Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Industry solution

Construction and Real Estate Ransomware Response

In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.

Critical business systems

  • Cost estimating and budgeting software and its databases
  • BIM model repositories and collaborative design platforms
  • CAD drawing shares and project documentation libraries
  • Project management systems and OA collaboration
  • Contract, tender and as-built archive systems
  • Finance and cost management ERP
  • Project-site NAS units, file servers and shared drives
  • Site endpoints and remote working devices

Threat landscape

Information systems in construction and real estate have an unusual shape: the core production asset is files, not database records, and those files are inherently scattered across many project sites, design institutes, subcontractors and personal computers. That creates a distinctive risk set:

  • Project sites are the weak link. A site typically runs one NAS or one Windows server for drawing sharing, on a temporary network, with lagging IT maintenance and simple passwords — and some expose the NAS or RDP directly to the internet so drawings can be retrieved remotely. This is the sector's most common entry point.
  • Overly broad share permissions. For collaboration convenience, drawing directories are often set to everyone-read-write, so one infected endpoint can encrypt an entire project's drawing library along a mapped drive. Public reporting shows the Phobos and Makop lineages, which enter chiefly through weak-password RDP, along with GlobeImposter and Crysis/Dharma, recurring persistently in file-server encryption cases.
  • Many external collaborators. Design institutes, supervisors, subcontractors and suppliers exchange files constantly, and USB drives, cloud shares, email and temporary shared accounts add further risk.
  • Weak backup practice. Many projects hold their drawings in exactly one place on a NAS, with no version retention or offline copy, and the "sync equals backup" misconception is especially widespread here.
  • High irreplaceability. As-built drawings, change orders, site instruction records and tender documents carry legal and settlement value, and cannot readily be reconstructed.

Business impact

  • Construction and design work stops. With drawings and models unavailable, site work, technical briefings, detailed design and change handling all stall, and schedule pressure converts directly into cost.
  • Lost bids and contract risk. Losing tender documents, pricing and technical proposals in preparation can mean missing a submission deadline, while missing contracts, site instructions and change records create disputes at settlement.
  • Difficult settlement and audit. Cost data, bills of quantities, and instruction and variation records are the basis for settlement, and gaps directly affect payment collection and audit clearance.
  • Risk to as-built and archival records. As-built drawings and acceptance documentation are statutory records that must be retained long-term; reconstructing them is extremely costly and may even affect acceptance and filing.
  • Multi-project knock-on. Where project sites share one credential scheme, or head office provides shared storage, one incident can affect several live projects simultaneously.
  • Exposure of knowledge assets. Leaked design proposals, cost models, supplier pricing and contract terms damage competitive position and commercial relationships.

Our response plan

  1. Stop writing and inventory dispersed storage

    Immediately disconnect affected NAS units, file servers and endpoints from the network. The single most important action is to stop all writes to the storage, since that directly determines how much of the deleted originals can be carved back. Never reset a NAS, rebuild its RAID or initialise its storage pool. Then inventory every location that may hold drawings and project documentation: site NAS units, head office file servers, designers' computers, external drives, cloud sync folders, and copies held by collaborators.

  2. Identify the family and assess encryption by file type

    Identify the family and entry point, focusing on internet-exposed NAS units and RDP, weak site passwords and external collaborator accounts. At the same time, sample entropy by file type: BIM models, point clouds, render files, video and archives are large and often only header- or segment-encrypted, carrying real repair value, while DWG drawings, Office documents and PDFs are mid-sized or small and usually fully encrypted, depending instead on backups, snapshots and carving. That classification drives both the recovery plan and the effort estimate.

  3. Prioritise by project value and urgency

    Agree a priority list with each project lead rather than working through directories in order. The usual sequence: live tender documents and pricing near deadline, then current-revision drawings and change records for projects under construction, then settlement and site instruction records, then as-built and archival material, then historical projects and reference material. This restores the most urgent work first and gives recovery a concrete acceptance standard — named projects and named drawing packages.

  4. Recover from multiple sources and verify drawing revisions

    Use every source at once: read-only NAS snapshots and backups, carving of deleted originals, partial-encryption repair on large files, and distributed copies — designers' local folders, cloud version history, email attachments, the same files held by collaborators (design institutes, supervisors, subcontractors), and printed or plotted archives. Afterwards, verify revisions: confirm whether each drawing is the current or a superseded version, so construction does not proceed on the wrong one. The project's technical lead must take part in that verification.

