Been contacted by a company just hit with ransomeware.
Looks like they were hacked via remote desktop (weak password) on their server (..!)
Files are renamed to .encrypted and there's a matching *.how_to_get_back.txt for each.encrypted file.
Text in the note says:
Attention!
All your data was Encrypted!
If you wanna get it back contact via email:
[email protected]
Your Personal ID: ********** (Removed)
WARNING: If you don't contact next 72 hours, then all DATA will be damaged unrecoverably!!!
However, have downloaded the apocalypse decrypter tool and