Synology’s knowledge base says it cannot access or decrypt ransomware-encrypted data on a Synology NAS. The recovery path it gives assumes you have backups.
What to do:
1. Restore your data from backup, if available.
2. Restore DSM and packages from your backup copies.
3. If you need to investigate, the Log Center may help identify how it was compromised.
4. Run the DSM Security Advisor.
5. Secure the NAS afterward:
- use very strong passwords
- enable 2FA for admin accounts
- turn off uPnP on your router
- turn on the Synology firewall if your gateway device does not have one
- always keep an external backup
For older DSM versions, Synology notes SynoLocker affected only older DSM releases with a vulnerability fixed and patched in December 2013; if that older-ransomware symptom applies, shut the system down immediately and contact Synology support.
The forum also mentions that the simplest and safest method after an attack is to wipe the NAS and restore from backup. It also notes that some free decryptors may exist at nomoreransom.org, but it does not guarantee recovery.
Sources used: [1], [2], [5]