Ransomware has a new target. Is your backup ready?

Ransomware groups have shifted their focus to targeting backup infrastructure, raising the stakes for organizations that rely on these safety nets in case of an attack. The financial costs of losing a backup can be devastating, with average incident costs reaching $5.08 million and reputational damage affecting up to 41% of victims.

The attacks on backup infrastructure are nothing short of deliberate sabotage. Ransomware groups have developed tactics to identify and destroy recovery points before encrypting everything else. The goal is clear: eliminate the organization’s ability to recover from an attack, making it more likely that the victim will pay the ransom.

Take the example of ALPHV/BlackCat, which encrypted Change Healthcare’s systems in February 2024 after breaching through a remote access portal with no multi-factor authentication. The backups were not isolated or robust enough to restore operations quickly, forcing UnitedHealth to pay $22 million in ransom and incur estimated recovery costs of $1.6 billion.

Other groups have followed suit. BlackMatter has made backup destruction its standard operating procedure, using compromised admin credentials to locate and wipe every backup data store and appliance on the network before encrypting everything else. Gunra ransomware has taken this tactic further by deleting backup and archived data at both primary and disaster recovery sites, exploiting a single set of stolen credentials to reach both locations.

The attacks point to a simple shift in how backup strategy needs to be thought about: it’s not just about having multiple copies or storing them off-site. Organizations need to consider what connects those copies, who can administer them, and whether a compromised account could reach all recovery points. The key is isolation – separating critical backups from production systems and limiting administrative access.

In an era where ransomware groups are increasingly targeting backup infrastructure, organizations must assume attackers will try to destroy the way out. This means taking proactive measures such as segregating backups from production, using robust authentication and authorization controls, and monitoring for suspicious activity. By doing so, organizations can mitigate the risk of losing their safety net and minimize the financial damage in case of an attack.

In the end, it’s not just about having a backup – it’s about ensuring that backup is only as vulnerable as what connects to it.


Source: Bleeping Computer — 2026-10-07