Ransomware Attacks: Backups Targeted Before Ransom Note

M-Trends 2025: Ransomware actors wipe backups before ransom note

Ransomware attacks have evolved significantly, with recent research showing that backups are often deleted or compromised before victims even see a ransom note. This shift in tactics, highlighted in Mandiant’s M-Trends 2025 report, poses a serious threat to organisations relying on their backup strategies as a last line of defence. Understanding how ransomware operators disable backups and the implications for recovery is crucial for any organisation seeking to protect its data and operations.

Ransomware Operators Now Delete Backups Early

The latest findings from Mandiant reveal a troubling trend: ransomware actors are systematically seeking out and destroying backup data at the earliest stages of their attacks. In many cases, this happens well before the ransom note appears or the victim realises their systems have been compromised. The traditional window for detecting and responding to a ransomware attack is now much shorter, and recovery options can be severely limited once backups are gone.

Mandiant’s M-Trends 2025 report details that when organisations detect ransomware incidents themselves, rather than being notified by law enforcement or the attackers, the median dwell time—the period attackers remain undetected—remains dangerously high. During this period, threat actors have ample opportunity to locate and erase backup files, shadow copies, and even cloud-based backups if those are accessible from compromised networks.

Technical Details: How Backups Are Compromised

Ransomware groups are now prioritising the destruction or encryption of backups as a key step in their playbook. The process typically unfolds as follows:

  • Initial Access: Attackers gain entry via phishing, credential theft, or exploiting vulnerabilities.
  • Privilege Escalation: Attackers move laterally, obtaining administrator or domain-level access.
  • Backup Discovery: Using built-in tools or custom scripts, they identify backup solutions in use, such as Windows Volume Shadow Copies, network-attached storage, or cloud backup services.
  • Backup Deletion: Attackers execute commands to delete or encrypt backups. For example, using vssadmin.exe delete shadows /all /quiet on Windows, or targeting backup management consoles with stolen credentials.
  • Ransomware Deployment: Only after backups are neutralised is the ransomware payload deployed, encrypting production data and displaying the ransom note.

This sequence ensures that, by the time organisations are aware of the attack, their main recovery method—restoring from backups—is no longer available. Notably, backup solutions that are accessible using the same credentials as production systems are especially vulnerable.

Who Is Affected: Sectors and Systems at Risk

The threat is not limited to any single sector. Mandiant’s research indicates that both large enterprises and smaller businesses are being targeted. However, small and medium-sized businesses (SMBs) may be at greater risk due to less mature security and backup controls.

All major backup solutions can be targeted, including:

  • Windows Volume Shadow Copy Service (VSS)
  • Network-attached storage (NAS) devices
  • Commercial backup platforms (e.g., Veeam, Commvault)
  • Cloud-based backup services (if accessible from compromised accounts)

Any backup that is online, connected, or accessible from compromised credentials is at risk of deletion or encryption. Attackers know to look for both local and remote copies, and cloud backup services are increasingly in their sights as organisations move away from on-premises solutions.

Timeline of the Attack Chain

The sequence of events in a modern ransomware attack, as described by Mandiant, generally follows this timeline:

  • Initial entry: Attackers breach the network, often undetected.
  • Reconnaissance: Mapping network assets and identifying backup infrastructure.
  • Escalation: Gaining privileged access to backup management systems.
  • Backup compromise: Backups are deleted, encrypted, or otherwise rendered useless.
  • Payload deployment: Ransomware is launched across production systems.
  • Ransom note: Only now do victims become aware, with no working backups to restore from.

According to Mandiant, this process is increasingly automated, and attackers often spend days or even weeks moving laterally and ensuring all backups are destroyed before striking.

Current Exploitation Status and Trends

Ransomware groups are sharing techniques and even specific scripts for backup deletion on underground forums. Some ransomware-as-a-service (RaaS) platforms now include backup targeting features as part of their standard toolkit. This trend is likely to continue, making it essential for organisations to adapt their backup strategies accordingly.

Notably, the number of incidents where backups were wiped before the main ransomware attack is rising year-on-year. Attackers are increasingly aware that backups are a critical obstacle to monetising their attacks and are making it a priority to remove them.

Why This Matters

These evolving tactics mean that organisations can no longer rely on conventional backups alone. If backups are online or accessible from the network, they are almost certainly targeted. The loss of backups can result in permanent data loss, regulatory issues, and extended downtime.

What Organisations Should Do Now

  • Implement immutable or offline backups that cannot be modified or deleted by compromised accounts.
  • Restrict administrative access to backup systems, using different credentials from those used elsewhere in the network.
  • Monitor backup systems for unusual activity, such as unexpected deletions or access attempts.
  • Test backup restoration processes regularly to ensure backups have not been tampered with.

Rapid detection and response are crucial. Organisations should assume that ransomware groups will seek out and destroy backups early in the attack chain.

Originally reported by cyberdefensemagazine.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call