How do you think they accessed your NAS?
1) Weak passcode. 2) Security exploit in DSM.
The fixes are easy; better passcode, and turn off remote access to the device until whatever flaw(s) can be patched.
Also, wasn't there a remote root exploit for samba4 patched just days ago?
However, there's really no reason to expose samba shares to the Internet. There are much better and more secure methods. As to the unfortunate victim, there's most likely no way anyone will be able to retrieve what has been locked by the remote attacker - except the remote attacker.