I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool."
If some kind of software was provided by the attackers, and Colonial installed it, this could be far from over.
Also, if the company has backups, then why not use them instead? If they're incomplete, then that's the real problem.