Ransomware groups now target backup systems in attacks
Recent reports highlight a shift in ransomware tactics, with criminal groups increasingly targeting backup infrastructure during attacks. Groups like ALPHV/BlackCat, BlackMatter, and Gunra have actively sought out and wiped backup data before encrypting victims' primary systems, making recovery far more difficult or impossible. As a result, some organizations have paid large ransoms but still failed to regain access to their data, facing substantial financial losses instead.
- Ransomware groups now erase backups before encrypting data
- Multiple groups have adopted this strategy since 2021
- Victims have been unable to recover even after ransom payments
- Authorities have documented tactics and issued warnings
Sources covering this
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.