Ransomware & Extortion · Ransomware

Ransomware Goes After the Recovery Path

Ransomware groups are increasingly targeting backup infrastructure, and BleepingComputer says the pattern includes ALPHV/BlackCat, BlackMatter, and Gunra. The goal is not just to encrypt live systems but to wipe the copies victims expect to restore from, which turns backup design into the pressure point that decides whether an outage stays temporary or becomes a payment event.

The common thread is reachability. In the examples cited, attackers used stolen or compromised credentials to reach backup stores, appliances, or disaster recovery sites, then deleted or wiped them before or alongside encryption. If the backup plane shares networks, identities, or admin paths with production, clean recovery can disappear even when copies exist on paper.

That puts isolation, immutable storage, and separate administration at the center of ransomware resilience. For organizations that still assume backups are the escape hatch, this trend changes the trust picture: the recovery path itself is now part of the attack surface, and a backup that can be managed like production can be destroyed like production.

1 source · 5h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-07

Every edition of this story: Ransomware Goes After the Recovery Path