// 1 CRITICAL · 2 ZERO-DAY · 6 CVE · 2 EXPLOIT IN THE LAST 24H→
Ransomware groups have turned backup destruction into standard operating procedure. Sophos confirms 94% targeting rate: the resilience of the last line of defense is under siege.

On October 7, 2026, the ransomware landscape shifted onto ground that until two years ago was considered safe. No longer just encryption of active data, but systematic siege of recovery infrastructure: according to the Sophos 2026 survey cited by Threatcop, 94% of organizations hit by ransomware suffered explicit targeting of their backups during the attack. The news isn't the novelty of the threat, but its standardization. What was the modus operandi of groups like BlackMatter in 2021 is today a shared operational procedure, with direct consequences for how enterprises must architect resilience.

Key Takeaways
  • 94% of ransomware victims face backup targeting: destruction of recovery copies has become a priority tactic, not collateral damage.
  • The n0n group, emerged in September 2026, explicitly threatens to encrypt or destroy backups and shadow copies; 23% of its victims fall in the financial services sector.
  • Gunra, documented in a joint CISA/FBI advisory from August 2026, wiped primary and disaster recovery backups using a single compromised credential.
  • 60% of U.S. organizations recovered via backup in 2026, up from 43% in 2025: defensive improvement drives attacker escalation.

From BlackMatter to n0n: How Backup Destruction Became Standard

The genesis of the pattern is documented. BlackMatter in 2021 made the search and deletion of every backup datastore on the victim network its standard operating procedure, according to BleepingComputer's reconstruction. The goal was to eliminate any alternative to paying the ransom, narrowing the victim's negotiating window to zero.

Five years later, the n0n group has taken this logic to its rawest expression. Emerging with first sightings on September 18, 2026, according to Infosecurity Magazine citing CyberXTron data, n0n explicitly threatens to "encrypt or destroy backups and shadow copies" in its extortion messages. The psychological timer on the leak site serves as additional leverage. 23% of identified victims fall in the financial services sector, but precise geographic distribution is not documented in the analyzed dossier.

The joint CISA/FBI advisory from August 2026 on the Gunra group offers the paradigmatic case of how backup destruction is implemented in practice. Gunra deleted backups and archived data both in the primary data center and the disaster recovery site, exploiting a single compromised credential for both environments. Shared identity and permissions between production and recovery opened the breach.

The Mathematics of Resilience: Why Backups Became Targets

The mechanism is readable in the numbers. Sophos 2026 records that 60% of U.S. organizations recovered via backup in 2026, versus 43% in 2025. 55% of victims restore their environment within a week. These data, cited by Threatcop, indicate that "defenders are getting better at using backups to route around the ransom demand." The attackers' response is predictable: if an independent recovery path exists, the extortion model fails. Attackers colonize that same path.

The average cost of a ransomware incident is $5.08 million according to IBM 2025, reported by BleepingComputer. For the February 2024 Change Healthcare/UnitedHealth attack, the ransom paid was $22 million; estimated recovery costs reached $1.6 billion. Backups, in that case, were "not isolated or sufficiently robust," according to the same source's reconstruction. The lesson isn't in the single incident, but in the repetition of the pattern: resilience built without architectural separation becomes organizational vulnerability.

"A backup is only a safety net if the attacker cannot reach it" — BleepingComputer

Identity as Achilles' Heel: 79% of Attacks Originate from Compromised Credentials

The primary vector isn't technical in the traditional sense. According to Sophos 2026 data cited in the company's official press release, 79% of ransomware attacks originate from compromised identities. Malicious email (26%) and phishing (24%) are the main technical causes. 67% of victims confirmed that the ransomware incident was also their most significant identity attack.

The architectural consequence is direct: if credentials for accessing backup systems are the same — or derived from the same identity provider — as those for production, compromise of a privileged user opens both environments. Gunra exploited exactly this continuity. The problem isn't in the backup software itself, but in its placement in the network topology and authorization model.

BleepingComputer flags an emblematic case: the Akira group's attack exploited vulnerabilities in backup software for which a patch had been available for over a year. Backup servers, the source notes, are "treated as appliances rather than software systems," with slower update cycles and reduced visibility in vulnerability management programs.

The Gap Between Backup and Recovery: Monthly Tests Are a Minority Practice

Technical availability of copies does not equal operational restore capability. According to the Kaseya report cited by ZDNet, only 18% of organizations test recovery capability monthly. 53% declare themselves only "fairly confident" of being able to restore the environment. The distinction between "backup" and "recovery," underscored in the report with the formula "Backup isn't recovery," has concrete operational implications: the copy exists, but the activation path is unreliable.

Adding to this is infrastructure fragmentation. Only 1 in 5 organizations has unified backup protection across hybrid environments, according to the same Kaseya data. Migration to cloud and multi-cloud has dispersed recovery surfaces across more vendors and configurations, reducing overall visibility. The source does not specify how this fragmentation numerically influences attack success.

Why It Matters

The dossier does not specify the exact success rate of backup destruction versus the 94% that suffer targeting: the data measures attacker intentionality, not complete action effectiveness. It is not documented whether the n0n group actually destroyed backups in all cases or whether the threat functions primarily as psychological pressure.

The brief does not list specific remedial measures nor verify the real-world effectiveness of countermeasures like immutability and air-gapping in mass deployments. The source does not detail the geographic distribution of n0n victims beyond cited examples, nor provide metrics on average RTO (Recovery Time Objective) achieved in post-attack restore operations.

The data that remains is the trend direction: improved defensive recovery capabilities have triggered an arms race in which architectural isolation of backups becomes the dividing line between a manageable incident and operational collapse. The demarcation is no longer between those who back up and those who don't, but between those who built a recovery path the attacker doesn't know exists and those who didn't.

The impact on cyber insurance is implicit in the numbers: with average costs of $5.08 million and recovery exceeding $1 billion in extreme cases, coverage requirements tighten around tested and verifiable RTO and RPO. 41% of incidents in 2026 included threats to brand reputation, according to BleepingComputer, extending the damage perimeter beyond the technical.

FAQ

Does 94% backup targeting mean backups are always successfully destroyed?

No. The Sophos 2026 data measures the percentage of organizations that suffered backup targeting during the attack, not the percentage of successful complete destruction. The dossier does not specify how many of these attempts succeeded.

Why is the n0n group significant if backup destruction existed in 2021?

n0n doesn't innovate the mechanism but accelerates its explicit standardization: the threat to "encrypt or destroy backups" is publicly declared as a negotiating lever, removing ambiguity about offensive posture and reducing the victim's decision time.

What is the relationship between compromised identities and backup vulnerability?

According to Sophos 2026, 79% of attacks originate from compromised identities. If credentials for accessing backup systems share the same identity provider or privilege level as production, compromise of one identity opens both environments. Gunra operated on exactly this principle.

Information is based on cited advisories and current as of publication.

Sources

Information is based on cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. infosecurity-magazine.com
  3. threatcop.com
  4. zdnet.com
  5. sophos.com
  6. kaspersky.com
  7. content.govdelivery.com