We Found The Cure For Ransomware. The Dutch Government Ignored Us.
We Found The Cure For Ransomware. The Dutch Government Ignored Us.
Kajsa Ollongren. Micky Adriaansens. Franc Weerwind. Alexandra van Huffelen.
We contacted them all.
We also contacted their respective ministries and tried to put what we had developed in front of the Dutch government.
We weren’t asking them to invest millions of euros in an idea written on the back of a napkin. We weren’t pitching another cybersecurity startup with a PowerPoint presentation and a promise that maybe, one day, we could build something useful.
We had already built it.
After approximately nine months of intensive research and development, we created custom software designed to recover files from systems that had already been hit by ransomware.
In our own testing, we achieved a recovery success rate of approximately 87%.
And the response from the Dutch government?
Nothing.
No meeting.
No technical evaluation.
No request for a demonstration.
No rejection.
Not even a letter saying, “Thank you, but we’re not interested.”
Just silence.
I still find that almost impossible to understand.
Ransomware Is Not a Small Problem
Ransomware is one of the most destructive forms of cybercrime in the world.
An attacker gains access to a computer or network, deploys malicious software and encrypts files so that the legitimate owner can no longer access them. Increasingly, attackers also steal data before encrypting it, creating a second threat: pay us, or we publish what we stole.
Hospitals, manufacturers, municipalities, schools, corporations and ordinary individuals can all become victims.
The European Union Agency for Cybersecurity, ENISA, described ransomware as the most impactful cyber threat in the EU in its 2025 threat landscape.
And this isn’t some distant theoretical threat.
According to the Dutch National Cyber Security Centre, 65 ransomware incidents were reported to Dutch police in 2025. The NCSC itself stresses that the real number is probably higher because not every victim reports an attack or engages one of the incident-response companies included in its statistics. Authorities observed 39 different ransomware families in the Netherlands during that year alone.
Think about what happens when one of those attacks succeeds.
Operations stop.
Employees cannot work.
Databases become inaccessible.
Customer information may be compromised.
Hospitals and other essential organisations can be disrupted.
Companies can lose days or weeks restoring systems.
And eventually a message appears demanding money for the possibility of getting your own files back.
The NCSC advises victims not to pay a ransom. Payment provides no guarantee that the data will actually be restored and financially supports the criminal ecosystem behind ransomware.
I completely agree.
The problem is what comes next.
What If You Don’t Have a Usable Backup?
The most reliable defence against ransomware remains prevention, proper security and good, isolated backups.
But prevention doesn’t help you after the encryption has already happened.
And backups aren’t always available.
Backups can be incomplete. They can be outdated. They can be incorrectly configured. Attackers can deliberately search for them and destroy or encrypt them before launching the final ransomware payload.
The Dutch NCSC’s own guidance says that restoring from backup is the most reliable way to recover encrypted files. If that isn’t possible, victims are advised to determine whether a decryptor exists for the ransomware that infected them.
And that’s the gap that interested us.
What if recovery could become another line of defence?
Not preventing the attack.
Not paying the attacker.
But attempting to undo the damage after the files have already been encrypted.
Nine Months of Research
That question turned into approximately nine months of intensive research.
We studied what happened to files before, during and after ransomware encryption. We experimented. We failed. We changed approaches. We tested again.
Eventually, we developed custom software capable of recovering encrypted files under a significant percentage of the conditions we tested.
Our internal testing produced a success rate of approximately 87%.
Let me be very clear about what that means.
I’m not claiming that we discovered some magical mathematical trick that can break every encryption algorithm ever created.
That would be nonsense.
Modern cryptography, implemented correctly with securely generated and protected keys, cannot simply be wished away by writing clever software.
Ransomware, however, isn’t just cryptography.
It is software.
Software has implementations, processes, behaviours, artefacts, mistakes, patterns and weaknesses. Different ransomware families operate differently. Recovery possibilities depend heavily on what happened during a particular infection.
Our work focused on those possibilities.
The software was designed to analyse what an infection had done and, where the necessary technical conditions existed, attempt to reconstruct or recover encrypted data without obtaining the criminal’s decryption key and without paying the ransom.
Across the ransomware samples and scenarios we tested, it worked in roughly 87% of cases.
For something that people are usually told may be unrecoverable without a backup or ransomware-specific decryptor, we believed that deserved serious investigation.
Not blind acceptance.
Not a government cheque.
Investigation.
Put our claims under a microscope.
Give the software to independent cybersecurity specialists.
Attack it.
Test it against different ransomware families.
Try to prove us wrong.
If our 87% became 70% under independent testing, that would still be extraordinary.
If it became 50%, it could still potentially save organisations millions.
And if independent researchers proved the entire concept was flawed?
Fine.
That is what scientific and technical scrutiny is for.
But somebody has to be willing to look.
So We Went to the Dutch Government
I believed something with this kind of potential should not simply become another commercial cybersecurity product sold to whoever could afford the biggest licence.
So I contacted the Dutch government.
Among the people we approached were Kajsa Ollongren, Micky Adriaansens, Franc Weerwind and Alexandra van Huffelen, together with their ministries.
