Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do newer ransomware families often target backup…
Threats, Abuse & Incident Response

Why do newer ransomware families often target backup services and shadow copies first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Attackers target backups and shadow copies because they reduce the victim’s ability to recover without paying. When recovery paths are disabled, the business impact rises quickly, response options narrow, and negotiation pressure increases. That makes backup protection, immutable storage, and rapid restoration testing core controls, not optional hygiene, for ransomware resilience.

Why ransomware groups go after backups and shadow copies first

Ransomware operators usually attack recovery options before or during encryption because recovery is the victim’s strongest negotiating position. If backups, snapshot systems, and shadow copies remain intact, an organisation can restore data instead of paying. Once those recovery paths are removed, the attacker raises downtime, increases operational pressure, and makes the encrypted data far harder to recover quickly.

That sequence is deliberate. Backup repositories often contain the same high-value data the business is trying to protect, and shadow copies may be reachable from the compromised host itself. If an attacker can delete, corrupt, encrypt, or exfiltrate the recovery set, they can turn a disruptive incident into a far more costly one.

What makes backup systems such an attractive first target

Backups are attractive because they concentrate trust and resilience in one place. They also tend to have broad read access, administrative privileges, and automation hooks that make them efficient for operators but dangerous when an attacker gets valid access. A single compromised account can sometimes reach backup consoles, storage buckets, or snapshot controls that were never meant to be interactive during an incident.

Shadow copies and local restore points are even easier to target on the endpoint itself. Attackers do not need to defeat the entire recovery strategy if they can disable the quick path that would let a defender roll the machine back. That is why ransomware playbooks often begin by stopping backup agents, removing volume snapshots, deleting restore points, or tampering with recovery catalogues.

In practice, the goal is not just destruction, but denial of recovery confidence. If defenders cannot trust that their latest restore point is clean, complete, and reachable, they are forced into slower manual validation and broader incident containment before they can restore at scale.

Why this changes the business outcome of an attack

When recovery is blocked, ransomware becomes much more than a file-encryption event. The organisation loses options, including rapid rollback, selective restoration, and clean-room recovery. That stretches outage duration, increases pressure on help desks and operations teams, and can push the incident toward business interruption rather than a contained security event.

Attackers understand that pressure. Removing backups often increases the chance that leadership will consider payment, or at least creates urgency around making operational decisions with incomplete information. Even when a company refuses to pay, recovery without backups is usually slower, more expensive, and more error-prone because every restore path has to be validated under incident conditions.

Risk and Threat Considerations

Backup compromise is dangerous because it attacks both resilience and trust in the recovery process. A defender may still have copies of data, but if those copies are outdated, inaccessible, or possibly tampered with, the practical value of the backup set drops sharply.

Failure mechanism: Ransomware actors remove shadow copies, delete or encrypt backup stores, and target the systems that manage restore permissions so the victim cannot quickly revert to a known-good state.

Impact: Recovery time increases, downtime expands, and the organisation may be forced to rebuild systems from slower, less certain sources while business pressure and extortion leverage rise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-11 — Data RecoveryBackups and restore testing are central to ransomware resilience.
Recommendation — Maintain tested offline or immutable backups and verify restorability regularly.
NIST CSF 2.0RC.RP-01 — Recovery Plan is ExecutedThe question is about blocking recovery paths and restoring operations after ransomware.
Recommendation — Define and rehearse recovery procedures that restore critical services quickly.
NIST SP 800-53 Rev 5CP-9 — System BackupBackup protection and recovery capability are the core control concerns here.
CP-10 — System Recovery and ReconstitutionShadow copies and backups are first-line recovery assets for ransomware events.
Recommendation — Protect backups with separate controls and verify they can be restored when needed. Test recovery and reconstitution procedures against destructive malware scenarios.
ISO/IEC 27001:2022A.8.13 — Information backupBackup integrity and recoverability are directly implicated by ransomware targeting backups.
A.5.30 — ICT readiness for business continuityRansomware that disables recovery paths is fundamentally a business continuity threat.
Recommendation — Implement backup controls that preserve availability, integrity, and recoverability. Ensure continuity planning includes protected recovery mechanisms and restore testing.

Practitioner Guidance

What to prioritise: Treat backup access and restore authority as part of the attack surface, not just an operations task. The most important control objective is not simply having backups, but preserving at least one recovery path that a compromised production account cannot reach or destroy.

What to verify: Confirm that backups are isolated from everyday admin credentials, that restore credentials are separate from backup-write credentials, and that restore tests prove you can recover under real incident constraints. If the last successful backup is visible but not restorable, it is not a reliable control.

What practitioners underestimate: Shadow copies and snapshot features are often the fastest recovery path, so they are also the first path worth hardening, monitoring, and testing. Ransomware resilience depends on whether recovery survives compromise, not on whether backups merely exist.

Practitioner takeaway: The right question is not whether the organisation has backups, but whether an attacker who lands on one system can also destroy the evidence, the snapshots, and the path back.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org