Ransomware gets a lot faster by encrypting the master file table instead of the filesystem

All the data’s there, but you have to figure out where one file stops and another starts, filenames, etc. I’ve had to do that a few times, but I usually ended up with a some files that are perfectly recovered and others that are gibberish. Software for it might have improved since then, though.

You could probably recover specific files of recognizable file types pretty easily, especially if they’re something simple like text files. But if you’re trying to get the entire OS install and all your data back into a working state, it could be a real crapshoot.

5 Likes