Ransomware Hits 90% of Backups, Pushing Recovery Readiness as New Standard
Updated
Updated · ZDNet · Aug 10
Ransomware Hits 90% of Backups, Pushing Recovery Readiness as New Standard
3 articles · Updated · ZDNet · Aug 10
Summary
More than 90% of ransomware attacks now try to delete or tamper with backups before deploying payloads, and nearly 60% of those backup-focused attacks succeed.
That shift is exposing a core weakness: backup copies alone do not ensure operations can restart fast enough to avoid downtime, lost revenue and customer churn.
About four in five ransomware attacks now begin with identity-based access, while cloud and SaaS setups add risk—69% of monitored 2025 SaaS accounts were guest accounts and only 27% of SMBs enforced MFA.
Recovery readiness remains thin across many firms: only 1 in 5 organizations report unified backup protection in hybrid environments, 53% of IT professionals are only somewhat confident in restoration, and just 18% test monthly.
Insurers and regulators are raising the stakes, with frameworks including CMMC, GDPR, NIS2 and DORA increasingly treating tested recovery, accurate RTOs and business continuity as obligations.