery: file-level database repairPage-level repair, log replay, table-by-table reconciliationSeveral days; longer for very large instances
Recovery: multiple VMs or a whole virtualization platformDisk mapping, rebuilds and staged restorationSeveral days to a week or two
Verification and acceptanceSampled file-open checks, database consistency checks, business acceptanceNever skipped to hit a date
Forensics and hardening (as needed)Forensic report; hardening in phases by scopeSeveral business days for a report when evidence is complete; days to weeks for hardening

The time goes to three places. First, moving data: every repair happens on copies, and imaging and copying terabytes takes time in its own right. Second, repair and extraction: intermittently encrypted large files are mapped and then extracted segment by segment, and databases are reconciled table by table. Third, verification: putting unverified data into production typically causes longer downtime and harder-to-fix inconsistencies, so we do not cut this step.

What speeds recovery up: early containment; the note and samples ready; usable backups or snapshots (66% of organisations whose data was encrypted recovered from backups in Sophos's 2026 survey); quick business decisions on priority, bringing production and finance systems back first and secondary data in later batches; remote access ready and a contact who can make decisions.

What slows it down: repeated reboots and reinstalls that close off recovery paths; missing logs that make it impossible to confirm whether encryption is still spreading; backups encrypted as well; and restored systems reconnected to production before the entry point is closed, only to be encrypted again. For the order of work on servers see what to do when a server is hit, and if backups were destroyed too see backups deleted or encrypted.

Low-price lures, upfront deposits, ransom brokers: what to avoid when getting quotes

Victims usually look for help when they are most rushed and least informed, which is exactly when sales scripts work best. Be cautious about the following:

  • A quote without looking at the environment, or a fixed price over the phone. Without samples, a family or data volumes, any figure is only there to get you on board; watch for extra charges later for "added difficulty" or "databases cost extra".
  • Promises of 100% decryption or guaranteed recovery. Whether decryption is possible depends on the family and version, and no provider can guarantee it. If someone claims to crack the newest builds of families with no public tool, ask exactly how.
  • A deposit or good-faith fee before samples have been examined, or full payment before the family identification is disclosed. Identification needs only the note and a few samples, so there is no reason to make it conditional on payment. If an assessment stage is chargeable, its scope and deliverables should be set out in writing beforehand.
  • Payment only to a personal account or in cryptocurrency. Legitimate providers settle through corporate accounts and issue invoices.
  • A price that moves with the ransom and timing that depends on the other side replying. These are hallmarks of a ransom broker: a decryption service on the surface that in fact contacts the attackers, pays the ransom and adds a margin. In ProPublica's 2019 investigation, the US firm MonsterCloud quoted one client US$25,000 where the ransom was about US$7,000, and China's Ministry of Public Security warned in September 2026 against trusting online decryption tools or decryption agents to avoid being defrauded twice. The risks are the same as paying the ransom yourself; how to tell the difference is covered in should we pay the ransom.

One more trap is easy to miss: giving the original disks to several providers to try while you compare prices. Every attempt on the original can write data and overwrite remnants, until nobody can repair it. Comparing providers is fine - but give them only the note, samples and a description of the environment, and keep the original disks read-only.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related questions

Related solutions

FAQ

Follow-up questions

  • Can you at least give a rough price range?

    No, and not to be evasive. An attack affecting a few PCs and one affecting an entire virtualization platform are different orders of magnitude, and whether usable backups exist, whether the database can be repaired and whether a site visit is needed all change the answer substantially. A figure given before we understand the environment is either wrong or just bait. Instead, the initial conversation and first read on the family are free, and after assessment you receive a written quotation, so you decide knowing what can be recovered, roughly how long it will take and roughly what it will cost.

  • If the assessment finds the data cannot be recovered, do we still pay?

    The initial conversation and first read on the family are free. A full recoverability assessment involves access to the environment, read-only imaging and trial repairs; whether and how it is charged is made clear and confirmed with you before it starts, never afterwards. Whatever the conclusion, we explain what can be recovered, what cannot and why, and where data is unrecoverable we do not continue with recovery work that has no substantive prospect of success.

  • Why do some firms quote very low and promise same-day decryption?

    Same-day decryption is only realistic when a matching public decryptor exists and data volumes are modest. A same-day promise for a family with no public tool means either a quote made without examining samples, or a provider that actually contacts the attackers and pays - in which case timing depends on their reply and the price includes the ransom. Ask three things: what method will be used; whether it can be demonstrated on files you choose, including large files and databases; and whether the contract states that no contact will be made with, and no payment made to, the attackers.

  • How does payment work - is full payment required up front?

    Payment milestones, methods and invoicing follow the contract or quotation, settled through corporate channels with invoices issued. We do not accept cryptocurrency and provide no ransom payment or purchase service. Family identification and assessment findings are never withheld as leverage, so there is no pay-first-then-hear-the-result arrangement.

  • Does an incident at night or at the weekend change the response or the cost?

    Intake runs 24/7, including nights and holidays. On cost, what changes the effort is the time requirement itself: if overnight work and parallel staffing are needed to bring core systems back fast, the workload rises accordingly, and that is set out and confirmed with you at the assessment and quotation stage. If the business can accept staged recovery at a normal pace, that extra effort is not needed.

  • Can the most critical systems be restored first and the rest later?

    Yes, and we recommend it. Recovery is prioritised by business importance: production and finance systems first, secondary data and historical archives afterwards, so core operations resume sooner - though every batch is verified before handover. Do not reconnect restored systems to production until credentials are rotated and security checks are done; with the entry point still open, the time and money spent can be wasted. See why ransomware keeps coming back and our hardening service.