Ransomware attacks have evolved significantly, with recent research showing that backups are often deleted or compromised before victims even see a ransom note. This shift in tactics, highlighted in Mandiant’s M-Trends 2025 report, poses a serious threat to organisations relying on their backup strategies as a last line of defence. Understanding how ransomware operators disable backups and the implications for recovery is crucial for any organisation seeking to protect its data and operations.
Ransomware Operators Now Delete Backups Early
The latest findings from Mandiant reveal a troubling trend: ransomware actors are systematically seeking out and destroying backup data at the earliest stages of their attacks. In many cases, this happens well before the ransom note appears or the victim realises their systems have been compromised. The traditional window for detecting and responding to a ransomware attack is now much shorter, and recovery options can be severely limited once backups are gone.
Mandiant’s M-Trends 2025 report details that when organisations detect ransomware incidents themselves, rather than being notified by law enforcement or the attackers, the median dwell time—the period attackers remain undetected—remains dangerously high. During this period, threat actors have ample opportunity to locate and erase backup files, shadow copies, and even cloud-based backups if those are accessible from compromised networks.
Technical Details: How Backups Are Compromised
Ransomware groups are now prioritising the destruction or encryption of backups as a key step in their playbook. The process typically unfolds as follows:
- Initial Access: Attackers gain entry via phishing, credential theft, or exploiting vulnerabilities.
- Privilege Escalation: Attackers move laterally, obtaining administrator or domain-level access.
- Backup Discovery: Using built-in tools or custom scripts, they identify backup solutions in use, such as Windows Volume Shadow Copies, network-attached storage, or cloud backup services.
- Backup Deletion: Attackers execute commands to delete or encrypt backups. For example, using
vssadmin.exe delete shadows /all /quieton Windows, or targeting backup management consoles with stolen credentials. - Ransomware Deployment: Only after backups are neutralised is the ransomware payload deployed, encrypting production data and displaying the ransom note.
This sequence ensures that, by the time organisations are aware of the attack, their main recovery method—restoring from backups—is no longer available. Notably, backup solutions that are accessible using the same credentials as production systems are especially vulnerable.
Who Is Affected: Sectors and Systems at Risk
The threat is not limited to any single sector. Mandiant’s research indicates that both large enterprises and smaller businesses are being targeted. However, small and medium-sized businesses (SMBs) may be at greater risk due to less mature security and backup controls.
All major backup solutions can be targeted, including:
- Windows Volume Shadow Copy Service (VSS)
- Network-attached storage (NAS) devices
- Commercial backup platforms (e.g., Veeam, Commvault)
- Cloud-based backup services (if accessible from compromised accounts)
Any backup that is online, connected, or accessible from compromised credentials is at risk of deletion or encryption. Attackers know to look for both local and remote copies, and cloud backup services are increasingly in their sights as organisations move away from on-premises solutions.
Timeline of the Attack Chain
The sequence of events in a modern ransomware attack, as described by Mandiant, generally follows this timeline:
- Initial entry: Attackers breach the network, often undetected.
- Reconnaissance: Mapping network assets and identifying backup infrastructure.
- Escalation: Gaining privileged access to backup management systems.
- Backup compromise: Backups are deleted, encrypted, or otherwise rendered useless.
- Payload deployment: Ransomware is launched across production systems.
- Ransom note: Only now do victims become aware, with no working backups to restore from.
According to Mandiant, this process is increasingly automated, and attackers often spend days or even weeks moving laterally and ensuring all backups are destroyed before striking.
Current Exploitation Status and Trends
Ransomware groups are sharing techniques and even specific scripts for backup deletion on underground forums. Some ransomware-as-a-service (RaaS) platforms now include backup targeting features as part of their standard toolkit. This trend is likely to continue, making it essential for organisations to adapt their backup strategies accordingly.
Notably, the number of incidents where backups were wiped before the main ransomware attack is rising year-on-year. Attackers are increasingly aware that backups are a critical obstacle to monetising their attacks and are making it a priority to remove them.
Why This Matters
These evolving tactics mean that organisations can no longer rely on conventional backups alone. If backups are online or accessible from the network, they are almost certainly targeted. The loss of backups can result in permanent data loss, regulatory issues, and extended downtime.
What Organisations Should Do Now
- Implement immutable or offline backups that cannot be modified or deleted by compromised accounts.
- Restrict administrative access to backup systems, using different credentials from those used elsewhere in the network.
- Monitor backup systems for unusual activity, such as unexpected deletions or access attempts.
- Test backup restoration processes regularly to ensure backups have not been tampered with.
Rapid detection and response are crucial. Organisations should assume that ransomware groups will seek out and destroy backups early in the attack chain.
Originally reported by cyberdefensemagazine.com.






