Picto Extranet Picto Map

Data Recovery for a German Industrial Company and Its SAN Server

We were commissioned by the IT Director of a German engineering firm to recover their data following a major AKIRA ransomware attack that had completely paralyzed their production.

📋 Case Technical Sheet

  • Target: Engineering company (Industrial sector)
  • Infrastructure: Dell Compellent SCv2020 SAN, Dell PowerEdge R730 / R730xd
  • Environment: ESXi, Windows NT4 (Legacy), Oracle DB, Veeam Backup
  • Technical Challenge: Deleted Veeam backups, SAS drives with T10 PI protection, deduplicated volumes
  • Result: Over 90% of data recovered (6 TB of usable data reconstructed)

Context and Scope of the Intervention

While the initial scenario pointed toward a standard recovery—given that the encrypted production virtual machines and their associated Veeam backups were theoretically available—on-site realities quickly revealed a far higher level of complexity:

  • Raw Infrastructure Delivery: Due to the complete destruction of their hypervisor, the client opted to hand over their entire storage array rather than just the encrypted Virtual Machines (VMs). While this approach maximizes overall recovery chances, it requires a complete rebuild of the physical hardware infrastructure, all while strictly preserving chain-of-custody integrity for forensic purposes.
  • Compromised Backups: The attackers deleted the Veeam backups and partially overwrote the volume to maximize damage.
  • A Shifting Organizational Context: The target company, a subsidiary of a French group, was in the middle of restructuring its IT infrastructure and transitioning ERP systems, significantly complicating access to system architecture details.

On the eve of a public holiday, a company executive personally delivered all hardware directly to our laboratory:

  • Production / Hypervisor: 2 Dell PowerEdge R730 servers (redundant configuration)
  • Storage: 1 Dell Compellent SCv2020 SAN
  • Backup: 1 Dell PowerEdge R730xd server housing the Veeam backups
The complete storage array upon arrival at our laboratory

The targeted operation involved around ten VMs, focusing primarily on 4 critical VMs: 2 file servers and 2 application servers hosting Oracle databases on a legacy Windows NT4 environment.

Phase 1: Hardware Securing and Low-Level Processing

During our initial analysis, we identified physical hardware errors. We immediately secured our intervention by performing a complete full-clone of the infrastructure—an essential step to guarantee complete reversibility (forensics, rollback) and allow a full restoration of the original array if needed.

This phase brought to light a critical technical specification: all SAS drives in the SAN utilized T10 protection, known as Data Integrity Fields (or T10 PI). This feature mandated the use of proprietary tools capable of handling non-standard block sizes. This step proved crucial: any alteration or omission related to T10 protection would have rendered the drives unreadable by the original array controller, preventing any rollback to the initial state.

The SAN array and its front panel as received by our engineering team

Phase 2: Logical Recovery and Data Reconstruction

Once the infrastructure was physically secured, our engineers began the logical reconstruction phase, which required deep technical expertise to overcome several major challenges:

  • Restoring Volume Access: Since the original hypervisor was destroyed, we restored access to the volumes by booting the infrastructure in a third-party ESXi environment. To ensure total security and avoid modifying any client configuration parameters, this boot process was executed in isolation via physical bootable media (CD/DVD)—a proven, legacy technique that guarantees the host system remains completely unaltered.
  • Post-Overwrite Reconstruction: The partial overwrite executed by the attackers on the Veeam volumes fragmented and damaged the data. Our teams conducted extensive manual reconstruction and repair work to extract the remaining usable data.
  • Underestimated Data Volume: The primary file server, initially reported at 600 GB, actually contained over 1.6 TB of usable data. Processing this volume of heterogeneous file sizes required optimizing our processing queues to minimize recovery turnaround times.
  • Deduplication Interdependency: Enabling file deduplication across all VMs significantly increased the technical complexity of the recovery. This process splits each file into multiple shared chunks. In a disaster scenario, this interconnected architecture means a single corrupted block can impact multiple virtual machines. Our experts had to operate with surgical precision to maintain the logical consistency of the deduplicated volumes.

Results Achieved

The advanced methodologies deployed by Recoveo achieved outstanding results given the severity of the attack:

  • File Servers: Full recovery and reconstruction of nearly 6 TB of usable data (post-deduplication volume).
  • Databases: Successful repair and extraction of the Oracle database, restored to the exact state prior to the crash.
  • Application Environment: Only one of the two legacy applications could not be reconstructed due to the intrinsic structure of the Windows NT4 file system (HPFS/FAT), which is significantly less resilient to massive data corruption than modern NTFS.

Have your SAN servers suffered a similar ransomware attack or data loss?

Cellule d'urgence ransomware

Ligne direct 24/7

Contactez dès à présent nos experts pour vous accompagner et accélérer votre reprise d’activité.

Whatsapp