Akira Ransomware Shut Down an Entire Business. We Had It Operating Again Within a Week.
Every server was affected. The company’s backups had also been encrypted. Normal operations had stopped, and the business believed paying the ransom might be its only way to recover.
That was the situation when the company contacted Blue Network after an Akira ransomware attack. They asked whether we could help before they made a decision about payment.
Within one week, the business was operating again. Based on our current assessment, we recovered approximately 95% of its data.
From a company-wide shutdown to recovery
The attack affected the company’s servers and virtual machines, including systems holding essential business data. Our first priority was to contain the incident and identify what was needed to get the company working again.
At the same time, we examined the affected storage to determine what could be recovered. A virtual machine that no longer starts can still contain valuable data. In this case, that distinction made a substantial difference.
From four affected virtual disk images, our team extracted more than one million files totaling approximately 845 GB. Over 181,000 files passed the available format validation checks. Work on additional images and checks of recovered files continued alongside the restoration of business operations.
The company was able to resume operations within a week of being shut down by the attack.
Do you have to pay a ransomware demand?
When servers and backups have both been encrypted, a ransom demand can appear to be the only remaining option. But before making that decision, a business needs to know what data is still available and what can realistically be restored.
The answer varies by incident. Akira, LockBit, Play, Conti and other ransomware families can affect systems differently. The condition of the servers, available evidence and actions taken after discovery also matter. Our result in this Akira case shows what was possible in this incident, though no recovery team can promise the same outcome in every case.
It does show why an expert assessment is worth making before writing off the data.
What to do if your company has been attacked
Isolate affected systems from the network immediately. Disconnect Ethernet and Wi-Fi to help contain the incident, then seek incident response assistance before rebuilding servers or making further changes to the affected storage.
Preserving the available evidence gives a recovery team the best opportunity to establish what happened, identify usable data and plan the route back to operation.
Contact Blue Network
If ransomware has shut down your business or encrypted your servers and backups, contact us for an assessment. Blue Network can help contain the incident, evaluate the affected systems, prioritize the data and services your business needs most, and determine what recovery options are available.
Before you decide that paying the ransom is your only option, find out what can still be recovered.
Call (949) 287-3374 or email info@bluenetworkinc.com