Can you recover your data after a ransomware attack without paying the ransom? Often yes, because ransomware encrypts files, it does not erase them: they stay on the disk, unreadable without the key. This guide explains what ransomware really does, why the direct decryption of a recent strain is out of reach, and above all what a recovery laboratory can still save without ever contacting the criminals: deleted but not overwritten RAIDs, snapshots (Shadow Copies), partially encrypted files, forgotten backups. You will find the steps to take in an attack (shut down, isolate, overwrite nothing), an honest decision on whether to pay, the shift toward blackmail by disclosure, your legal obligations in Switzerland (FOCS, nFADP) and the only real safeguard: an offline, immutable and off-site backup.