Ransomware & Incident Response

Backup Targeting & Destruction

Ransomware groups specifically hunt for and destroy backups before encrypting.

What it is

Before deploying encryption, attackers identify and destroy or encrypt backup infrastructure. Shadow copies are deleted via vssadmin. Network-attached backup appliances are accessed with stolen credentials and wiped. Cloud backup policies are modified to reduce retention. Organisations with backups on the same network as production systems have no effective recovery option.

Attack techniques

  • Volume Shadow Copy deletion (T1490)
  • Inhibit System Recovery (T1490)
  • Backup credential theft and destruction
  • Modification of cloud backup retention policies
  • Network storage wipe

Business impact

Without viable backups, organisations face a binary choice: pay the ransom or rebuild from scratch. Rebuilding typically takes weeks to months and costs significantly more than prevention.