No More Ransom Marks Five Years of Free Decryption Tools, Helping 6 Million Victims Recover Files
What Happened — The No More Ransom initiative, launched in 2016 by law‑enforcement and security firms, celebrated its fifth anniversary. Since then the public repository of free ransomware decryptors has grown to 121 tools covering 151 ransomware families, assisting more than six million victims worldwide and preventing an estimated €1 billion in criminal earnings. ESET, a long‑time partner, contributed five remediation tools and reports that its brute‑force protection blocked roughly 55 billion attack attempts on nearly one million clients between Jan 2020 and Apr 2021.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a documented incident‑response and recovery control that can be invoked quickly when ransomware encrypts data.
- Shows how continuous monitoring of attack attempts (e.g., brute‑force detection) provides defensible evidence for audit readiness and risk‑based decision‑making.
- Highlights the value of integrating publicly‑available decryption resources into your recovery playbooks to reduce downtime and financial impact.
Who Is Affected
- Enterprises of all sizes that rely on endpoint protection and backup solutions.
- Managed security service providers (MSSPs) and other security vendors that advise customers on ransomware resilience.
Recommended Actions
- Map your ransomware response procedures to the control objective of “incident response and recovery” and capture evidence of tool usage, detection logs, and restoration testing.
- Incorporate free decryptor tools from the No More Ransom repository into your incident‑response playbooks and validate them in tabletop exercises.
- Ensure continuous monitoring alerts (e.g., brute‑force detection) are retained as audit evidence for compliance frameworks. Source: ESET press release
Technical Notes
- The initiative covers 151 ransomware families; tools are publicly downloadable and operate offline, requiring no network connectivity.
- ESET’s brute‑force protection blocked ~55 billion attempts, illustrating the scale of credential‑guessing attacks that often precede ransomware deployment. Source: same as above