Ransomware Is Targeting Backups: How to Protect Your Recovery Strategy
Ransomware becomes less frightening when you know you can recover. That is why attackers are increasingly targeting backup infrastructure.
By encrypting or deleting backups, ransomware groups can erase recovery points and disrupt the systems needed to restore encrypted data. Once the path to recovery is gone, pressure to pay a ransom can increase rapidly.
For IT leaders, the lesson is simple, albeit unpleasant: backups are only a safety net if attackers cannot access and destroy them.
What attacks against backup infrastructure look like
Ransomware groups have found several ways to cripple backups, and their methods are becoming increasingly deliberate.
ALPHV/BlackCat ransomware group
In February 2024, the ALPHV/BlackCat ransomware group encrypted Change Healthcare’s systems after breaching a remote access portal that did not use multifactor authentication. Backups were not isolated and were not robust enough to restore operations quickly.
UnitedHealth reportedly paid a $22 million ransom, but no data was returned. Total recovery costs were estimated at $1.6 billion.
BlackMatter ransomware
The BlackMatter group made destroying backups a standard operating procedure. When it attacked NEW Cooperative, an Iowa-based agricultural services provider, and Crystal Valley, a Minnesota agricultural cooperative, in 2021, the attackers used compromised administrator credentials to identify backup data stores and appliances across the networks.
They then wiped or reformatted the backups before encrypting other systems. Because the backups were connected to the same network, they became easy targets.
CISA, the FBI and the NSA jointly documented this tactic. The group demanded ransom payments ranging from $80,000 to $15 million, payable with Bitcoin or Monero.
Gunra ransomware
Gunra ransomware, documented in a joint CISA and FBI advisory in August 2026, took this approach even further. In one confirmed case, attackers deleted backups and archived data located in both the organization’s primary data center and disaster recovery site.
Only one set of stolen credentials was needed to access both locations. Keeping two copies in different locations provides little protection if the same compromised identity is trusted in both places.
Protect your path to recovery
These attacks demonstrate a fundamental shift in how organizations need to think about backup strategy. Do not just ask how many copies exist or where they are stored. Ask what those copies are connected to, who can control them and whether a compromised account can access every copy.
A resilient recovery strategy must assume that an attacker will attempt to destroy the exit route. Separate critical backups from the production environment, limit administrative access and ensure that no single identity or connection can erase every recovery copy.
Ransomware groups are now targeting backup infrastructure first, wiping recovery points before encrypting everything else.
Our report, Building Security That Withstands Human Error, reveals what is holding organizations back from closing the security gap and where IT teams should focus first.
The economic impact of losing backups
The cost difference between recovering with a complete backup and recovering without one can separate a manageable interruption from a business-threatening event.
According to IBM’s 2025 Cost of a Data Breach Report, the average cost of a ransomware incident is $5.08 million. However, the economic damage is only part of the impact.
IBM’s 2026 study found that 41% of ransomware incidents included threats such as damage to the victim’s brand reputation. The finding shows how quickly the effects can spread from system disruption to loss of customer trust.
When an attacker destroys a backup, the organization may lose much of its ability to refuse the ransom.
Why do backup attacks keep happening?
These incidents tend to expose the same weaknesses. A recovery environment may exist, but the security protecting it is often less mature than the security protecting production systems.
- Backups share the same network and credentials. If the same administrator account can access both production systems and backups, an attacker who compromises that account may gain access to both. True separation requires intentional architecture.
- Backup software is patched last. The attack on Akira Airlines exploited a vulnerability that had been patched more than a year earlier. Backup servers are often treated as appliances rather than software systems, so they may be updated late or not at all. Attackers closely track what remains unpatched.
- Monitoring rarely extends to backup infrastructure. Security teams often focus on production detection and alerting. Backup servers may have minimal logging, weak access controls and slow response processes, allowing attackers to operate with less scrutiny.
- Resources remain a significant barrier. Superior backup security requires budget, trained staff and operational capacity. Many IT teams and managed service providers operate without all three. They understand their exposure but cannot close every gap quickly enough.
How to strengthen backup security
Organizations must treat their recovery environment as critical infrastructure.
- Make immutable storage the baseline. A write-once backup copy that cannot be modified or deleted, even by a user with administrative credentials, fundamentally changes an attacker’s calculations. Most modern cloud storage platforms support object-locking functionality to accomplish this. Immutability is now a minimum requirement, not an advanced measure.
- Separate networks and credentials. A backup environment that shares network access and credentials with production is not meaningfully isolated. Proper isolation helps keep backup data inaccessible after a network compromise. Multifactor authentication and role-based access controls for backup infrastructure add friction that can significantly slow attackers.
- Patch backup software as urgently as production systems. This requires discipline rather than new tools. Backup platforms should be explicitly included in the patch cycle instead of being treated as an exception.
- Test backups and restores. Untested backups are assumptions. Regular restoration tests, including attack simulations where possible, can expose gaps before an attacker does. Organizations that discover a recovery failure during an incident may not have time to fix it.
The gap between cybersecurity awareness and action
The challenge of securing backups reflects broader issues in cybersecurity. Most organizations understand the risk of attack. Even when teams know they need stronger isolation, better monitoring and more resilient recovery, they may lack the budget, personnel and operational capacity to implement those protections.
Almost 77% of IT organizations participated in the cybersecurity report survey. Building Security That Withstands Human Error says that cybersecurity investments have not kept pace with the threats organizations face. In addition, 65% of managed service providers say their clients are underinvesting in cybersecurity.
The result is a familiar tension: security teams know what needs attention, but limited resources force them to make difficult choices about where to focus first.
Based on responses from more than 1,100 IT and cybersecurity professionals, the report examines the pressures behind those choices, including human error, limited investment, understaffing and operational friction.
If you know where your team needs to improve but are struggling to make those improvements, the report offers a closer look at what is holding organizations back and where they are focusing their efforts.
Sponsored and written by Kaseya.
Source: www.bleepingcomputer.com


