🇩🇪 Digital Recovery recovers data for a German company after a dual‑encryption ransomware attack by LYNX and INC

A large German company in the food industry faced a critical situation after a ransomware attack that compromised virtual machines, corporate files, and data essential to its operations.

With more than 250 employees, the company produces food and poultry-based specialties and depends on a stable technology infrastructure to keep operations running.

After the attack, key systems became unavailable, and the company needed a specialized solution to recover its data, as traditional restoration methods were not available due to compromised backups.

The technical investigation determined that the attackers gained access to the company’s environment through the exploitation of a vulnerability.

During the incident analysis, a dual-encryption scenario involving the LYNX and INC ransomware groups was identified.

LYNX ransomware typically appends the .lynx extension to compromised files, while the INC group uses the .INC extension, indicating that different layers of encryption were applied to the affected environment.

The main compromised data included:

  • VMDK files from the virtual machines;
  • Data stored on the File Server;
  • Documents and shared information used by internal teams.

The encryption directly affected the virtualized environments and the data required for the German company’s business continuity.

Compromised backups prevented conventional restoration

The company had data backups; however, the available copies were also affected during the ransomware attack.

As a result, traditional restoration of the environment was not a viable option, making a specialized approach necessary for analysis and recovery of the data encrypted by the ransomware.

In addition, the organization did not have a structured ransomware incident response plan prior to the attack, which complicated the first steps after the compromise was identified.

Critical scenario required an emergency response

At the time of first contact, the company was in a critical situation.

The unavailability of systems and important files directly impacted operations, and there was significant concern about the potential permanent loss of information.

As the incident had occurred three days before the support request, there was an urgent need to understand the level of compromise and quickly define the most appropriate technical strategy.

Digital Recovery initiated an emergency 24×7 analysis to assess:

  • The structure of the affected virtual machines;
  • The condition of the VMDK files;
  • The level of encryption applied;
  • The technical feasibility of data recovery.

Due to the distance between the affected site and the technical laboratory, a specific strategy was defined for the secure transport of data.

The company copied the compromised virtual machines to external drives, which were subsequently sent to the Digital Recovery laboratory.

This approach enabled the entire analysis to be performed in a controlled environment without transporting the client’s original infrastructure.

Proprietary tools were critical to the recovery

One of the main factors behind the project’s success was the use of proprietary technologies developed for the analysis and recovery of VMDK environments.

The tools enabled an in-depth investigation of the affected virtual machine structures, making it possible to:

  • Identify data still recoverable;
  • Extract information in a controlled manner;
  • Analyze the compromised virtual disks;
  • Reconstruct access to stored data.

The proprietary TRACER tool played a key role in the process, enabling advanced analysis of the compromised environment and directly contributing to data recovery.

Due to the size and complexity of the virtualized environment, it was necessary to adapt the infrastructure used in the laboratory.

High-performance equipment capable of handling the data volume was employed to optimize processing and recovery stages.

This preparation maintained stability throughout the project and reduced the time required to make the data available to the client.

The project was completed in approximately six days, allowing the German company to regain access to essential information stored on the virtual machines and on the File Server.

Result

This case demonstrates that ransomware attacks can compromise entire environments, including virtual servers, corporate files, and backup structures.

Even in a complex scenario involving the LYNX and INC groups, encryption of virtual machines, and unavailability of backup copies, a specialized analysis made it possible to identify technical paths for data recovery.

The combination of technical expertise, proprietary tools, and specialized infrastructure was decisive in helping the German company recover critical information and gradually resume operations.

We are always online

Please fill out the form, or select your preferred contact method. We will contact you to start recovering your files.

Latest insights from our experts

We can detect, contain, eradicate, and recover data after cyber attacks.

Post-incident