Ransomware groups are changing the order of operations. According to a Kaseya explainer covered by BleepingComputer, attackers are increasingly going after backup infrastructure to remove victims' recovery options and raise the pressure to pay. For anyone running a home office or small business, ransomware targeting backups protection is no longer a nice-to-have. It is the difference between a bad week and a ransom negotiation.
The source article is brief, but its message is clear: organizations need backups that are isolated, immutable, and regularly tested, so attackers cannot easily reach or destroy them. Below, we unpack what that means in practice for smaller setups.
Why Attackers Go After Backups First
The logic is simple. Encrypting files only works as leverage if the victim cannot restore them. If a clean backup exists, the attacker's demand loses most of its force. By finding and disabling backups before triggering encryption, ransomware operators remove the victim's best alternative to paying.
This shifts how we should think about backups. They are not a passive safety net sitting quietly in the corner. They are a high-value target, and attackers treat them that way. A backup that is reachable from the same network, with the same credentials as everything else, may be encrypted or deleted along with your primary data.
This fits a broader pattern of ransomware crews adding pressure tactics. Our coverage of how the Gunra ransomware gang ramps up double extortion attacks shows how groups layer threats so that restoring from backup alone does not end the problem. Still, a working backup remains your strongest first move, which is exactly why attackers want it gone.
What Makes a Backup Attack-Resistant: Isolation, Immutability, Testing
Kaseya's guidance rests on three properties. Each one answers a different way backups fail.
Isolation. Isolated backups sit apart from your everyday network and credentials. If an attacker compromises a workstation or an admin account, they should not automatically gain access to the backup copy. Isolation can mean an offline or disconnected copy, a separate account with separate credentials, or a segmented network location.
Immutability. An immutable backup cannot be altered or deleted for a set period, even by someone with administrative access. This protects against an attacker who has stolen credentials and tries to wipe your restore points.
Regular testing. A backup you have never restored is an assumption, not a plan. Testing confirms that the data is complete, that it is not already corrupted, and that you know how long recovery actually takes.
None of these is sufficient alone. Isolation without testing can leave you with a safe but unusable copy. Immutability without isolation can still leave the system exposed in other ways. Together, they make a backup that an attacker cannot easily reach and that you can trust.
Where Backups Fail in Home and Small-Business Setups
The source article speaks to organizations broadly, but the gaps are easy to spot in smaller environments. These are common patterns to check for, based on the three criteria above:
- An always-connected external drive or NAS. If it is mounted and writable from your computer, ransomware running on that computer can usually reach it too.
- Cloud sync mistaken for backup. Sync tools may faithfully replicate encrypted or deleted files. Without versioning or retention controls, sync is not the same as recovery.
- Shared credentials. If the backup uses the same admin login as your main systems, one stolen password exposes both.
- No restore test. Many people discover problems only during an emergency.
- No written recovery steps. Knowing what to restore first, and where, saves time under pressure. Our piece on ransomware incident response plans explains why planning ahead matters.
Securing Remote Access to Backup Systems
Remote access is a frequent route for attackers, so the way you reach your backups matters as much as where they live. Practical steps include:
- Use unique credentials for backup systems, not the ones you use daily.
- Turn on multi-factor authentication for backup consoles and cloud storage accounts.
- Avoid exposing backup management interfaces directly to the internet. If you need remote access, route it through a secured connection such as a properly configured VPN, and keep that VPN software updated.
- Limit who and what can delete or modify backups.
- Keep backup software and devices patched.
A VPN protects the connection to your backup system, but it does not make a backup immutable or isolated. Treat it as one layer, not a substitute.
What This Means For You
If you assume your backups would survive an attack, this is the moment to verify it. Ransomware crews are looking for your backups specifically, so a copy that is always connected, shares credentials, or has never been restored may fail when you need it most. The good news is that the fixes are mostly about configuration and habits, not expensive tools.
Takeaways: Audit Your Backups This Week
Use this short checklist to strengthen your ransomware targeting backups protection:
- Isolation: Is at least one copy disconnected, or protected by separate credentials?
- Immutability: Can anyone, including an admin, delete or overwrite your restore points right now?
- Testing: When did you last restore real files from backup, and how long did it take?
- Access: Is remote access to your backup system protected with unique credentials and multi-factor authentication?
