An emerging group known as n0n ransomware is reportedly threatening to destroy victims’ backups as part of its extortion demands. The claim, identified in the group’s ransom notes, appears designed to make recovery seem impossible and increase pressure on targeted organisations.
The reported capability has not been independently confirmed. However, the wording of the notes shows how ransomware operators are seeking additional leverage beyond encrypting production systems and threatening to publish stolen information.
n0n ransomware threatens backup destruction
The n0n ransomware activity was reported on 24 September 2026. According to the available report, ransom notes associated with the emerging group claim that it can destroy a victim’s backups, extending the established double extortion model.
Double extortion usually combines two sources of pressure. Attackers encrypt systems to interrupt operations, then threaten to publish data stolen before encryption. The n0n ransomware notes reportedly introduce a further threat: eliminating the backups an organisation might use to restore its affected systems.
This distinction is important because reliable backups can reduce an attacker’s leverage. If an organisation can rebuild systems without purchasing a decryption tool, the operational case for paying a ransom becomes weaker. A claim that those recovery copies have also been compromised is therefore intended to create urgency and uncertainty.
What the ransom notes claim
The central claim is that n0n can destroy victim backups. The available reporting does not establish whether the group has demonstrated this capability, successfully deleted backup data or merely included the threat in its ransom messaging.
No technical evidence has been disclosed showing how the group would access, modify or erase backup repositories. There is also no identified command sequence, malware module or management tool associated with the alleged backup destruction activity.
The report does not name a specific backup product, vendor, appliance, cloud platform or software version. Organisations should not interpret the warning as a vulnerability disclosure affecting one particular technology. It concerns an attacker claim about post intrusion activity rather than a confirmed flaw in a named product.
Current exploitation status remains unconfirmed
At the time of reporting, the backup destruction claim remained unconfirmed. The available information does not verify that n0n ransomware has destroyed backups during a completed attack, nor does it provide forensic evidence from an affected environment.
This evidential limit matters. Ransom notes are written to influence victims under pressure, and their claims may exaggerate an operator’s access or capabilities. A threat to erase backups should therefore be investigated seriously, but it should not automatically be treated as proof that every recovery copy has been lost.
There is also no confirmed information in the source material about the number of incidents, the scale of any ransom demands or whether victims have paid. The report identifies an emerging extortion tactic rather than a fully documented campaign with a published victim count.
How n0n ransomware extends double extortion
The n0n ransomware approach seeks to target confidence in recovery. Traditional ransomware creates immediate disruption by making live files or systems unavailable. Data theft then creates regulatory, legal and reputational pressure, even where restoration is possible.
Threatening backups adds a third point of leverage. It suggests that the victim may be unable to restore encrypted systems, unable to avoid a prolonged outage and still exposed to the publication of stolen information. Whether or not the threat is genuine, it can complicate decisions during an already difficult incident.
For backup destruction to be credible, attackers would generally need access to systems or credentials that control recovery data. Depending on the victim’s architecture, that could involve backup consoles, storage repositories, administrative accounts, connected appliances or cloud based recovery services. The reporting does not confirm which, if any, of these routes n0n has used.
The tactic is different from encryption alone. Backup deletion may involve abusing legitimate administrative functions rather than deploying a separate destructive payload. This can make investigation dependent on identity logs, management console records and storage audit trails, not only antivirus or endpoint alerts.
The reported threat also highlights the difference between having backups and having recoverable backups. Copies that remain continuously reachable through the same administrative environment as production systems may be exposed if an intruder gains sufficiently privileged access.
Timeline, targets and affected products
The available timeline is limited. The n0n ransomware claim was publicly reported on 24 September 2026, based on language observed in ransom notes. No earlier intrusion date, initial discovery date or sequence of confirmed victim incidents is provided in the source material.
No affected organisations are named, and the report does not identify a targeted country, industry or organisation size. It is therefore not possible to conclude that the activity is restricted to a particular sector or geographical region.
Likewise, no products or versions are listed as vulnerable. The event should not be treated as a conventional security advisory with a patchable software defect. The immediate issue is the possibility that ransomware operators may seek privileged access to backup infrastructure after entering an organisation’s network.
There is currently no disclosed technical indicator set in the available report. No file hashes, malicious domains, internet addresses, filenames or specific detection signatures are associated with the backup destruction claim. Defenders must consequently focus on evidence of unauthorised access and unusual administrative actions within their own environments.
Why the n0n ransomware claim matters
Even without confirmation, the claim is relevant because it identifies backup infrastructure as part of the extortion process. Recovery platforms hold business critical data and powerful administrative functions, making their security central to an organisation’s ability to respond without relying on an attacker.
The uncertainty itself can benefit criminals. If incident responders cannot quickly determine whether backups are intact, executives may face ransom deadlines without a reliable view of restoration options. Tested and independently protected recovery copies help remove that ambiguity.
Actions tied to the reported backup threat
Organisations should review whether a compromise of production administrator credentials could also provide access to backup systems. The priority is to establish separation and preserve evidence, rather than assuming that a successful backup job means recovery data is safe.
- Maintain immutable or offline copies that cannot be altered through ordinary backup administration.
- Use multifactor authentication for backup consoles, cloud recovery services and privileged accounts.
- Separate backup credentials from production domain administration and restrict destructive functions.
- Monitor for deleted recovery points, changed retention settings, disabled jobs and unexpected administrator logins.
- Test restoration from protected copies so decision makers know which systems can be recovered and how long that process will take.
If n0n ransomware is suspected, responders should preserve backup platform logs and verify recovery points before reconnecting or changing systems. This can help determine whether the destruction threat reflects genuine access, an attempted action or unsupported pressure in a ransom note.
Originally reported by infosecurity-magazine.com.





