← Back to work
Incident Response & Recovery — Case Study

Two ransomware attacks in three months.

A multi-site medical practice had been encrypted twice in three months. Their IT provider gave the same answer both times — restore and carry on — but couldn’t say how it got in, or whether patient data had left. They called us for a second look.

Twice
encrypted in three months — same advice both times from their previous provider
72 hrs
staged, verified restoration — access brought back one tier at a time, not all at once
Account won
they moved off their previous IT provider to Lordeus Pro

01 The situation

They had been encrypted twice in three months. The second time, their existing IT provider gave the same answer as the first: restore from backup and carry on. Nobody could tell them how it got in, whether patient data had left the building, or why it had happened again.

They called us after the second event. Days into the first discovery call, they asked for a second team to look at what was actually going on. That is usually the moment an owner stops asking “can you fix it” and starts asking “does anyone here know what they’re doing.”

02 What was actually wrong

Not the malware. The arrangement around it. Their backups were reachable using the same credentials as their live systems, so whoever held an administrator account held the backups too. Retention was short enough that by the time anyone noticed the encryption, the clean copies had already rotated out. And nobody had ever restored from them, so the recovery time they had been quoted was a guess.

None of that is unusual. It is what most small and mid-size organizations have — right up until the day it matters.

“A backup you have never restored from is a theory.”

03 What we did

  • Contained before investigating. Locked the affected shares at network, share and file level. A share that stays writable while somebody analyzes it is still being encrypted.
  • Checked what recovery was actually possible before choosing a strategy — the backup history first, not last.
  • Found the carrier. Encrypted files stop matching their own format internally. Reading file headers against their declared type identified every affected file, and ordering those by timestamp pointed back to the first one — the entry point.
  • Removed, restored, then verified the restore. Destroyed the infected content rather than cleaning it, restored from the last copy predating the carrier, then scanned the restored data before it went back into service. If the infection predates your restore point, recovery reintroduces it — which is why this practice had been hit twice.
  • Brought access back one layer at a time, across 72 hours. Under real pressure to switch everything on at once. Staged restoration means that if something is missed, it surfaces in one tier rather than across every site.
  • Established whether data had left. Sign-in records, file-access history, mail-forwarding rules, outbound traffic in the preceding weeks. For a practice holding patient records, that finding decides whether they are cleaning up or notifying people — a different cost and a different legal clock.

04 What they got

A recovered environment, and the thing their previous provider had never given them: a written backup, recovery and incident-management plan. Retention designed to outlast how long an attacker actually sits inside a network. At least one copy their production systems cannot reach. Restore testing on a schedule, against a separate system, with the recovery time measured rather than estimated.

And a named decision for the owner rather than a technical default — how often copies are taken, priced, so the business could choose how much work it was willing to lose. They moved their account to us.

What the practice walked away with

A recovered environment, a recovery plan they can actually trust, and a clear answer to the one question that decides what an attack costs: when was the last successful full restore, and how long did it take.

05 The part worth stealing

Most ransomware conversations are about prevention, and prevention matters. But a determined attacker gets in eventually, and the thing that decides what it costs you is whether your recovery works.

“The gap between a bad afternoon and a business-altering event is almost always the difference between a backup strategy that was designed and tested, and one that was assumed.”

Worried your recovery has never been tested?

If nobody at your organization can say when the last successful full restore was — and how long it took — that is the answer. The first call is free.

Book a free 15-minute call

Or get the sample recovery plan — the redacted version of the document these clients get.

One email with the download. No spam.

Published with the client’s identity withheld. No client name, patient data, or figures are disclosed.