Nowadays, ransomware gangs are constantly improving their techniques, and one of the things they try to do is to compromise backups. This way, they want to ensure that encrypted data cannot be restored.

Organizations that lose their backups are forced to pay ransoms to hackers and lose much more time in the recovery process, according to Sophos.
See also: City of Pensacola confirms ransomware attack
The company surveyed nearly 3,000 IT and cybersecurity whose organizations suffered a ransomware attack in 2023. Nearly all respondents said the attackers also tried to compromise their backups.
According to the research, organizations in the energy, oil, gas, and utilities sectors were most likely to lose their backups ransom to ransomware (79%). Across all sectors, more than half (57%) of breach attempts were successful. As a result, demands increased. Victims whose backups were compromised were asked to pay significantly more money than other companies that had backups their. The average payout was approximately $2.3 million (in cases of backup compromise) and $1 million (when backups were not compromised).
See also: Carolina Foods company fell victim to ransomware attack
Not surprisingly, organizations with compromised backups were almost twice as likely to pay ransom to ransomware gangscompared to those with secure backups ( 67% vs. 36%). Furthermore, in these cases, negotiating ransoms was difficult, as the attackers knew their advantage.

Backup protection
In general, the first protection strategy is to use the 3-2-1 method. This means that you should keep three copies of data , on two different media, one of which is offline.
Additionally, protecting copies with passwords and other security measures can prevent ransomware gangs from accessing them.
Using intrusion detection software and behavioral analysis to identify threats in real time can also help protect backups.
See also: City of Huntsville confirms ransomware attack
Finally, educating users on how to recognize and avoid ransomware attacks is crucial. This can include learning about phishing and recognizing dangerous attachments and links.
“Backups are a key part of a holistic ransomware risk mitigation strategy ,” the researchers said. “If your backups backups and store them in multiple locations. Be sure to add MFA (multi-factor authentication) to cloud backup accounts to prevent attackers from gaining access, practice recovering from backups, and secure your backups.”
Source: www.techradar.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
