Originally published May 1, 2025 by Tony Phung. Updated October 2026.
I met a paralegal at a trade show in Hong Kong who works for a local law firm. When I told her about our ransomware protection services, the firm wasn’t ready to talk about it, which is completely fair. We kept in touch over the months that followed. Then she reached out with a screenshot of a ransom note, and we jumped in to help.
What we found
The note said the network was encrypted and offered a decryptor in exchange for payment. It looked like one of the known ransomware families, possibly LockBit 3.0, DoNex or Black Busta, though we’re still confirming that.
The firm has a Fortinet 100F firewall, but nobody had the login for it, which made it hard to see what had happened. They haven’t chosen a full assessment yet, and we hope they will soon. We gathered what we could and did a quick check for possible decryptors.
Here is what the setup looked like:
- A tower server sitting in a nice server rack, which is a bit of a mismatch.
- No virtualization. We think of Hyper-V as a must-have for production servers, because it makes backups and recovery much easier.
- Storage on a mirrored pair of drives (RAID 1), with an 8TB drive.
- No domain controller and no separate application server.
- A NAS that may have been affected too. We haven’t been able to confirm that yet.
About 65 staff were cut off from client files and couldn’t work. In the first rush, the firm shut down its whole setup, which took the VoIP phones offline as well.
What usually helps
- Run servers on Hyper-V, with a domain controller and a dedicated application server.
- For storage, we recommend RAID 10, or RAID 6 when budget or capacity matters more. Either way, RAID is not a backup.
- Keep tested 3-2-1 backups, with a copy offsite and immutable copies that can’t be changed or deleted for a set period.
- Keep the firewall login and documentation somewhere safe and current.
- Have an incident response plan and round-the-clock monitoring, which can help limit the damage when something does happen.
Where things stand
We felt we had a solid lead on decrypting the files. The principal lawyer was understandably shaken and wasn’t sure about going down that route, and we respect that. The firm has also heard other advice, including wiping all the computers and starting over. That is one option, but we’d usually suggest finding out where the attack came from first, so the same gap doesn’t stay open. We’ll keep following up with them.
If you’re dealing with ransomware, don’t give up. There may be help. At the very least, get good advice and pay for an assessment so you know where it came from.
We offer full-cycle managed IT and cybersecurity services for businesses in Hong Kong and beyond. Call (604) 813-7881 for a free consult with Tony. No pressure, no jargon.