Once you have audited your setup, read our guide to ransomware incident response planning and our coverage of Gunra's double extortion tactics to see how backup failure fits into a wider ransomware response.


. Společnost, jejíž jméno je na produktu, nebyla ta, která byla hacknuta, přesto byli její zákazníci zasaženi.
## Co je a co není známo o exponovaných datech
Co je známo: incident se stal dříve tohoto roku, EY byla původním cílem a Goldman Sachs a Man Group byly nyní jmenovány jako další oběti.
Co není ve zdrojovém materiálu stanoveno:
- Zda byla zapojena data klientů, data zaměstnanců nebo data o vlastních zákaznících firem
- Počet zasažených jednotlivců v kterékoli z firem
- Zda byla data zveřejněna nebo zneužita
- Jaká oznámení, pokud vůbec nějaká, jednotlivci obdrželi
Dokud firmy nebo regulátoři neposkytnou více podrobností, je moudré vyhnout se předpokladu toho nejhoršího i toho nejlepšího. Velké instituce často zveřejňují informace postupně a raný obraz se může změnit.
## Co to znamená pro vás
Možná jste nikdy neslyšeli o interních systémech EY, ale přesto můžete být zasaženi, pokud banka, fond nebo zaměstnavatel, s nimiž jednáte, použili kompromitovaného dodavatele. Málokdo si vybírá dodavatele své instituce a oznámení o únicích často přicházejí od společnosti, kterou neznáte.
To má dvě stránky. Zaprvé, dopis nebo e-mail o úniku u dodavatele může být legitimní, takže jej neodhazujte. Zadruhé, zprávy o únicích jsou oblíbeným háčkem pro podvodníky, proto ověřte jakoukoli zprávu přímým přechodem na oficiální webové stránky instituce, místo abyste klikali na odkazy v oznámení.
Stejná dynamika se objevuje v menších incidentech. Naše pokrytí [úniku dat SafePal zasahujícího téměř 40 000 zákazníků](/en/safepal-data-breach-exposes-nearly-40-000-customers) ukazuje, jak se údaje zákazníků mohou dostat do nesprávných rukou, i když je samotný produkt postaven kolem bezpečnosti.
## Co by jednotlivci měli dělat po úniku u dodavatele
Nemusíte čekat na potvrzení, že vaše vlastní data byla získána. Rozumné a nízkonákladové kroky zahrnují:
1. **Sledujte své účty.** Kontrolujte výpisy z banky, makléřských a kreditních účtů na neznámé aktivity a zapněte upozornění na transakce.
2. **Zkontrolujte si úvěrové zprávy.** Zvažte upozornění na podvod nebo zmrazení úvěru, pokud obdržíte oznámení, že byly zapojeny citlivé identifikátory.
3. **Buďte skeptičtí k neočekávaným zprávám.** Phishing často následuje po zprávách o únicích. Nesdílejte kódy, hesla ani osobní údaje v reakci na nevyžádaný kontakt.
4. **Používejte jedinečná hesla a vícefaktorové ověřování.** To omezí škody, pokud bylo jakékoli pověření exponováno.
5. **Uchovejte si jakékoli oznamovací dopisy.** Mohou být užitečné, pokud budete později potřebovat zpochybnit podvod nebo požádat o monitorování úvěru nabízené zasaženou společností.
## Shrnutí
Únik dat společnosti EY, s nímž byly nyní Goldman Sachs a Man Group spojeny, je připomínkou, že vaše data jsou jen tak v bezpečí, jak bezpečný je nejslabší dodavatel v řetězci. Plný rozsah je stále nejasný, proto sledujte oficiální aktualizace od zúčastněných firem. Mezitím sledujte své účty, zpřísněte zabezpečení svých účtů a zacházejte s neočekávanými zprávami souvisejícími s únikem opatrně. Pro další příklady toho, jak se expozice u třetích stran vyvíjí, si přečtěte naše zprávy o [úniku u přepravního partnera Trezor](/en/trezor-shipping-partner-breach-exposes-13-000-buyers) a [úniku SafePal](/en/safepal-data-breach-exposes-nearly-40-000-customers).](/api/img?p=articles%2F7893%2Fimage-0.jpg&w=640)

