124 City Rd, London EC1V 2NX Caxton Point, Stevenage SG1 2XT
Book a consultation Call 020 4634 2518
Cyber Security 21 May 2026 7 min read

How ransomware targets business backups

Modern ransomware doesn't just encrypt your live data, it hunts down your backups first. Here's how attackers do it, and the controls that keep your recovery intact.

5.0 Google reviews Microsoft Cloud Solution Provider 10-minute average response London & Hertfordshire

Backups are your safety net. If your business can restore its data quickly, there is no reason to pay a ransom, and attackers know it. That is exactly why modern ransomware campaigns no longer stop at your live systems. Before they encrypt anything, they go looking for your backups.

In the early days of ransomware, a good backup was often enough. You wiped the affected machines, restored from a clean copy and carried on. Attackers have adapted. Today they deliberately target your recovery capability, because a business that cannot recover is a business far more likely to pay. Understanding how they do it, and how to make your backups genuinely resilient, is now a core part of any sensible security strategy.

Why attackers go after your backups first

Ransomware is a business, and the product being sold back to you is your own data. The whole model depends on you having no realistic alternative to paying. Reliable, isolated backups break that model completely: if you can restore in hours, a ransom demand becomes an inconvenience rather than a crisis.

So attackers have learned to neutralise recovery before they trigger encryption. They often spend time inside a network, sometimes days or weeks, quietly locating backup servers, cloud backup consoles and replication jobs. By the time the ransom note appears, the backups they found have frequently already been deleted, encrypted or corrupted. Treating backups as a set-and-forget insurance policy is no longer safe.

How attackers reach your backups

Most attacks follow a recognisable pattern. It usually begins with credential theft, a phished password, a reused login or an exposed remote-access account, which gives the attacker a foothold. From there they work towards administrative access, because admin rights over your backup platform are the keys to the kingdom.

Once they have that access, the tactics are straightforward. They delete backup files and snapshots outright. They encrypt the backup storage alongside everything else. And where deletion is harder, they simply disable recovery from the inside: shortening retention policies so older copies quietly age out, interrupting replication so off-site copies never complete, or switching off backup jobs so nothing new is protected. All of this can happen in the background while your day-to-day systems appear completely normal.

Where backups are most vulnerable

A handful of common weaknesses turn a backup system into an easy target:

  • Weak access controls. If backup consoles rely on single passwords, shared logins or no multi-factor authentication, one stolen credential is enough to reach them.
  • Shared infrastructure. When production and backup systems sit on the same network, use the same credentials or share the same management tools, compromising one often means compromising both.
  • Inadequate isolation. Backups that are always online and always writable can be encrypted or deleted as easily as any other file. Without genuine separation, they are not really a safety net at all.

On-premise, cloud and hybrid backups

Where your backups live changes the risks you need to manage.

  • On-premise backups are quick to restore from and fully under your control, but they are vulnerable if your network is compromised. An attacker who reaches your servers can often reach the backup appliance sitting alongside them.
  • Cloud backups move your copies off-site and away from local attacks, but they are only as safe as their configuration. Weak credentials, over-permissive access and missing MFA on the cloud console can hand an attacker the same delete button you use.
  • Hybrid backups combine both and can offer real resilience, but they also introduce complexity, and any weakness in either environment can be inherited by the whole setup. More moving parts means more to configure correctly and more to monitor.

How to protect your backups

The good news is that resilient backups are entirely achievable with a handful of well-established controls:

  • Keep an air-gapped copy. Maintain at least one backup that is physically or logically isolated from your live network, so it cannot be reached or altered even if everything else is compromised.
  • Use immutable storage. Immutable, or write-once, backups cannot be changed or deleted for a set period, even by someone with administrative rights. This is one of the single most effective defences against backup tampering.
  • Lock down access with MFA. Protect every backup console and admin account with multi-factor authentication and the principle of least privilege, so a stolen password alone is never enough.
  • Separate backup credentials and infrastructure. Do not reuse production logins for your backup platform, and keep backup systems off the everyday network path wherever you can.
  • Test your recovery regularly. A backup you have never restored from is only a hope. Run real recovery tests so you know your copies work and how long a restore actually takes.

A simple rule of thumb many businesses still rely on is 3-2-1: keep three copies of your data, on two different types of storage, with at least one held off-site. Layering air-gapping and immutability on top of that turns a basic backup routine into recovery you can genuinely trust.

Test your recovery, not just your backups

This point deserves stressing on its own, because it is the one most often overlooked. Backups that complete successfully every night can still fail when you actually need them, because of a configuration error, a missing dependency or a corrupted file that nobody noticed. The only way to know your recovery works is to practise it.

For your most critical systems, aim to test a full restore every few months, and document how long it takes. That figure, your realistic recovery time, is what turns a backup policy into a genuine business-continuity plan.

The bottom line

Ransomware has evolved from a data problem into a recovery problem. Attackers win when they can take away your ability to bounce back, so the businesses that stay in control are the ones whose backups are isolated, immutable, tightly access-controlled and regularly tested.

If you are not certain your backups would survive a determined attack, or that you could actually restore from them under pressure, that is exactly the gap worth closing now, before it is tested for you. We are always happy to review your current setup and help you build recovery you can rely on.

Good to know

Frequently asked questions

Not automatically. Cloud backups move your data off-site, which helps, but they are only as secure as their configuration. Without strong credentials, multi-factor authentication and sensible access limits, an attacker who compromises the cloud console can delete cloud backups just as easily as local ones.
Yes. Small and medium-sized businesses are frequently targeted precisely because their defences and backups are often weaker than those of large enterprises. Attackers look for the easiest route to a payout, not the biggest name.
For critical systems, test a full recovery every few months at minimum, and again after any significant change to your infrastructure. Testing confirms both that your backups work and how long a real restore would take.
An immutable backup is written in a way that cannot be altered or deleted for a defined period, even by an administrator. That makes it extremely resistant to ransomware, which relies on being able to encrypt or remove your recovery copies.
An air-gapped backup is kept physically or logically separate from your live network, so it cannot be reached by an attacker who has compromised your main systems. It is one of the most reliable ways to guarantee you always have a clean copy to restore from.
Ready when you are

Would your backups survive a ransomware attack?

Book a free consultation and we'll review your backup and recovery setup, then help you close any gaps.

Call us Book a consultation