Ransomware attackers are shifting their focus from merely encrypting primary data to actively targeting and destroying backup infrastructure. This change in strategy aims to eliminate recovery options for victims, thereby increasing the pressure to pay ransom demands. By neutralizing backups, attackers remove the safety net that typically allows organizations to restore operations without succumbing to extortion.
The ALPHV/BlackCat ransomware group encrypted Change Healthcare's systems in February 2024, where backups were not sufficiently isolated to enable quick restoration, leading to a $22 million ransom payment and an estimated $1.6 billion in recovery costs. The BlackMatter group made backup destruction a standard procedure, using compromised admin credentials to locate and wipe backup data stores before encrypting other systems, as seen in attacks on NEW Cooperative and Crystal Valley in 2021. The Gunra ransomware, documented in an August 2026 advisory, extended this by deleting backup and archived data at both primary and disaster recovery sites using a single set of stolen credentials.
These incidents demonstrate that traditional backup strategies, which often focus on the number of copies or their physical location, are no longer sufficient. Attackers are exploiting vulnerabilities in how backups are connected and administered. If a single compromised credential can access and wipe multiple backup locations, the redundancy of having multiple copies becomes irrelevant.
Organizations must now consider not just where backups are stored, but also what connects them, who can administer them, and whether a compromised account could reach all recovery points. The new imperative is to assume attackers will attempt to destroy recovery options. This requires separating critical backups from production environments and limiting administrative access to these recovery systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Ransomware groups are increasingly targeting and destroying backup infrastructure to prevent data recovery and force victims to pay ransoms. This tactic has been observed in attacks by groups like ALPHV/BlackCat, BlackMatter, and Gunra, highlighting a critical shift in ransomware strategy. Organizations must re-evaluate backup strategies to ensure isolation and protection from compromised credentials.