NEWS

Ransomware Has a New Target: Is Your Backup Ready?

Ransomware gangs now destroy backups first to kill recovery options. Kaseya, CISA, and recent Veeam CVEs show why isolated, tested backups matter.

Dylan H.

News Desk

October 7, 2026
9 min read
Ransomware Has a New Target: Is Your Backup Ready?

Backup Infrastructure Is Now a Primary Ransomware Target

Ransomware operators are no longer treating backup systems as an afterthought — they are treating them as the first objective. A new industry analysis, built on a report from backup and recovery vendor Kaseya and covered by BleepingComputer on October 7, 2026, documents a clear shift: attackers now prioritize destroying or disabling recovery infrastructure before encrypting production data, eliminating a victim's ability to simply restore and refuse payment. Kaseya's survey of 1,100+ IT professionals, titled "Building Security That Survives Human Error," found that organizations are not keeping backup defenses aligned with this shift — a gap underscored by a string of 2026 incidents, including a federal advisory on the Gunra ransomware group deleting backups at two separate data centers using a single stolen credential, and a cluster of critical remote-code-execution flaws disclosed in Veeam Backup & Replication earlier this year.


Threat Landscape at a Glance

AttributeValue
Underlying reportKaseya, "Building Security That Survives Human Error" (survey of 1,100+ IT professionals)
Covered byBleepingComputer, October 7, 2026
Average ransomware incident cost$5.08 million (IBM Cost of a Data Breach data)
Reputational-damage threats41% of ransomware incidents also threatened to damage the victim's brand (IBM, 2026)
Underinvestment signal77% of IT organizations say cybersecurity investment is not keeping pace with threats; 65% of MSPs say clients are underinvesting
Notable backup-killing campaignGunra ransomware — joint CISA/FBI/NSA/DC3/USSS/KNPA advisory AA26-222A, published August 10, 2026
Notable backup-software vulnerability clusterVeeam Backup & Replication — 8 CVEs disclosed March 12, 2026, including four rated CVSS 9.9 (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)
Recommended baselineImmutable, network/credential-isolated, regularly tested backup copies

How Backup-Targeting Ransomware Works

Backup destruction has become doctrine, not opportunism

Historically, ransomware crews encrypted whatever they could reach and hoped backups were either absent or also encrypted as a side effect. That is no longer the model. Kaseya's report frames backup destruction as a deliberate, prioritized step in the attack chain — on par with credential theft and lateral movement — because it directly determines whether a victim has any option besides paying. The tactic traces back at least to BlackMatter in 2021, which made backup destruction standard procedure in attacks against targets including NEW Cooperative and Crystal Valley, with ransom demands ranging from $80,000 to $15 million. By 2026, that playbook has become the norm across major ransomware-as-a-service (RaaS) operations rather than the exception.

Backup software itself is the entry point

Attackers do not need to compromise backups indirectly through a broader network breach — backup platforms are increasingly a direct exploitation target in their own right. On March 12, 2026, Veeam disclosed eight vulnerabilities in Backup & Replication, four of them rated CVSS 9.9: CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, and CVE-2026-21708. Each allows an authenticated, low-privilege domain user — not an administrator — to achieve remote code execution on the backup server itself. Veeam shipped patched builds (12.3.2.4465 and 13.0.1.2067) alongside the advisory. This followed a separate critical flaw tied to CVE-2025-59470 patched in January 2026 (build 13.0.1.1071, CVSS approximately 9.0). Veeam products have now appeared on CISA's Known Exploited Vulnerabilities (KEV) catalog four times since late 2022, every instance tied to ransomware activity — a track record that has made backup servers one of the most reliably exploited pieces of enterprise infrastructure.

Case study: Gunra's dual-site backup wipe

The clearest illustration of the new doctrine came from a joint CISA, FBI, NSA, Department of Defense Cyber Crime Center, U.S. Secret Service, and South Korea's National Police Agency advisory (AA26-222A, published August 10, 2026) covering Gunra ransomware, a RaaS operation (also branded "Golden Community") built on leaked Conti source code. In at least one documented incident, Gunra actors obtained a single stolen credential from a central access-control server — a key that also decrypted stored passwords for every enterprise server in the environment. Using that one credential set, the actors deleted backup and archived data at both the victim's primary data center and its disaster recovery site, both before and after deploying the ransomware encryptor. Initial access came through known FortiOS/FortiProxy authentication-bypass flaws (CVE-2024-55591 and CVE-2025-24472), and the group has struck at least 51 organizations across the Americas, Europe, the Middle East, Africa, and Asia-Pacific, with ransom demands typically exceeding tens of millions of dollars. The lesson CISA draws is blunt: having two backup copies in two locations provided no real protection because both locations trusted the same compromised credential.

