Trusence Every claim has a source
Last updated 7 October 2026 Search Türkçe
← All stories
Security

Ransomware crews are now targeting backups first

Attackers are deleting recovery copies before encryption, making restoration harder and raising the stakes for victims.

Ransomware operators are increasingly going after backup systems first, because destroying recovery points can force victims into paying and make restoration much harder. The report cites the 2024 Change Healthcare intrusion by ALPHV/BlackCat, where UnitedHealth paid $22 million and still could not recover the data, with total recovery costs estimated at $1.6 billion. It also points to BlackMatter attacks in 2021, where compromised admin credentials were used to find and wipe backup stores before encryption, and to a Gunra case documented by CISA and the FBI in August 2026 in which backup and archived data were deleted at both a primary data center and a disaster recovery site. The article argues that organizations need immutable backups, stronger isolation between production and recovery systems, tighter access controls, and more aggressive patching for backup infrastructure.

Why it matters

For organizations, the shift means a backup is no longer enough on its own if attackers can reach it with the same access they use on production systems. The cases cited show that once recovery data is wiped, victims can still pay and remain unable to restore, while costs and downtime mount. That makes backup isolation and protection part of the incident outcome, not just a technical detail.

Sources

  • BleepingComputer