← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Ransomware Groups Target Backups to Increase Pressure for Ransom Payments

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Ransomware groups are destroying backups to prevent recovery.
  • ALPHV/BlackCat, BlackMatter, and Gunra groups used this tactic.
  • Compromised admin credentials are used to wipe backup data.
  • Backup strategies need to isolate critical recovery points.

Evolving Ransomware Tactics

Ransomware attackers are shifting their focus from merely encrypting primary data to actively targeting and destroying backup infrastructure. This change in strategy aims to eliminate recovery options for victims, thereby increasing the pressure to pay ransom demands. By neutralizing backups, attackers remove the safety net that typically allows organizations to restore operations without succumbing to extortion.

Examples of Backup Destruction

The ALPHV/BlackCat ransomware group encrypted Change Healthcare's systems in February 2024, where backups were not sufficiently isolated to enable quick restoration, leading to a $22 million ransom payment and an estimated $1.6 billion in recovery costs. The BlackMatter group made backup destruction a standard procedure, using compromised admin credentials to locate and wipe backup data stores before encrypting other systems, as seen in attacks on NEW Cooperative and Crystal Valley in 2021. The Gunra ransomware, documented in an August 2026 advisory, extended this by deleting backup and archived data at both primary and disaster recovery sites using a single set of stolen credentials.

Why This Matters

These incidents demonstrate that traditional backup strategies, which often focus on the number of copies or their physical location, are no longer sufficient. Attackers are exploiting vulnerabilities in how backups are connected and administered. If a single compromised credential can access and wipe multiple backup locations, the redundancy of having multiple copies becomes irrelevant.

Rethinking Backup Strategy

Organizations must now consider not just where backups are stored, but also what connects them, who can administer them, and whether a compromised account could reach all recovery points. The new imperative is to assume attackers will attempt to destroy recovery options. This requires separating critical backups from production environments and limiting administrative access to these recovery systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Ransomware groups are increasingly targeting and destroying backup infrastructure to prevent data recovery and force victims to pay ransoms. This tactic has been observed in attacks by groups like ALPHV/BlackCat, BlackMatter, and Gunra, highlighting a critical shift in ransomware strategy. Organizations must re-evaluate backup strategies to ensure isolation and protection from compromised credentials.