Crypto Sheriff
top of page

Crypto Sheriff


Crypto Sheriff is an online service which can help decrypt files that have fallen victim to a ransomware attack. See: https://www.nomoreransom.org. The “No More Ransom” project helps identify keys needed for decryption. It is a joint project of Europol, Kaspersky, McAfee, and the national police of the Netherlands. See the recommendation on the Europol site here.

Ransomware typically uses two keys - a public key to encrypt files, and a private key to decrypt files. It's sometimes possible to decrypt files encrypted with ransomware because of mistakes in how they are implemented, or because they are posted somewhere online. Law enforcement agencies also seize servers containing keys and make them known.

You use the service by uploading two files, each less than 1 MB, which have been encrypted by ransomware, and then entering an email address, Bitcoin address, or URL used in the ransomware demand that you received.

If Crypto Sheriff finds a way to decrypt your files, it will provide a link to tools you can use to access your files, and provide instructions on how to use those tools. The malware should be removed from an operating system before the files are decrypted.

Crypto Sheriff allows you to download more than 100 decryption tools, many of which are designed specifically for particular types of ransomware.


Sean O'Shea has more than 20 years of experience in the litigation support field with major law firms in New York and San Francisco.   He is an ACEDS Certified eDiscovery Specialist and a Relativity Certified Administrator.

The views expressed in this blog are those of the owner and do not reflect the views or opinions of the owner’s employer.

If you have a question or comment about this blog, please make a submission using the form to the right. 

Your details were sent successfully!

© 2015 by Sean O'Shea . Proudly created with Wix.com

bottom of page