A manufacturing client

The Backups Were the First Thing Encrypted

Ransomware Recovery for a Manufacturer Whose Backups Died with Its Server

A manufacturer with USB-drive backups and RDP open to the internet lost everything to ransomware in one morning, including the backups. What recovery looked like, what the ransom really bought, and what exists now instead.

The situation

In 2016, a manufacturer of about forty people, ten in the office and thirty on the floor, ran its entire business through one server: the ERP that scheduled and costed every job, and every file the office produced. The server was running Small Business Server 2003, a product that had passed the end of its extended support the year before. Remote users reached it over RDP, left open to the internet because that was the easiest way to make remote access work.

The backups were USB drives plugged into that same server.

When the ransomware arrived through the open remote access, it did what ransomware does: it encrypted everything it could reach. And because the backup drives were attached to the machine being encrypted, they were not a backup at all. They were just more disk. The backups were among the first things lost.

  • The ERP, encrypted. No job costing, no scheduling, no order history
  • Every office file, encrypted
  • The USB backup drives, encrypted along with the server they were plugged into
  • An operating system so old that modern recovery tooling no longer expected to meet it

The company had an IT person, and this was the day that arrangement reached its limit. This is not a story about a client of ours. They were not a client. They called Tech Dynamix the way you call for help when the person responsible has run out of answers, because thirty people on a production floor were about to have nothing to build from.

What we did

What we did

Triage came first, and triage delivered the worst version of the facts: there was nothing to restore from. No offsite copy, no disconnected drive, no earlier server. The choices were to rebuild the business from paper, or to pay.

That decision belonged to the owner, and with the ERP holding every order and every job, the owner paid. Several thousand dollars, in Bitcoin, to criminals, for the return of the company's own data. We will not dress that up as a strategy. It is the position a business is in when its backups fail with it, and everything else in this case study exists so that no one reading it ends up making that decision.

Paying was not the end of it, and this is the part people do not expect. The decrypter the attackers provided assumed a modern Windows system. Pointed at a 2003-era server, it failed: runtimes it depended on did not exist there, and the tool itself was buggy. Tech Dynamix spent the weekend debugging the criminals' own software, supplying the components it silently required and working around its failures, to make the ransom the owner had already paid actually produce the data it was paid for.

Around that ran the rebuild. By the end of the weekend the core systems were running and the floor could work. Getting to nearly everything back took over a week, file by file, system by system, on hardware that should have been retired years earlier.

Where it landed

The company came out the other side, which in 2016, with encrypted backups and a server two years past the end of its support, was not the likely outcome.

  • Core systems running after one weekend
  • Nearly everything recovered in just over a week
  • The full cost was the ransom plus the downtime plus the rebuild, and the ransom was the smallest of the three

They became a managed services client, and the environment that made the incident possible was dismantled: the server replaced, backups moved to a system that runs automatically, keeps copies away from the machines it protects, and gets tested rather than assumed, and remote access closed off from the open internet.

The lesson is the one the USB drives taught. A backup that sits attached to the server it protects fails at the exact moment it is needed, because whatever takes the server takes the backup with it. And paying the ransom is not the recovery plan people imagine: the money buys you a broken tool written by criminals, and if nobody on your side can make it work, the payment buys nothing at all.

Real backups make the entire question disappear. That is what they are for.

The numbers

What changedBeforeAfter
Backups USB drives plugged into the server Automatic, tested, with copies kept apart
Remote access RDP open to the internet Closed off from the open internet
Server SBS 2003, past end of support Replaced and supported
Time to get core systems running No plan existed One weekend
Time to nearly everything recovered No plan existed Just over a week
What ransomware could take Everything, backups included What the last backup missed

What it changed

  • The ransom, several thousand dollars in Bitcoin, turned out to be the smallest of the three costs. The downtime and the rebuild were the other two.
  • The ransom worked only because somebody debugged the attackers' broken decrypter on a weekend. Nothing about that is a plan. The plan is the backup system that has existed since.

Something similar going on at your company?

Tell us about it. We will tell you honestly whether this maps onto your situation or whether yours is a different problem.

  • Fast Track 50 Emerging Business Award, 2025
  • Top 3 Computer Support, Lake County, 2025
  • CyberCert SMB1001 Bronze
  • MSPAlliance member
  • Microsoft Partner
  • Dell Partner
  • Lenovo Partner
  • More than 20 years of experience
  • Managed services since 2010
  • Based in Northeast Ohio
  • Offices in Lake and Summit counties
  • Owner operated and independent
  • CMMC and HIPAA experience