Why Ransomware Targets Backups First, and How to Stop It
Ransomware targeting backups explained: why 94% of attacks hit backups first, how attackers pull it off, and how to build backups that survive.
Ransomware targeting backups explained: why 94% of attacks hit backups first, how attackers pull it off, and how to build backups that survive.
Ransomware targeting backups is now standard attacker behavior, not an edge case. Before encrypting production systems, most ransomware operators actively search for and disable, delete, or encrypt backup repositories first, because a working backup is the one thing that lets a victim refuse to pay.
Table of Contents
ToggleA backup is the single control that neutralizes a ransomware attacker’s leverage. If a victim can restore clean data without paying, the entire extortion model collapses. Attackers have adapted accordingly: modern ransomware playbooks treat backup destruction as a required step before deploying the encryption payload, not an optional extra.
This shift explains why ransomware has evolved into double and triple extortion. Encrypting data alone stopped being reliable once organizations improved their backup discipline, so attackers added data theft (threatening to leak stolen files even if the victim restores from backup) and backup destruction (removing the restore option entirely) to restore their leverage. How ransomware actually damages an organization rarely stops at the initial encryption event; the backup layer is where a contained incident either stays contained or turns into a full operational shutdown.
The scale of backup targeting is no longer a fringe statistic. A widely cited Sophos survey of nearly 3,000 organizations that suffered ransomware attacks found that 94% of them had their backups targeted during the attack, and organizations that lost their backups paid substantially higher ransoms and recovery costs than those that didn’t.
Sophos’s State of Ransomware 2026 report, published July 2026 from a survey of organizations across 17 countries, shows the flip side of that pressure: 56% of ransomware attacks succeeded in encrypting data, but recovery through backups is climbing sharply. In the United States specifically, 60% of organizations used backups to recover encrypted data in 2026, up significantly from 43% just a year earlier. That improvement is exactly why backup destruction has become such a priority for attackers: defenders are getting better at using backups to route around the ransom demand, so attackers are working harder to take that option away first.
Discover how Threatcop protects your workforce from modern cyber threats.
Backup compromise is rarely a separate hack. It is usually the same intrusion that leads to encryption, just aimed at a different target once the attacker has enough access.
The technical mechanics above all depend on the same starting point: initial access. Sophos’s 2026 data found malicious email (26%) and phishing (24%) are now the two leading technical root causes of ransomware attacks, ahead of exploited vulnerabilities, which dropped sharply as the top cause compared to prior years. Human error was the most common operational root cause at 40%.
Ransomware doesn’t succeed because of exotic malware; it succeeds because a person clicked, approved, or reused a credential that gave an attacker the initial foothold everything else builds from, including the eventual attack on backups. A security awareness program that reduces successful phishing and credential compromise is doing backup protection work before an attacker ever reaches the backup console.
Backup infrastructure needs to be defended like a primary target, because that is exactly what it has become.
Treating backups as a purely technical safety net misses how ransomware actually works today. Attackers assume backups exist and plan specifically to reach them, which means a backup strategy has to assume the same thing: isolate what you can, verify what you have, and close the human-driven access paths that get an attacker close enough to try.
If your organization’s incident response planning doesn’t already account for an attacker who goes after backups on the way to encryption, that gap is worth closing before it gets tested for real.
Yes. A widely cited Sophos survey of ransomware victims found that 94% had their backups specifically targeted during the attack, and organizations that lost their backups faced significantly higher ransom demands and recovery costs.
Common methods include deleting Windows Volume Shadow Copies with built-in system commands, using compromised admin credentials to access and disable backup software directly, and exploiting vulnerabilities in backup platforms themselves.
An extension of the classic 3-2-1 rule: three copies of data, on two different media types, with one copy offsite, one copy immutable or offline so an attacker with network access cannot alter it, and zero errors confirmed through regular restore testing.
It becomes much harder. This is precisely why attackers prioritize backup destruction: removing the restore option removes the victim’s strongest alternative to paying the ransom.
Both, but it starts as a human risk problem. Sophos’s 2026 data shows phishing and malicious email are now the leading root causes of ransomware attacks, meaning the backup compromise that follows almost always traces back to an initial human-driven access point.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Security fatigue explained: the NIST-documented exhaustion behind risky clicks, MFA approvals, and password reuse, and how to actually reduce...
Vibe coding security risks explained: 7 real threats, why AI-generated code fails on security, and a checklist to catch...
What is OSINT in cyber security: how attackers use public social media data to research and target employees, and...
Table of Contents
×