Case study: purpose-built multi-platform lockers targeting Veeam and NAS

A separate 2026 RaaS operation known as The Gentlemen illustrates the same priority from a different angle. The group deploys separate ransomware lockers for Windows, Linux, BSD, NAS, and VMware ESXi, letting a single intrusion encrypt an organization's full infrastructure footprint in one pass. Security researchers note the group specifically targets organizations running Veeam backups with default configurations and exposed NAS devices, alongside unpatched FortiGate VPN appliances. By mid-2026, The Gentlemen had listed hundreds of victims across dozens of countries, with affiliates required to exfiltrate victim data before being issued a ransomware binary — reinforcing double extortion even when backups survive.


Impact Assessment

Impact AreaDescription
Recovery capabilityDestroying or encrypting backups removes an organization's ability to restore without paying, regardless of how good its production defenses were
Extortion leverageNo usable recovery point forces a binary choice between paying or extended downtime — attackers deliberately engineer this before demanding ransom
Double-extortion overlapMost backup-targeting campaigns (Gunra, The Gentlemen) also exfiltrate data first, so even a successful restore does not eliminate the leak-site threat
Downtime and costIBM data cited in the report puts average ransomware incident cost at $5.08 million; real-world cases like the Change Healthcare attack show recovery costs can run into the billions
False sense of redundancyMultiple backup copies or sites provide no protection if they share the same credentials or trust domain, as Gunra's dual-site wipe demonstrated
Reputational and regulatory exposure41% of ransomware incidents now include explicit threats to damage the victim's brand, per IBM's 2026 data, compounding pressure beyond the technical outage

Recommendations

For backup and infrastructure administrators

  • Make at least one backup copy immutable. Use write-once storage — hardened Linux repositories, S3 Object Lock, tape/WORM, or a cloud immutability tier — so a compromised administrator account cannot delete or modify retained copies.
  • Enforce true credential and network isolation for backup infrastructure, separate from production Active Directory. Gunra's dual-site wipe succeeded specifically because both the primary and disaster-recovery backups trusted the same credential.
  • Patch backup software with production-level urgency. Treat Veeam, and any backup platform, as Tier-1 infrastructure for patching — the CVSS 9.9 Veeam flaws disclosed in March 2026 are exploitable by a low-privilege authenticated domain user, not just an administrator.
  • Keep at least one recovery copy offline or logically air-gapped, outside the reach of any credential that also has production access.

For security teams

  • Monitor backup infrastructure for anomalous authentication and deletion activity with the same priority given to domain controllers — bulk deletions, repository configuration changes, or off-hours admin logins to backup consoles are high-fidelity indicators of an active intrusion.
  • Run restore tests that simulate an active attack, not just routine recovery drills — confirm backups are recoverable after assuming credentials may be compromised, not only that files exist.
  • Inventory all internet-facing VPN, firewall, and RDP-exposed systems against the CISA KEV catalog; Gunra's initial access and several other 2026 campaigns rely on known, patchable Fortinet flaws (CVE-2024-55591, CVE-2025-24472).

For executives and MSP clients

  • Ask directly whether your backups are immutable and credential-isolated — not just "do we have backups." Kaseya's survey data suggests a significant gap between confidence and actual resilience, with 77% of IT organizations admitting investment is not keeping pace with the threat.
  • Budget backup resilience as a ransomware control, not a storage line item. The cost of immutable storage and isolated recovery infrastructure is small relative to the $5.08 million average incident cost cited in the underlying IBM data.
  • Request evidence of tested recoverability, including documented restore-test results, from any MSP or internal team responsible for backups.

Key Takeaways

  1. Ransomware groups now prioritize destroying backup infrastructure before encrypting production systems, a deliberate tactic designed to eliminate recovery options and force payment.
  2. Backup software itself has become a direct exploitation target. Veeam Backup & Replication had eight CVEs disclosed in March 2026, four rated CVSS 9.9, exploitable by low-privilege authenticated users.
  3. A joint federal advisory (CISA AA26-222A) confirmed Gunra ransomware deleted backups at both a victim's primary and disaster-recovery data centers using a single stolen credential — proving that multiple backup copies provide no protection without credential isolation.
  4. Multi-platform RaaS operations like The Gentlemen deploy dedicated lockers for Veeam, NAS, and ESXi environments, specifically to deny recovery across an organization's entire infrastructure footprint in one attack.
  5. Kaseya's survey of 1,100+ IT professionals found cybersecurity investment broadly failing to keep pace with these tactics, even as average ransomware incident costs reach $5.08 million.
  6. The core defensive baseline is consistent across every source: immutable backup storage, network and credential isolation separate from production, urgent patching of backup software, and regular restore testing that assumes an active compromise.

Sources