Data Recovery Case File · NAS & Network Storage · A Mirror Is Not a Backup
Both Copies Were Encrypted, Because Both Are the Same Copy
This enquiry describes an attack rather than a failure. A two-bay network unit in a mirrored configuration holding around a terabyte: "I have had a cyber attack and all my files encrypted into archives — only the larger video files survived. The attacker left a note in every folder saying I have to pay to get the key." Two things are worth separating immediately. The mirror was never going to help, for a reason worth understanding — and the detail about the large files being untouched is not a lucky accident but a known behaviour that points at where to look.
| Media | Two-bay network storage unit in mirrored configuration — user files encrypted by malicious software; larger video files reported unaffected; ransom notes present throughout |
| Reported situation | Network unit in mirrored configuration holding approximately 1TB · files encrypted into archive containers by malicious software · larger video files reported to have survived · ransom notes placed throughout the folder structure · both members affected identically |
| Fault class | Malicious encryption of user data — no device fault; recovery dependent on snapshots, unaffected files and independent backups |
| Equipment used | Unit isolated from the network before any other step · both members imaged write-blocked (Atola TaskForce 2) · appliance snapshot and versioning stores enumerated · unaffected and partially processed files identified by signature · no engagement with the attacker undertaken or advised |
The decode: why the mirror failed him, and the three places to look
The first instruction, before anything technical: disconnect the unit from the network. Malicious software of this kind spreads to whatever it can reach, and a unit still connected can be re-encrypted, can act as a route to other machines, and may still be under active access. Isolation comes first.
Why the mirror offered no protection, and this is the doctrine: a mirror writes the same data to two disks simultaneously so that either can be lost. It protects against a disk failing. It does not protect against anything that happens to the data itself, because whatever happens is written faithfully to both members at the same instant. Deletion, corruption, an accidental overwrite and an encrypting attack all propagate to both copies immediately. Two copies that update together are one copy in two places — which is exactly the property that makes a mirror useful for uptime and useless as a backup.
Why the large video files survived, and what it tells us: not luck. Software of this kind is written to work quickly across as many files as possible before it is noticed, and encrypting a very large file takes time. So many variants skip files above a size threshold entirely, or encrypt only the first portion of them and move on. That is why large media is so often the survivor — and it means files that appear damaged may in fact be intact beyond their first few megabytes, which is worth testing rather than assuming.
The first place to look, and the most likely to succeed — snapshots. Many network appliances take periodic point-in-time snapshots of their volumes, often enabled by default and often forgotten. Those are stored differently from ordinary files and a great deal of malicious software cannot reach them. If snapshots were running, a version of the data from before the attack may simply be there. This should be checked before anything else, and it is the reason to preserve the unit rather than wipe it.
The second — the appliance's own recycle bin or versioning, which some units maintain separately and which is likewise frequently overlooked.
The third — any genuinely independent copy. A drive that was disconnected at the time, a copy on a machine that was switched off, an older backup nobody has thought about. The defining characteristic is that it was not reachable when the attack ran.
On the note in the folders: no engagement with the attacker is undertaken or advised. That is not a technical judgement about outcomes; it is simply not something this bench does or recommends, and it should be reported to the relevant authorities rather than answered.
On the bench
The unit was isolated from the network before any other step, since a connected unit can be re-encrypted, reached again, or serve as a route to other machines. Both members were imaged write-blocked on the Atola TaskForce 2, preserving the state for any later examination. Appliance snapshot and versioning stores were enumerated first — held separately from ordinary files, frequently enabled by default, and often beyond the reach of the software. Unaffected and partially processed files were identified by signature, since large media is commonly skipped or only partly encrypted. No engagement with the attacker was undertaken or advised.
The outcome
The unit isolated, both members imaged and preserved, snapshots and versioning enumerated first and partially affected files identified by signature. Free assessment, one fixed written figure including VAT, no recovery, no fee. The decode, for anyone whose network unit has been encrypted: disconnect it from the network first. Then understand why the mirror did not help — it writes the same data to both disks at once, so it protects against a disk failing and not against anything happening to the data, which is written faithfully to both. Check the appliance's snapshots before anything else, since those are stored separately and are often out of reach. And test the large files, because many are only partly encrypted.
Network storage hit by an encrypting attack
Disconnect the unit from the network before anything else, then check its snapshots. Most network appliances take periodic point-in-time snapshots, often switched on by default and forgotten about, and they're stored separately from ordinary files in a way a lot of malicious software can't reach — so a copy of your data from before the attack may simply be sitting there. Check the appliance's recycle bin and versioning too. Test your large files rather than assuming they're lost: encrypting a big file is slow, so many variants skip them or encrypt only the first portion, which is why large media so often survives. And understand why the mirror didn't help — it writes the same data to both disks at once, so it protects against a disk dying, not against anything happening to your files.
Disconnect it first — call Newcastle Data Recovery on 0191 406 1051; unit isolated, both members imaged write-blocked, snapshots and versioning enumerated before anything else.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.