Ransomware has a new target. Is your backup ready?

Ransomware gangs have been terrorizing organizations for years, but recently they’ve set their sights on a new target: backups. These critical recovery points are meant to provide a safety net in case of an attack, but if attackers can erase them, the pressure to pay a ransom grows exponentially.

The devastating effects of this tactic were seen in the 2024 attack on Change Healthcare, where the ALPHV/BlackCat ransomware group encrypted the company’s systems and wiped out its backups. UnitedHealth paid $22 million in ransom, but even that wasn’t enough to recover all their data – the total recovery costs are estimated at a staggering $1.6 billion.

But this isn’t an isolated incident. The BlackMatter gang has made backup destruction a standard part of their operating procedure, targeting farm cooperatives and other organizations with compromised admin credentials. They use these credentials to locate every backup data store and appliance on the network, then wipe or reformatted them before encrypting everything else.

In August 2026, the CISA and FBI jointly documented another variant of this tactic: Gunra ransomware. In one confirmed case, attackers deleted backup and archived data at both the organization’s primary data center and its disaster recovery site – all it took was a single set of stolen credentials to reach both locations.

The takeaway from these attacks is clear: organizations need to rethink their backup strategy. Simply having multiple copies in different locations isn’t enough. What connects those copies, who can administer them, and whether a compromised account could reach them all are questions that must be answered.

To protect the way back, organizations should separate critical backups from production systems, limit administrative access, and ensure there is no single compromised identity or pathway that can wipe every recovery copy. It’s time to assume attackers will try to destroy the way out – and build backup infrastructure accordingly.

The financial reality of losing your backup is stark. According to IBM’s 2025 Cost of a Data Breach Report, the average cost of a ransomware incident is $5.08 million. But it’s not just about the money: 41% of ransomware incidents also involve threats to damage the victim’s brand reputation.

When attackers destroy backups, they take away the leverage that lets organizations refuse the ransom. It’s a sobering reminder that backup infrastructure needs to be designed with security in mind – and not treated as an afterthought.

The weaknesses exposed by these attacks are all too familiar: recovery environments often have less mature security than production systems, backups share the same network and credentials, and backup software gets patched last. By addressing these vulnerabilities head-on, organizations can build a more resilient defense against ransomware gangs – and protect their critical data in the process.

So, what can you do to protect your organization’s backups? Start by asking tough questions about your recovery strategy: what connects your copies, who has access to them, and whether a compromised account could reach them all. Then take deliberate steps to separate your backups from production systems, limit administrative access, and ensure there is no single point of failure.

The stakes are high, but with the right mindset and infrastructure, you can protect your organization’s backups – and keep ransomware gangs at bay.


Source: Bleeping Computer — 2026-10-07