
What the document says
On 25 July 2016, the Netherlands' National High Tech Crime Unit, Europol's European Cybercrime Centre, Kaspersky Lab and Intel Security (McAfee) launched No More Ransom, a public portal offering free decryption tools and ransomware information. The initial release included four decryption tools containing more than 160,000 keys. Kaspersky researcher Jornt van der Wiel framed the problem the project targeted: victims with encrypted data readily pay criminals to recover it, which funds further attacks. Intel Security's Raj Samani described the aim as going beyond intelligence sharing, consumer education and takedowns, to help repair the damage already done to victims. The project's current page, retrieved 16 September 2026, lists a larger set of law enforcement and industry partners and repeats the founding advice plainly: the general recommendation remains not to pay, both because payment funds criminal activity and because it carries no guarantee of a working decryption key. The decryption tools page now lists an extensive catalogue organised alphabetically by ransomware family.
Confidence and limits
The launch date, founding partners and initial scale come from Europol's own contemporaneous press release, which is strong, first-party evidence. The pages describing today's catalogue are living documents: this account states only what is present as retrieved on 16 September 2026, not a verified count of tools, victims helped or ransom payments avoided, because none of the pages opened here state those aggregate figures with a source or method attached.
Why it mattered
A free, publicly maintained decryptor catalogue changed the calculation for some ransomware victims by giving them a checkable alternative to consider before paying. It also formalised a channel between police forces and security vendors for adding new decryptors as researchers or law-enforcement operations recovered keys, which is why the catalogue has grown well beyond its four original tools. The project does not cover every ransomware family, and a family's absence from the list is not evidence that no decryptor could ever exist for it.
Defensive takeaway
Check the current decryption tools catalogue against the specific ransomware family identified in your incident before making any payment decision, and treat a missing entry as inconclusive rather than final.
- Does our incident response plan reference checking No More Ransom before any ransom-payment discussion begins?
- Can we correctly identify the ransomware family involved, which the catalogue requires to find a matching tool?
- Have we verified a tool's legitimacy through the listed project partners rather than a third-party search result?
A decryptor catalogue is a step to check early, not a guarantee available for every incident. Building that check into a response plan costs little and can only help, even when no matching tool exists yet.
Check the current decryption tools catalogue for the specific ransomware family in your incident before any payment decision.
Europol's own 2016 announcement and the project's current pages establish the launch date, founders and standing advice. Total victims helped or ransom payments avoided are not stated with a source or method in the pages opened here, so this account does not repeat aggregate savings figures sometimes quoted elsewhere.
Sources & reading trail
Confirms the 25 July 2016 launch, the four founding partners, and the initial release of four decryption tools containing over 160,000 keys.
government-primary · Source published: 25 July 2016 · Retrieved: 16 September 2026
States the current partner list and the standing advice not to pay a ransom, as retrieved 16 September 2026.
project-primary · Source published: Not established · Retrieved: 16 September 2026
Shows the current catalogue of free decryption tools organised by ransomware family, as retrieved 16 September 2026.
project-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.