How One Offline Backup Saved 10 Years of Data
The Day Every File Became an MP3
About five years ago, a ransomware attack brought a small company's entire computer network to a standstill.
I was the company's outside IT person. They paid me a fixed monthly fee to manage their computers, network, and backups. I had been looking after their system for years.
It started with a phone call on a Friday morning.
"Something's wrong with our files. They've all turned into music files."
Music files? I knew immediately this wasn't going to be a normal Friday.
I told the employee not to touch anything and drove straight to the office.
When I arrived, the problem was already spreading.
One employee had opened an email attachment that looked harmless. Within minutes, JPGs, GIFs, DOCX files, and almost everything else had been encrypted. The files had strange new extensions, and none of them would open.
The company's computers were all connected to the same network.
That was the problem.
The ransomware moved from one computer to another, faster than anyone realized. Even the owner's computer was infected.
Ten years of business records were suddenly locked. Then we found the ransom note.
The hacker wanted US$600.
For a few minutes, nobody said much. The owner looked at me.
"Should we just pay it?"
I shook my head.
"Let's see what we have first."
I had always followed the 3-2-1 backup rule: three copies of the data, on two different types of storage, with one copy kept offline.
It sounded almost too simple. That morning, it didn't feel simple at all. The backups connected to the network had been infected too.
For a moment, it looked like the company's ten years of data were gone. Then I remembered one old external hard drive.
After each scheduled backup, I had physically disconnected it from the network and put it away.
I plugged it into my own laptop. The files were there.
Ten years of company data!
Untouched.
That little hard drive was their lifeline.
I spent the next two days rebuilding the network, one machine at a time. Wipe the infected computer. Reinstall Windows. Install updates. Restore the clean data.
Move to the next machine. Then do it again. And again.
It took two days.
By Monday morning, the employees were back at their desks. Their computers worked. Their files were there. The business was running again.
They never paid the $600 ransom.
Looking back, the real lesson wasn't simply "Don't open suspicious attachments." Of course, you shouldn't.
But the bigger lesson was this: A backup that is connected to the network is not always a safe backup. One little hard drive. One simple habit. And 48 hours of hard work.
Everyone was happy that Monday except one person: the hacker.
* You can check out XLOOKUP vs VLOOKUP: Why You Should Switch in Excel Today
* The top image was created by Google Nano Banana.
Comments
Post a Comment