logo

Why Ransomware Deletes Your Backups Before You Know You've Been Hit

ID: 8146f4c5-88e7-5795-afde-275eade4b8d4

STIX ID: report--8146f4c5-88e7-5795-afde-275eade4b8d4

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-25

...
...

Most modern ransomware attacks deliberately target and neutralize backup infrastructure (MITRE T1490) during extended dwell periods (avg >70 days) to force victims to pay; attackers succeed in compromising backups at high rates (document cites 96% targeting and 76% success) by abusing admin credentials to change retention, delete catalogs, and bypass immutability/quorum/air-gap defenses. The report explains why recovery timelines extend (22–38 days) due to identity and forensic recovery needs, and outlines Halcyon's three-layer approach: intercept active encryption, inoculate other systems to limit spread, and capture encryption key material at execution time to enable decryption without backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.