A new ransomware gang calling itself n0n has surfaced with a tactic that changes the calculus for victims facing a breach: the deliberate destruction of backup systems, not just the encryption of live data. This isn't a minor variation on an old theme. By eliminating the one safety net organizations traditionally rely on, n0n is pushing double extortion into a more coercive phase, one where paying the ransom may be the only remaining path to recovery.
What Makes n0n Different From Typical Ransomware
Most ransomware operations follow a familiar double extortion playbook: encrypt a victim's files, steal a copy of sensitive data, then threaten to leak that data publicly unless a ransom is paid. Backups have long served as the escape hatch. If an organization has clean, accessible backups, it can often restore operations without paying attackers a cent.
n0n's approach removes that escape hatch entirely. Rather than simply encrypting backup files alongside production data, the gang has been documented explicitly threatening, and in some cases executing, the outright destruction of backup infrastructure. This shifts the attack from a data hostage situation into something closer to a data annihilation event, where recovery without attacker cooperation becomes effectively impossible.
Why Destroying Backups Is a Game-Changing Extortion Tactic
The psychological and operational impact of backup destruction cannot be overstated. When a company knows its backups are intact, it has leverage: it can weigh the cost of downtime and rebuilding against the cost of a ransom payment, often choosing to restore systems independently. Backup destruction eliminates that leverage entirely.
This tactic also signals a shift in how ransomware operators approach their targets. Rather than treating backups as an afterthought or secondary target, groups like n0n appear to be prioritizing backup infrastructure early in the attack chain, understanding that neutralizing recovery options is often more valuable to them than the encryption payload itself. For victims, this means the moment of discovery often arrives too late. By the time encrypted files are noticed, the backups meant to reverse the damage may already be gone.
Who's Been Hit So Far and What It Signals
n0n has already demonstrated it is willing to target infrastructure at massive scale. The group previously claimed responsibility for an attack on Inter, Venezuela's largest internet service provider, an incident that reportedly affected roughly 15.3 million users, as detailed in prior coverage of the n0n attack on Venezuela's Inter ISP. That attack illustrated the group's willingness to go after critical infrastructure providers whose outages ripple across entire populations, not just isolated corporate networks.
The combination of high-impact targeting and backup destruction tactics suggests n0n is positioning itself as a serious and disruptive actor rather than a fringe operation. When a ransomware group can knock out connectivity for millions of people while simultaneously erasing the technical means of recovery, it raises the stakes for how quickly and thoroughly organizations, especially those managing internet infrastructure, need to harden their defenses.
Building a Defense: Immutable Backups, Offline Storage, and Network Security Layering
The rise of backup-targeting ransomware makes it clear that a single backup copy sitting on a connected network is no longer sufficient protection. Organizations need to rethink backup architecture with the assumption that attackers will actively try to find and destroy it.
Immutable backups, storage configured so that data cannot be altered or deleted for a set retention period even by administrators, are becoming a baseline requirement rather than a nice-to-have. Offline or air-gapped backups, physically or logically disconnected from the primary network, add another layer of resilience since attackers cannot destroy what they cannot reach. Beyond backups themselves, layered network security matters just as much: segmenting networks so a single compromised credential cannot reach backup systems, monitoring for unusual access patterns to backup infrastructure, and reducing overall exposure through tools like VPNs to limit unauthorized remote access all contribute to closing the gaps attackers exploit.
What This Means For You
Whether you run IT for a small business or simply manage personal files, the n0n threat is a reminder that backup strategy needs active maintenance, not passive assumption. A backup that lives on the same network as your primary systems, with the same credentials granting access to both, offers far less protection than most people assume. Regularly testing backup restoration, keeping at least one copy offline or immutable, and limiting who and what can access backup systems are no longer optional best practices. They are the difference between a recoverable incident and a catastrophic one.
Actionable Takeaways
- Maintain at least one immutable or offline backup copy that is logically separated from your main network.
- Regularly test backup restoration to confirm data is actually recoverable, not just present.
- Restrict administrative access to backup systems separately from general network credentials.
- Monitor for unusual activity targeting backup infrastructure, not just production servers.
- Use network security layers, including VPNs and access controls, to reduce the attack surface that could lead to a ransomware foothold in the first place.
The emergence of n0n and its backup destruction tactics underscores that ransomware defense can no longer stop at prevention alone. Resilience now depends on assuming a breach will happen and ensuring your recovery options survive the attack itself.




