A report on a group calling itself n0n describes a tactical shift in cyber extortion: ransomware without encryption backup destruction. Instead of locking files and demanding payment for a decryption key, the group reportedly wipes out recovery options and threatens to expose stolen data. The source article we reviewed was truncated, so this post sticks to the high-level picture it describes and to widely understood defensive practice rather than specifics we cannot verify.
How n0n's Backup-Destruction Playbook Works
According to the report, n0n's approach skips the encryption stage that has defined ransomware for years. The emphasis falls on two things: destroying a victim's backups and threatening to release data the group has taken.
The logic is straightforward. Traditional ransomware creates pressure by making systems unusable. Defenders answer by restoring from backups, which is why many ransomware operators have long tried to find and delete accessible backups first. Removing that safety net raises the stakes without needing to encrypt a single production file.
We do not have confirmed technical details on n0n's tooling, entry points, or victim counts from the material provided, so we are not going to speculate on them. What matters for defenders is the pattern: attackers who gain privileged access can go after backup infrastructure directly.
Why Encryption-Free Extortion Shifts the Pressure to Data Exposure
When there is no encryption, there is often no obvious outage. Systems keep running, which can make an intrusion quieter and harder to notice. The leverage comes from a different place: the threat that sensitive data will be published or sold.
This changes the victim's calculation. Restoring from a clean backup solves downtime, but it does nothing about data that has already left the network. Customer records, employee information, contracts, and internal communications cannot be "restored" once they are in someone else's hands.
That is also why privacy matters here. Organizations that hold personal data face regulatory, legal, and reputational consequences from exposure regardless of whether their servers were ever locked. A similar dynamic appeared in the Revolut data extortion breach, where the crisis came from extortion over data rather than classic malware on servers.
Why Traditional Backups and Offline Copies Fall Short
For years, the standard advice was to keep offline backups. That is still sound, but the n0n report suggests it is no longer sufficient on its own. A few gaps are worth understanding:
- Backups protect availability, not confidentiality. A perfect restore does not un-steal data.
- Backup systems are reachable. Backup consoles, cloud storage, and admin credentials are often accessible from the same environment an intruder has compromised.
- Offline copies can be stale. Backups that are disconnected but rarely tested or updated may not support a full recovery when it matters.
- Legitimate tools hide theft. Data can leave through ordinary cloud storage channels. In an earlier case involving Vice Society, attackers abused OneDrive for data theft, a reminder that trusted services can become exfiltration routes.
The takeaway is not that backups are useless. They remain essential. They are just one layer, and attackers are plainly aware of that.
Hardening Steps: Immutable Backups, Segmentation, and Monitoring
Defenders can reduce exposure to this model with controls that address both backup destruction and data theft.
Make backups immutable. Use storage that cannot be altered or deleted for a set retention period, even by an administrator account. This blunts an attacker who obtains privileged credentials.
Separate backup access from everyday admin access. Backup systems should use their own credentials, protected with multifactor authentication, and should not share a login domain with general servers where practical.
Segment the network. Limit which systems can talk to backup infrastructure and to the internet. Segmentation slows lateral movement and makes large data transfers easier to spot.
Encrypt data at rest. Encrypting sensitive data and backup contents can reduce the value of anything taken.
Monitor for exfiltration and backup tampering. Alert on unusual outbound transfers, sudden deletion of snapshots, changes to retention policies, and new use of cloud-copy tools.
Test restores and rehearse response. Know how long recovery takes and who makes the call when a threat to publish data arrives.
What This Means For You
If you run or advise a small or mid-sized business, the key point is that "we have backups" is no longer a complete answer to ransomware. Ask a second question: "What happens if the data is stolen and the backups are gone?"
Individuals are affected indirectly. When organizations holding your personal data are extorted, your information is what is at stake. Use unique passwords, enable multifactor authentication, and watch for phishing that references a breach, since extortion campaigns can spawn follow-on scams such as the one described in our coverage of the Ransom Busters scam targeting victims.
Audit Your Backups and Access Controls Now
Ransomware without encryption backup destruction rewards attackers who find weak access controls and unprotected backups. Start this week:
- List where your backups live and who can delete them.
- Turn on immutability and separate backup credentials.
- Require multifactor authentication on all admin and backup accounts.
- Set alerts for large outbound transfers and backup deletions.
- Run a restore test and write down the result.
Speed matters too. Attackers are compressing the time victims have to react, as explained in our piece on why ransomware gangs now give victims just 7 days. The best time to check your defenses is before a deadline appears in your inbox.