And I went considerably further than simply asking the government to listen to a sales pitch.
I was prepared to offer the commercial rights to the finished product.
That part matters to me.
Because my motivation was never to become rich because other people were being attacked by ransomware.
There would undoubtedly be enormous commercial potential in technology capable of recovering data after ransomware attacks.
But that wasn’t what excited me.
What excited me was the possibility of taking one of the cybercriminal world’s most powerful weapons and making it less powerful.
Ransomware works because the attacker has leverage.
They have something you desperately need: your data.
Reduce that leverage and you change the equation.
Make recovery possible without paying them and suddenly one of the most profitable forms of cybercrime becomes a little less profitable.
That was worth more to me than squeezing every possible euro out of a licence.
I wanted to build something capable of giving ransomware operators the technological equivalent of:
🖕
Your encryption worked.
Your ransom note appeared.
But we’re getting the files back anyway.
I Expected Skepticism. I Didn’t Expect Silence.
I never expected government officials to simply take our claims at face value.
In fact, I wouldn’t have wanted them to.
If somebody walks into a government ministry claiming to have developed technology capable of recovering ransomware-encrypted files with an 87% success rate, the appropriate reaction should be scepticism.
Ask questions.
Demand evidence.
Bring in experts.
Run controlled tests.
Challenge every claim.
That’s responsible cybersecurity.
What I didn’t expect was for nobody to apparently be interested enough to even have that conversation.
There is an enormous difference between:
“We tested your technology and don’t believe it works.”
and:
Silence.
The first answer I could respect.
The second one I still struggle to understand.
To be precise, I am not claiming that the Dutch government tested our technology and rejected it.
That’s exactly the problem.
As far as I am aware, we never got far enough for the technology to receive the serious technical evaluation we were asking for.
What Makes It Particularly Disappointing
There is another reason this experience became personal for me.
During the investigation surrounding Donny M. and the murder of nine-year-old Gino van der Straeten in 2022, Dutch law enforcement needed specialist technical assistance.
I was asked to help.
They didn’t send me through twelve layers of bureaucracy.
They came to me because there was a serious investigation and they believed I could contribute technical expertise.
I helped.
I did so because when technology can assist an investigation involving something that serious, you help.
I wasn’t thinking about what favour I would get in return.
But that experience demonstrated something important to me: when authorities believe technical expertise is useful, they know how to find you.
That is why the later silence surrounding our ransomware research was so disappointing.
When expertise was needed from me, the distance between government and specialist could apparently become very small.
When I came back with something that I believed could potentially help thousands of ransomware victims, suddenly that distance seemed enormous.
I wasn’t asking for a medal.
I wasn’t asking anyone to believe me without evidence.
I was effectively saying:
“We may have something important here. Please test it.”
I don’t think that was an unreasonable request.
Maybe We Were Wrong.
There is something else I want to make clear.
Maybe our results wouldn’t have survived independent testing.
Maybe ransomware families we hadn’t tested would have dramatically reduced that 87%.
Maybe large-scale enterprise networks would have exposed weaknesses that never appeared in our laboratory environment.
Maybe another research team would have looked at our approach and discovered limitations we hadn’t considered.
All of that is possible.
That’s research.
But there’s only one way to discover those things:
You test it.
What frustrates me isn’t the possibility that somebody might prove us wrong.
What frustrates me is never being given the opportunity to be proven right or wrong in the first place.
Ransomware Hasn’t Gone Away
Years have passed.
Ransomware didn’t disappear.
Criminal groups continued developing new variants. New Ransomware-as-a-Service operations appeared. Organisations continued being attacked.
ENISA reported 82 ransomware variants deployed against organisations in EU member states during its 2024–2025 reporting period.
Law-enforcement agencies continue trying to dismantle the financial infrastructure supporting these groups. In June 2026, for example, Europol announced an operation against a cryptocurrency laundering service suspected of processing more than €336 million between 2022 and 2025 and linked to numerous international cybercrime investigations.
The fight continues.
And I still believe recovery technology should be a much bigger part of that fight.
We need prevention.
We need backups.
We need endpoint security.
We need law enforcement.
We need international cooperation.
We need to disrupt ransomware infrastructure and cryptocurrency laundering.
But we should also be asking a different question:
What can we do after the criminals have already pressed the button?
Because if technology can significantly increase the chance that victims recover their files without paying criminals, that changes the economics of ransomware itself.
This Was Never Just About Money
I don’t particularly care whether something like this ultimately carries my name.
I don’t care whether a government agency develops it further, a university researches it, or cybersecurity companies take the underlying concept and improve upon it.
I care about the result.
Imagine a future ransomware attack where the victim sees the ransom demand and instead of asking:
“How much do they want?”
the first question becomes:
“How much can we recover?”
That is the future I wanted to help create.
Maybe our technology isn’t the complete answer.
Maybe it’s one part of the answer.
Maybe what we built needs substantially more development.
But an internally measured 87% recovery rate after nine months of research was, in my view, enough to warrant somebody taking a serious look.
Instead, we got silence.
And that may be the part of this story I will never understand.
We weren’t asking the Dutch government to believe us.
We were asking them to test us.
They never did.
