Ransomware backup attacks follow a consistent five-step sequence: attackers map your backup repositories, change retention settings to purge older copies, delete the backup catalog, try to release immutability locks, and stop backup services before encrypting. Veeam’s 2024 Ransomware Trends Report found attackers target backup repositories in 96% of attacks and compromise them 76% of the time [1].
TL;DR
Attackers often spend days or weeks inside a network before they encrypt anything, and they use that time to work through these steps. The table below maps each step to the control that answers it: a second backup copy on a separate network, immutable storage that keeps deleted backups recoverable, compliance mode that no administrator can switch off, and behavioral detection that isolates backups before encryption.
How much time you have
The fastest quarter of intrusions reached data exfiltration in 72 minutes in 2025, down from 285 minutes a year earlier, according to Unit 42’s 2026 Global Incident Response Report [2]. Mandiant’s M-Trends 2026 found the median handoff between the broker who sells initial access and the group that deploys ransomware fell to 22 seconds, from more than 8 hours in 2022 [3].
At that speed, a plan that depends on someone noticing an alert starts too late. The controls that count are the ones that act on their own.
How ransomware backup attacks work
Attackers rarely strike the moment they get in. They usually spend days or weeks inside the network first, and they use that time in a consistent order. Here is each step and what stops it.
| What the attacker does | What stops it |
|---|---|
| 1. Maps backup repositories and retention policies | A second backup copy on a separate network. A compromised domain account can only map what its own network reaches. |
| 2. Changes retention settings to purge older backup generations | Immutable storage locks each backup copy against modification or deletion for 14 days. |
| 3. Deletes the backup catalog | Immutable storage keeps deleted backups. Even if attackers delete backups from the console, they stay in immutable storage for the retention period, where you can still browse them and recover data. |
| 4. Tries to release immutability locks | Compliance mode. Once you switch it on, nobody can disable the lock, administrators included. |
| 5. Stops backup services, then encrypts | Machine learning-based detection watches backup processes for ransomware behavior and isolates backups before encryption completes. |
| After the attack: you restore | Restore into an isolated environment first, and check the workload is clean before it goes back into production. |
Here’s step 4 failing in practice, with compliance mode switched on. An attacker compromises an admin account at 2 AM and deletes every recovery point before deploying ransomware at 6 AM. The deletion goes through, but every recovery point is still in immutable storage, and the attacker can’t switch that protection off. You restore from it.
Sophos’s research on ransomware backup attacks shows what that difference is worth. When backups were compromised, the median recovery cost was $3 million. When they stayed intact, it was $375,000. 46% of organizations with intact backups fully recovered within a week, against 26% of those whose backups were hit [4].
Where compliance comes in
For EU organizations in scope of NIS2, backup and disaster recovery are required risk-management measures, with fines up to €10 million or 2% of global turnover for essential entities, and personal liability for management [5]. Commission Implementing Regulation 2024/2690 sets the technical requirements for digital infrastructure and ICT service providers. When we ask customers which frameworks matter to them, GDPR and ISO 27001 come up most, and immutable storage supports the requirements of both. If you want a second opinion on your setup, talk to our team.
Ransomware backup attacks in the real world
The attack on Jaguar Land Rover, which began on August 31, 2025, halted production in the UK, Slovakia, Brazil, and India. It cost £485 million in pre-tax losses for the quarter and led to a £1.5 billion UK government loan guarantee to stabilize JLR’s suppliers [6][7]. JLR had no cyber insurance.
European ransomware incidents rose 55% year over year into early 2026, to an average of 171 a month [8].
Since 1997, we’ve built infrastructure so customers decide where their data lives and who can change it. With Acronis on Leaseweb, you choose the data center that holds your backups, and with compliance mode switched on, the 14-day lock on them holds even if an admin account is compromised. For the recovery side of this story, read our piece on backup recovery testing.
About the survey: We run this survey to understand how customers use Acronis on Leaseweb and where we can help them get more out of it. Leaseweb surveyed customers using Acronis Cyber Protect on Leaseweb in June 2026. Between 40 and 43 customers answered each question. With a sample this size, the results describe this group of Leaseweb customers and aren’t statistically representative of all backup users.
See how Acronis on Leaseweb protects backups before encryption happens