Yes, ransomware can infect backups, and modern attackers deliberately go after them first because a business with no clean copy is far more likely to pay. Backups get encrypted or deleted when they sit on the same network with the same credentials as everything else, when a synced cloud folder is mistaken for a backup, or when the backup console itself is reachable by the attacker. The fix is to keep at least one copy that cannot be altered or deleted by anyone, including an administrator, for a fixed period of time.
How does ransomware reach backups?
It helps to understand that ransomware is no longer a virus that spreads randomly. It is a person, or a team, who has been inside the network for days or weeks before anything is encrypted. During that time they do reconnaissance, and the backup system is high on the list. Here is what we see when we perform incident response for businesses on the Treasure Coast.
Shared credentials
The backup software runs under a domain administrator account, or the backup server is joined to the domain and managed with the same passwords as everything else. Once the attacker has domain admin, they have the backups. They log into the console, delete the backup chains, and only then trigger encryption.
Network-attached storage on the same network
Backups written to a NAS or a USB drive that is always connected are just another writable share. Encryption software simply walks through it like any other folder. External drives are only protection when they are disconnected, and in practice they rarely are.
Cloud sync mistaken for backup
OneDrive, Dropbox, and Google Drive replicate your working folders. When files on a workstation are encrypted, the sync client uploads the encrypted versions immediately. Version history may let you recover individual files, but restoring tens of thousands of files that way is slow, the retention window is limited, and some attackers now explicitly purge version history using the account they have compromised.
Backup consoles exposed to the internet
Web management interfaces for backup appliances and cloud backup portals get attacked directly, especially when they lack multi-factor authentication or run old firmware. Widely reported campaigns have targeted popular backup platforms specifically.
Long dwell time
Even when backups survive, an attacker who has been inside for six weeks means your last six weeks of backups may contain their tools and back doors. If you only keep two weeks of history, you have no clean point to restore to.
What is the difference between sync and backup?
This distinction is the source of most of the false confidence we encounter, so it is worth stating plainly. Sync keeps two or more locations identical; whatever happens in one happens in the others, including damage. Backup takes a separate copy at a point in time, stores it somewhere the original systems cannot modify, and keeps multiple versions going back weeks or months. Sync services are excellent for collaboration and are a reasonable defense against a dead laptop. They are not a defense against ransomware, an angry employee, or a mistake that goes unnoticed for a month.
How do you make backups ransomware-proof?
No system is invulnerable, but four controls together make it extremely unlikely that an attacker can leave you with nothing to restore.
1. Immutability
Immutable storage accepts new backups but does not allow existing ones to be changed or deleted until a retention period expires, even by an administrator with valid credentials. Most modern backup platforms and cloud storage services offer this as a setting. It is the single most important control on this list, and it is increasingly required by cyber-insurance carriers.
2. Separate credentials and separate management
The backup system should not trust your domain. It gets its own accounts, its own multi-factor authentication, and ideally its own network segment. Domain admin on your network should mean nothing to the backup console. Alerts on any deletion or retention change go to someone who will actually read them.
3. An offline or off-site copy
The 3-2-1 rule still applies: three copies, two different media or platforms, one off site. For a Florida business the off-site copy should be outside the hurricane zone, because the storm that floods your office will also flood the closet where the backup appliance lives. A copy in a data center in another region, replicated automatically, satisfies both the ransomware and the weather requirement. Truly offline media such as rotated drives or tape still have a place for the most critical data, provided someone actually rotates them.
4. Retention long enough to outlast dwell time
Keep daily restore points for at least 30 days and monthly points for a year. That way a restore from before the intrusion is always available, and you can rebuild systems from a known-clean date while recovering the most recent data files separately after scanning them.
How do you know your backups would survive an attack?
Ask your provider, or yourself, these questions and expect specific answers:
- If someone had domain administrator rights on our network right now, could they delete our backups? How do we know?
- Is immutability turned on, for how long, and where is the proof?
- When was the last time we restored a full server, how long did it take, and did the application work afterward?
- How many days of history do we have, and how many months?
- Is the backup console protected by multi-factor authentication and kept off the public internet?
If any of those produce a pause, that is the gap to close. Our backup and disaster recovery service was redesigned around these questions after seeing what happens to businesses that could not answer them.
What if the backups are already gone?
Sometimes there is still a path. Immutable cloud snapshots the attacker did not know about, an old rotated drive in a desk drawer, database files on a workstation, or vendor-hosted copies of application data can be pieced together. Specialized data recovery techniques can occasionally salvage partially encrypted volumes. It is slow and uncertain, which is exactly why the four controls above are worth putting in place now.
MainSail Data will review your backup design against modern ransomware tactics at no charge for any business in Indian River, St. Lucie, or Martin County, and tell you honestly whether a determined attacker could reach your last copy. Call (772) 794-1194 or schedule a backup review.

