Successful Data Recovery from .flocked Ransomware Attack by Fog

Overview

A client experienced a ransomware attack that encrypted critical business data with the .flocked extension. A cybercriminal group, calling themselves Fog, claimed responsibility for the attack and demanded a ransom for decryption. Thanks to the client’s timely actions and our data recovery expertise, client’s critical data has been partially restored without paying the ransom.

Challenge

“If you're reading this, then you have been the victim of a cyberattack. We call ourselves Fog and we take responsibility for this incident.” — that was the beginning of frightening message on the client’s screen.

Ransomware Data Recovery

The ransomware infected the client’s system, renaming and encrypting files, and made them inaccessible. This virus attack not only threatened business continuity but also created the potential for permanent data loss. Unfortunately, no decryption tools exist for this kind of malware at this time. The client didn’t want to pay the ransom, as even if it were paid, there would be no guarantee of getting the data back, since cybercriminals may not provide decryption tools.

Solution

Our ransomware data recovery strategy involved a comprehensive approach to ensure maximum data retrieval and security.

Ransomware Data Recovery

As the client promptly shut down the server upon discovering the virus, some data had not yet been encrypted. During the investigation of the hard drives, ACE Data Recovery engineers discovered that it was also possible to get access to renamed but not yet encrypted files. Additionally, they were able to recover files from unallocated space, such as temporary files, previous document versions, and deleted files.

Results

As a result of our data recovery efforts, over 5 million of the client’s affected files were recovered, minimizing data loss and ensuring business continuity. The recovery was completed in just a few days — from receiving the drives in our lab for diagnostics, to copying the recovered data to return media, and finally delivering it back to the client.

If you're hit by a ransomware attack, act quickly! Immediately power off your infected system and all computers in your local network and call 877-304-7189 to speak with a data recovery expert.