  5. Govern project-site IT and rebuild backups

    Hardening centres on bringing project sites — the management blind spot — into unified governance: keep NAS units and servers off the public internet, enable read-only or immutable snapshots, minimise share permissions by project and role, deploy EDR and patching uniformly on endpoints, and move remote access to VPN. The backup architecture must cover every project drawing library with version history and at least one offline or immutable copy, and a standard channel for exchanging files with collaborators should replace ad hoc USB drives and temporary shared accounts.

Common ransomware families

Hardening recommendations

  • Never expose project-site NAS units or servers to the internet. Remove router port forwards and UPnP and route remote drawing access through a VPN. This is the sector's principal entry point and also its easiest fix.
  • Enable read-only or immutable snapshots. Turn on snapshots with a sensible retention period on the NAS, and use immutable snapshots where available — they sit outside the permission scope of the encrypted filesystem and are the most effective single defence for a drawing library.
  • Minimise share permissions by project and role. Remove Everyone / Full Control, make archive and as-built directories read-only, and scope read-write access by role on live projects — directly shrinking the reach of any single encryption run.
  • Backup cannot mean sync. Cloud sync and real-time NAS sync push encrypted files off-site; use versioned backup with retention, and keep one offline copy such as an external drive detached between runs.
  • Manage endpoints centrally. Bring designers' and estimators' computers into central patch and EDR management, remove unnecessary local administrator rights, and restrict automatic execution from unknown USB devices.
  • Govern remote access and accounts. Remove internet-facing RDP in favour of VPN with MFA, issue collaborators time-limited accounts, and revoke them when the project ends.
  • Standardise file exchange with collaborators. Use a single file exchange platform or controlled shared directory instead of permanently open shared accounts and casual USB copying.
  • Keep critical records in more than one place. For as-built drawings, site instructions and contracts with legal and settlement value, retain paper or offline archives alongside electronic backups, with a named custodian.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

FAQ

Frequently asked questions

  • An entire project's drawings are encrypted — how much can be recovered?

    The rate varies sharply by file type, so a single figure is meaningless. The general pattern: large files — BIM models, point clouds, renders, video, archives — have more room, because many families encrypt only headers or segments above a size threshold. DWG drawings and Office documents are mid-sized or small and usually fully encrypted, depending instead on read-only snapshots, backups, carving of deleted originals, and distributed copies. During assessment we sample encryption coverage by file category and set expectations per project and per drawing package, rather than quoting one percentage.

  • The site NAS is encrypted — can we reset it or rebuild the RAID?

    Absolutely not. Resetting the device, rebuilding the RAID or initialising the storage pool genuinely erases the underlying data and turns a recoverable case into an unrecoverable one — the most common and most fatal mistake in this sector. The correct approach: remove port forwards at the router, disconnect, leave the device untouched with no writes, and record the original drive slot order. Where low-level work is needed, a team with NAS experience takes read-only block-level images, reassembles the array on the copies, and evaluates snapshots, carving and the repair value of the encrypted files.

  • We are mid-tender and the drawings and bid documents are gone — what now?

    Run two things in parallel. On recovery, make the tender files the highest priority and concentrate on snapshots, backups and distributed copies — bid documents very often exist on the handler's computer, in sent-mail records, in cloud version history, and as attachments in correspondence with design institutes and subcontractors, which in practice is the fastest route to recovering them. On the business side, assess in parallel whether to inform the tendering party, request an extension or adjust your bid strategy. With a deadline looming, both tracks must run together rather than waiting for recovery to finish.

  • How do we confirm recovered drawings are the current revision?

    Revision verification is a mandatory step here, because building to the wrong revision can be worse than losing the drawing. Available references include the revision block and date on the drawing itself, change orders and technical clarification records, receipt logs from the supervisor and client, printed copies in use on site, the same file held by collaborators, and issue records in the project management system or OA. After recovery, the project's technical lead should confirm each drawing package, and anything whose revision cannot be established should be explicitly flagged with a plan to verify it.

  • Several project sites use NAS units — how do we protect them consistently?

    The practical answer is to bring project-site IT under a head office standard rather than relying on local maintenance. A minimum viable set of requirements: keep the NAS off the public internet (remove port forwards and UPnP); disable the default administrator and enforce strong passwords with two-factor authentication; enable read-only or immutable snapshots with a retention period; minimise share permissions by role; keep backup job destinations off the device with an offline copy retained; and update firmware and packages regularly. Combined with a head office asset register and periodic checks, that substantially reduces the sector's principal risk.

Updated