🇰🇪 Recovery of a critical database after The Gentlemen ransomware attack in Kenya

A financial company in Kenya faced a severe ransomware incident that compromised its VMware virtual environment and paralyzed its operations for one week. The attack affected a volume exceeding 10 TB of critical data and created an extremely high-pressure situation for the client, who needed to restore business continuity as quickly as possible.

The group responsible for the attack was identified as The Gentlemen, which encrypted essential systems hosted on the company’s VMware virtual hypervisor. As this was a financial sector organization, the impact was immediate and severe. Access to critical systems was blocked, essential operations were interrupted, and the client was left in a state of despair due to the prolonged downtime.

One of the most critical points of the incident was the unavailability of backups. The attackers deleted the existing backups, eliminating the fastest conventional recovery path and significantly increasing the urgency and complexity of the project. In addition, the client did not have a ransomware incident response plan, which made the scenario even more challenging.

To address this situation, we provided a remote diagnosis followed by a remote recovery strategy, focusing on restoring the most critical data in the shortest possible time. This approach required adaptation, as cases with this level of complexity and data volume are not typically handled remotely. However, in this project there were two important limitations: the client’s internet connection was very poor, and they did not want the data to leave their premises.

Even with these constraints, we were able to structure a secure and efficient operation. Remote recovery always requires additional care, especially to protect our technology, methodology, and operational environment throughout the entire process. Even so, the project progressed well, with constant communication and full availability from our team.

One of the decisive factors for the success of the case was the recovery of the company’s main database. As this database concentrated essential information for operations, its restoration represented the most important step for business recovery. Throughout the entire project, we maintained support 24 hours a day, 7 days a week, which was essential to provide confidence to the client, accelerate decision-making, and maintain technical progress without interruptions.

Despite the challenges involved, including the remote recovery of more than 10 TB of data in a sensitive environment, the project was completed in one week, from the moment the case was initiated to the final approval of the recovered data. In the end, the client received their main database back and was very satisfied with the result achieved.

This case shows that, even in complex scenarios, with deleted backups, large volumes of data, and significant operational limitations, a well-executed technical strategy can enable the recovery of critical information and drastically reduce the impact of a ransomware attack.

We are always online

Please fill out the form, or select your preferred contact method. We will contact you to start recovering your files.

Latest insights from our experts

We can detect, contain, eradicate, and recover data after cyber attacks.

Post-incident