When data is deliberately destroyed or encrypted.
WHAT IT LOOKS LIKE
Files encrypted or replaced A ransom message Database tables dropped or emptied Backups on the server deleted deliberately
WHY THIS IS DIFFERENT
An attacker with access will look for and destroy backups stored on the same account. This is standard practice in these attacks.
Only backups stored elsewhere survive.
IMMEDIATE ACTION
Open a ticket immediately Do not pay. There is no assurance of recovery and it funds further attacks Take a copy of the current state for evidence Change every credential
RECOVERING
Restore from an off-server backup predating the attack.
Check our server-side restore points, which are outside the attacker's reach.
IF EVERYTHING WAS ON THE SERVER
This is the scenario where people lose everything. It is the entire reason off-server backups matter.
AFTERWARDS
Rebuild credentials completely. Assume everything on the account was accessible.
Identify and close the entry point before restoring, or it recurs.
PREVENTION
Off-server backups, several copies, one of which is not accessible from the hosting account.