Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NASA’s Webb finds signs of Mars-sized worlds smashing together

    October 7, 2026

    Scientists Urge Consumers to Stop Buying Products Made From Antarctic Krill

    October 7, 2026

    China’s AI Rollout Has No Kill Switch

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NASA’s Webb finds signs of Mars-sized worlds smashing together
    • Scientists Urge Consumers to Stop Buying Products Made From Antarctic Krill
    • China’s AI Rollout Has No Kill Switch
    • Ex-German spy chief arrested: A history of spooks working for enemy powers | Espionage News
    • ‘All me’: Tory party riding high on Kemi Badenoch’s wave of popularity | Kemi Badenoch
    • Tony Fadell on why the first wave of AI gadgets failed — and what comes next
    • Ransomware has a new target. Is your backup ready?
    • Engineer Gets 32 Months for Bitcoin Extortion Plot Against His Own Employer
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Ransomware has a new target. Is your backup ready?

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ransomware is far less frightening when you know you can recover.

    That’s why threat actors are turning their attention to encrypting backups. They wipe recovery points and disrupt the infrastructure needed to restore the encrypted data. Once that recovery path disappears, the pressure to pay rises sharply.

    For IT leaders, the lesson is uncomfortable but simple. A backup is only a safety net if the attacker cannot reach it.

    What attacks on backup infrastructure look like

    Ransomware groups have found several ways to neutralize backups, and the methods keep getting more deliberate.

    ALPHV/BlackCat ransomware group

    In February 2024, the ALPHV/BlackCat ransomware group encrypted Change Healthcare’s systems after breaking through a remote access portal with no multi-factor authentication. The backups were not isolated or robust enough to restore operations quickly.

    UnitedHealth paid $22 million in ransom and still did not get its data back. Total recovery costs hit an estimated $1.6 billion.

    BlackMatter ransomware

    The BlackMatter group made backup destruction their standard operating procedure. When they hit NEW Cooperative, an Iowa-based farm services provider, and Crystal Valley, a Minnesota farm cooperative, in 2021, they used compromised admin credentials to locate every backup data store and appliance on the network — then wiped or reformatted them before encrypting everything else. Since the backups were on the same network, they were easy targets.

    CISA, the FBI, and the NSA jointly documented this tactic, noting the group has demanded ransom payments ranging from $80,000 to $15 million in Bitcoin and Monero.

    Gunra ransomware

    Gunra ransomware, documented in a joint CISA and FBI advisory in August 2026, pushed that logic further. In one confirmed case, attackers deleted backup and archived data at both the organization’s primary data center and its disaster recovery site.

    A single set of stolen credentials was all it took to reach both. Having two copies in two locations meant nothing, because both locations trusted the same key.

    Protecting the way back

    The attacks above point to a simple shift in how backup strategy needs to be thought about. Do not only ask how many copies you have or where they are stored. Ask what connects those copies, who can administer them and whether a compromised account could reach them all.

    Your recovery strategy should assume attackers will try to destroy the way out. Separate critical backups from production, limit administrative access, and ensure there is no single compromised identity or pathway that can wipe every recovery copy.

    Ransomware groups are now targeting backup infrastructure first — wiping recovery points before encrypting everything else.

    Our report, Building Security That Survives Human Error, reveals what’s stalling organizations from closing the gap and where leading IT teams are focusing first.

    Download the Report

    The financial reality of losing your backup

    The cost difference between recovering with intact backups versus without them is the difference between a manageable disruption and a business-threatening event.

    IBM’s 2025 Cost of a Data Breach Report puts the average cost of a ransomware incident at $5.08 million. But the financial damage is only part of the picture.

    IBM’s 2026 research found that 41% of ransomware incidents also involved threats to damage the victim’s brand reputation, showing how quickly the impact can spread from disrupted systems to lost customer trust.

    If attackers destroy the backups, they take away the leverage that lets organizations refuse the ransom.

    Why this keeps happening

    These attacks tend to expose the same weaknesses. The recovery environment may exist, but the security around it is often less mature than those protecting production systems.

    • Backups share the same network and credentials: If the same administrator accounts can access both production systems and backups, an attacker who compromises one of those accounts may be able to reach both. True isolation requires deliberate architecture.
    • Backup software gets patched last: The Akira airline attack exploited a vulnerability that had a patch available for over a year. Backup servers are frequently treated as appliances rather than software systems, which means they get updated last, or not at all. Attackers keep careful track of what remains unpatched.
    • Monitoring rarely extends to backup infrastructure: Security teams concentrate detection and alerting on production environments. Backup servers often carry minimal logging, weaker access controls and slower response processes. They are watched less carefully, which makes them quieter to work in.
    • The deeper barrier is resources: Knowing what good backup security looks like and having the budget, trained staff and operational bandwidth to implement it are separate problems. Many IT teams and MSPs operate with all three in short supply. They understand the exposure but simply cannot close it fast enough.

    What closing the gap requires

    It requires treating the recovery environment as critical infrastructure.

    • Immutable storage as a baseline: Write-once backup copies that cannot be altered or deleted — even by someone with admin credentials — fundamentally change the attacker’s calculation. Most modern cloud storage platforms support object lock features that achieve this. It is a minimum requirement now, not an advanced measure.
    • True network and credential isolation: A backup environment sharing network access and credentials with production is not meaningfully separate. Proper isolation keeps backup data out of reach even after a network compromise. Multi-factor authentication and role-based access controls for backup infrastructure add another layer of friction that slows attackers down significantly.
    • Patch backup software with the same urgency as production systems: This requires discipline, not new tooling. Backup platforms need to be built explicitly into the patch cycle rather than treated as exceptions.
    • Test restores, not just backups: An untested backup is an assumption. Regular restore testing — ideally including attack scenario simulations — surfaces gaps before attackers do. Organizations that discover restoration failures during an actual incident have no time to fix them.

    The gap between awareness and action

    The challenge of protecting backups points to a broader problem in cybersecurity. Most organizations understand the risk of an attack. They may know they need stronger isolation, better monitoring or more resilient recovery, but lack the budget, staff or operational capacity to put those protections in place.

    Almost 77% of IT organizations surveyed for our cybersecurity report, Building Security That Survives Human Error, say their cybersecurity investment is not keeping pace with the threats they face. Among MSPs, 65% say their clients are underinvesting in cybersecurity.

    The result is a familiar tension. Security teams know what needs attention, but limited resources force them to make difficult choices about where to focus first.

    Drawing on responses from more than 1,100 IT and cybersecurity professionals, the report looks at the pressures behind those choices, from human error and underinvestment to staffing shortages and operational friction.

    If your team knows where it needs to improve but struggles to make those improvements happen, our report offers a closer look at what is getting in the way and where organizations are focusing their efforts.

    Download the report

    Sponsored and written by Kaseya.

    backup ransomware ready Target
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers exploit critical Atlassian flaw after public PoC release

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

    Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

    Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

    100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NASA’s Webb finds signs of Mars-sized worlds smashing together

    October 7, 2026

    Scientists Urge Consumers to Stop Buying Products Made From Antarctic Krill

    October 7, 2026

    China’s AI Rollout Has No Kill Switch

    October 7, 2026

    Ex-German spy chief arrested: A history of spooks working for enemy powers | Espionage News

    October 7, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NASA’s Webb finds signs of Mars-sized worlds smashing together

    October 7, 2026

    Scientists Urge Consumers to Stop Buying Products Made From Antarctic Krill

    October 7, 2026

    China’s AI Rollout Has No Kill Switch

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.