This article keeps to what government advisories and primary sources support. It leaves out several vendor claims that couldn't be verified.
Backup destruction is a tactic, not a trend
Two US government advisories show the same behavior five years apart.
BlackMatter (2021). A joint advisory from CISA, the FBI and the NSA covered BlackMatter ransomware. It said BlackMatter actors targeted multiple US critical infrastructure entities since July 2021, including two food and agriculture organizations. The advisory's technical detail matters to Windows administrators. The variant it analyzed used embedded, previously compromised credentials with LDAP and SMB. It used them to enumerate hosts in Active Directory and remotely encrypt shares, including ADMIN$, C$, SYSVOL and NETLOGON. It also said that, rather than encrypting backup systems, BlackMatter actors wipe or reformat backup data stores and appliances. Ransom demands ran from $80,000 to $15 million in Bitcoin and Monero.
Gunra (2026). On August 10, 2026, CISA and the FBI released joint advisory AA26-222A with partners. Those partners included the NSA, the US Secret Service, the Department of Defense Cyber Crime Center and the Republic of Korea's National Police Agency. The advisory's technique table says that Gunra actors disable backup features such as volume shadow copies to augment encryption and prevent system recovery. It adds that in one instance they prevented restoration by deleting backup and archived data at the primary data center and the disaster recovery center.
That is one documented victim, not a statement about every Gunra intrusion. Secondary coverage says the deletion happened both before and after the ransomware deployment.
The "single stolen key" claim
The sponsored article says a single set of stolen credentials reached both sites. The official summaries I reviewed don't spell that out. Secondary analysis from backup vendor Eon does. It says the reach came from one key taken from a central access-control server, and that key decrypted the stored passwords for every enterprise server.
Treat that as vendor analysis of the advisory, not a government finding. It is plausible and consistent with the advisory's lessons. I couldn't confirm the exact wording in the advisory itself, so read the Impact section before quoting it.
The lesson holds either way. Two sites that trust the same identity plane are one failure domain.
How Gunra got in
The Gunra advisory is a reminder that backup protection starts well before the backup server.
- Secondary reporting says the advisory names two FortiOS/FortiProxy authentication-bypass flaws, CVE-2024-55591 and CVE-2025-24472, plus default credentials on internet-facing SSL-VPN appliances.
- TechTimes reports that patches for both CVEs were released in January and February 2025, and both are in CISA's Known Exploited Vulnerabilities catalog.
- In CISA's key actions, the first is to prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure.
- Reporting on the advisory also describes attackers tampering with the VPN authentication flow so that MFA no longer stopped them. That is a reason to monitor appliance configuration, not just to enable MFA.
What the agencies tell you to do
The two advisories give a consistent list.
- Keep offline, immutable backups. BlackMatter guidance says to maintain offline backups and regularly maintain backup and restoration. It also says backups should be encrypted and immutable, meaning they cannot be altered or deleted. The Gunra summary says to implement and test offline, immutable backups stored in a physically separate, segmented location.
- Segment the network. CISA recommends segmenting networks to restrict lateral movement from an initially compromised device.
- Use strong, unique passwords and MFA. The BlackMatter advisory applies this to service, admin and domain admin accounts.
- Limit access to administrative shares. Remove unnecessary access to ADMIN$ and C$. Use host-based firewalls to allow SMB to administrative shares only from a limited set of admin machines.
- Use just-in-time admin access. Time-based access for admin-level accounts shrinks the window in which a stolen credential works.
- Scan backups before restoring. If possible, check backup data with antivirus to confirm it is free of malware.
A practical audit for Windows shops
This section is my analysis, built on the agencies' guidance. It is not a vendor checklist.
Who can delete your backups? List every account, group and service principal with delete or administrative rights on the backup platform and its storage. If a domain admin can do it, a stolen domain admin credential can too.
Is the backup server domain-joined to production? A backup server on the same Active Directory shares the same blast radius. A separate identity store, or at least dedicated accounts with MFA, breaks the chain. Secondary reporting on the Gunra advisory says to ensure backup infrastructure cannot be reached using ordinary domain credentials.
Does a second site mean a second trust boundary? Replication to a disaster recovery site is not isolation if both sites accept the same credentials or key.
Is "immutable" configured, not just purchased? Immutability prevents alteration or deletion during a defined retention period. It depends on correct configuration and on who holds account permissions. It complements offline copies and restricted administration. It does not replace them.
Have you tested a restore? A green backup job proves the job ran. It doesn't prove you can rebuild a domain controller, a database server and a NAS in the right order. The agencies recommend regularly testing restoration. They don't mandate a cadence.
Is the backup software patched? The sponsored article claims an Akira airline attack exploited a vulnerability whose patch had been available for over a year. I couldn't verify that claim, so I haven't relied on it. The general principle still stands. CISA's BlackMatter advisory says timely patching is one of the most efficient and cost-effective steps an organization can take.
Are volume shadow copies your only fallback? Gunra disables them, so treat them as convenience, not recovery.
If Linux systems are hit
The Gunra advisory includes a notable incident-response instruction. For a Gunra Linux variant, preserve encrypted files, file timestamps, ransom notes and relevant system logs. TechTimes reports that file timestamps can make key reconstruction practical, and that the Windows variant (.ENCRT extension) is not recoverable through this method. If you run mixed estates with ESXi or Linux file servers, don't reboot or wipe before consulting CISA or the FBI.
Figures to treat with care
The sponsored article cites several numbers. Here is what holds up.
- Change Healthcare. The article claims a $22 million ransom, no data returned, and $1.6 billion in recovery costs. The primary-source material I reviewed doesn't establish those figures. It also doesn't verify that the intrusion came through a portal without MFA. UnitedHealth's April 22, 2024 update shows the scale of disruption and recovery. It said approximately 80% of functionality was restored on major platforms and products, and payment processing was at about 86% of pre-incident levels. Don't use Change Healthcare as a proven "backups failed" case study on this evidence.
- IBM's $5.08 million. The 2025 Cost of a Data Breach release says the average cost of an extortion or ransomware incident remains high, particularly when disclosed by an attacker, at $5.08 million. That is the attacker-disclosed figure, not an average for all ransomware incidents.
- IBM's 41%. IBM's 2026 report is based on 602 organizations globally between March 2025 and February 2026. It says attackers most commonly exploit brand reputation (41%), followed by employee data (35%) and intellectual property (31%). That shows extortion pressure goes beyond encryption. It doesn't prove that backup deletion drives those figures.
- Kaseya's survey. Kaseya says its report draws on 1,132 MSPs and IT professionals. It reports that 77% describe themselves as under-resourced in some way and that 65% of MSPs say clients are underinvested. It is vendor research, so read it as a sentiment snapshot, not a census.
Bottom line
The strongest advice comes from the agencies, not the sponsor. Count the credentials, networks and administrators that connect your copies, not just the copies. Keep at least one recovery path that production credentials cannot touch. Patch the edge devices that let attackers in. Then run a restore and see what breaks while the stakes are low.
References
- Ransomware has a new target. Is your backup ready? BleepingComputer · 2026-10-07T10:01:11-04:00
- #StopRansomware: Gunra Ransomware cisa.gov
- BlackMatter Ransomware | CISA cisa.gov