Skip to content
Ransomware has a new target. Is your backup ready?

Ransomware has a new target. Is your backup ready?

Bleepingcomputer •Sponsored by Kaseya • October 7, 2026

That’s why threat actors are turning their attention to encrypting backups. They wipe recovery points and disrupt the infrastructure needed to restore the encrypted data. Once that recovery path disappears, the pressure to pay rises sharply.

For IT leaders, the lesson is uncomfortable but simple. A backup is only a safety net if the attacker cannot reach it.

What attacks on backup infrastructure look like

Ransomware groups have found several ways to neutralize backups, and the methods keep getting more deliberate.

ALPHV/BlackCat ransomware group

In February 2024, the ALPHV/BlackCat ransomware group encrypted Change Healthcare’s systems after breaking through a remote access portal with no multi-factor authentication. The backups were not isolated or robust enough to restore operations quickly.

UnitedHealth paid $22 million in ransom and still did not get its data back. Total recovery costs hit an estimated $1.6 billion .

BlackMatter ransomware

The BlackMatter group made backup destruction their standard operating procedure. When they hit NEW Cooperative, an Iowa-based farm services provider, and Crystal Valley, a Minnesota farm cooperative, in 2021, they used compromised admin credentials to locate every backup data store and appliance on the network — then wiped or reformatted them before encrypting everything else. Since the backups were on the same network, they were easy targets.

CISA, the FBI, and the NSA jointly documented this tactic, noting the group has demanded ransom payments ranging from $80,000 to $15 million in Bitcoin and Monero.

Gunra ransomware, documented in a joint CISA and FBI advisory in August 2026, pushed that logic further. In one confirmed case, attackers deleted backup and archived data at both the organization's primary data center and its disaster recovery site.

A single set of stolen credentials was all it took to reach both. Having two copies in two locations meant nothing, because both locations trusted the same key.

Protecting the way back

The attacks above point to a simple shift in how backup strategy needs to be thought . Do not only ask how many copies you have or where they are stored. Ask what connects those copies, who can administer them and whether a compromised account could reach them all.

Your recovery strategy should assume attackers will try to destroy the way out. Separate critical backups from production, limit administrative access, and ensure there is no single compromised identity or pathway that can wipe every recovery copy.

Your Backup Is Only as Safe as What Connects to It

Ransomware groups are now targeting backup infrastructure first — wiping recovery points before encrypting everything else.

Our report, Building Security That Survives Human Error , reveals what's stalling organizations from closing the gap and where leading IT teams are focusing first.

The financial reality of losing your backup

The cost difference between recovering with intact backups versus without them is the difference between a manageable disruption and a business-threatening event.

IBM's 2025 Cost of a Data Breach Report puts the average cost of a ransomware incident at $5.08 million . But the financial damage is only part of the picture.

IBM’s 2026 research found that 41% of ransomware incidents also involved threats to damage the victim’s brand reputation , showing how quickly the impact can spread from disrupted systems to lost customer trust.

If attackers destroy the backups, they take away the leverage that lets organizations refuse the ransom.

Why this keeps happening

These attacks tend to expose the same weaknesses. The recovery environment may exist, but the security around it is often less mature than those protecting production systems.

Backups the same network and credentials: If the same administrator accounts can access both production systems and backups, an attacker who compromises one of those accounts may be able to reach both. True isolation requires deliberate architecture.

Backup software gets patched last: The Akira airline attack exploited a vulnerability that had a patch available for over a year. Backup servers are frequently treated as appliances rather than software systems, which means they get updated last, or not at all. Attackers keep careful track of what remains unpatched.

Monitoring rarely extends to backup infrastructure: Security teams concentrate detection and alerting on production environments. Backup servers often carry minimal logging, weaker access controls and slower response processes. They are watched less carefully, which makes them quieter to work in.

The deeper barrier is resources: Knowing what good backup security looks like and having the budget, trained staff and operational bandwidth to implement it are separate problems. Many IT teams and MSPs operate with all three in short supply. They understand the exposure but simply cannot close it fast enough.

What closing the gap requires

It requires treating the recovery environment as critical infrastructure.

Immutable storage as a baseline: Write-once backup copies that cannot be altered or deleted — even by someone with admin credentials — fundamentally change the attacker's calculation. Most modern cloud storage platforms support object lock features that achieve this. It is a minimum requirement now, not an advanced measure.

True network and credential isolation: A backup environment sharing network access and credentials with production is not meaningfully separate. Proper isolation keeps backup data out of reach even after a network compromise. Multi-factor authentication and role-based access controls for backup infrastructure add another layer of friction that slows attackers down significantly.

Patch backup software with the same urgency as production systems: This requires discipline, not new tooling. Backup platforms need to be built explicitly into the patch cycle rather than treated as exceptions.

Test restores, not just backups: An untested backup is an assumption. Regular restore testing — ideally including attack scenario simulations — surfaces gaps before attackers do. Organizations that discover restoration failures during an actual incident have no time to fix them.

The gap between awareness and action

The challenge of protecting backups points to a broader problem in cybersecurity. Most organizations understand the risk of an attack. They may know they need stronger isolation, better monitoring or more resilient recovery, but lack the budget, staff or operational capacity to put those protections in place.

Almost 77% of IT organizations surveyed for our cybersecurity report, Building Security That Survives Human Error , say their cybersecurity investment is not keeping pace with the threats they face. Among MSPs, 65% say their clients are underinvesting in cybersecurity.

The result is a familiar tension. Security teams know what needs attention, but limited resources force them to make difficult choices where to focus first.

Drawing on responses from more than 1,100 IT and cybersecurity professionals, the report looks at the pressures behind those choices, from human error and underinvestment to staffing shortages and operational friction.

If your team knows where it needs to improve but struggles to make those improvements happen, our report offers a closer look at what is getting in the way and where organizations are focusing their efforts.

and written by Kaseya .

Extracted Entities

Attack Types (1)

Domains (1)

Industries (1)

Ransomware Groups (3)