For years the standard advice after a ransomware attack has been simple: wipe the affected computers and restore from backup. Attackers know this too. That is why many of them now look for your backups before they do anything else, and try to delete or lock them so you have no choice but to deal with them.
A report Microsoft published on September 25, 2026 shows how quickly this can happen in the cloud. For a small business in New York or anywhere else, the lesson is not to panic. It is to check that at least one copy of your data is out of an attacker's reach, and that you know how to bring it back.
What Microsoft found
Microsoft's security researchers described an attack on a company's Microsoft Azure environment (Azure is Microsoft's cloud platform for servers, storage and databases) by a group it tracks as Storm-3168. Here is what the report says happened:
- The way in was a leaked password for an app. An employee had posted the login details for a "service principal" in a public GitHub issue. A service principal is an account that software uses, rather than a person, to sign in to cloud services. The details stayed visible in the post's edit history even after they were removed from the post itself.
- The attackers looked around first. One compromised account spent about 15 and a half hours quietly listing servers, storage and other resources, with more than 300 successful read requests.
- Then they moved fast. A second account made more than 150 destructive or credential-related attempts within 35 minutes, including over 100 attempts to delete storage accounts. It also deleted a Key Vault, which is where passwords and encryption keys are stored.
- They went after recovery. The attackers tried to remove the locks that protect Azure Backup and Azure Site Recovery, the services used to restore systems after a disaster.
According to The Hacker News, the same group has previously been linked by the security firm Sysdig to a ransomware operation run with the help of AI tools, which helps explain how so many actions were packed into such a short window.
The good news: separate protections held
Not everything was lost. Microsoft reports that the attempts to remove the Azure Backup and Azure Site Recovery protection locks failed, and that resource locks and deletion protection stopped some storage accounts from being deleted. Microsoft notes these safeguards worked even though the stolen account had broad administrative permissions.
That is the most useful takeaway for any business owner. A backup is only as safe as the weakest account that can delete it. Protections that sit apart from your everyday logins can buy you the time you need to recover.
Why backups are a target for every business, not only large ones
You do not need to run servers in Azure for this to matter. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns in its #StopRansomware Guide that many types of ransomware try to find and then delete or encrypt any backups they can reach. The same thing can happen to:
- An external hard drive left plugged into the office server or a front-desk PC.
- A network storage box (often called a NAS) that every computer in the office can write to.
- A cloud backup account that uses the same password as someone's email.
- Microsoft 365 or Google Workspace data that an administrator account can delete in a few clicks.
If an attacker can sign in as you, they can usually do anything you can do, including deleting your backups.
Five steps to make your backups harder to destroy
- Keep at least one copy offline or immutable. CISA recommends offline, encrypted backups of critical data. "Immutable" storage means a backup that cannot be changed or deleted for a set period, even by an administrator. Either approach keeps one copy out of reach if your network or accounts are taken over.
- Use separate logins for backups. The account that manages your backups should not be the same one used for daily email and web browsing. Protect it with multi-factor authentication (a second check, such as a code from an app, on top of the password).
- Turn on deletion protection and locks where your services offer them. The Microsoft case shows these settings can stop deletions even when an attacker has administrator access. Many backup and cloud storage services offer a similar "soft delete" or retention setting that keeps deleted data recoverable for a period of time.
- Treat app keys and passwords like cash. Never paste passwords, API keys or connection details into support forums, shared documents, chat threads or code repositories. If one is ever exposed, Microsoft's advice is to revoke or rotate it right away, because deleting the post does not make the leaked secret stop working.
- Give accounts only the access they need. Microsoft recommends "least privilege," meaning each account, including accounts used by software, gets only the permissions its job requires. An account that only needs to read files should not be able to delete storage.
Test your restores, not just your backups
A green check mark in your backup software tells you a job finished. It does not tell you that you can actually get your business running again from it. CISA's guide recommends regularly testing that backups are available and intact, and keeping ready-to-use system images so machines can be rebuilt quickly.
A simple routine for a small office:
- Every month, restore a handful of files from different folders and confirm they open correctly.
- A few times a year, restore a whole computer or server to spare hardware or a test environment and time how long it takes.
- Write down who does what during a recovery, where the backup logins are kept and who your IT contacts are. Store a printed copy somewhere other than the office network.
Watch for the quiet part of an attack
In the Microsoft case, the attackers spent many hours exploring before they started deleting anything. That quiet period is a chance to catch them. Microsoft's recommendations include restricting and monitoring access to backup and recovery systems. For a small business, that can mean turning on alerts for unusual sign-ins, new administrator accounts, failed backup jobs and large numbers of deletions, and making sure someone actually reads those alerts.
How Rise Technologies can help
Rise Technologies is a New York-based IT consulting and support company that has served businesses across New York, Long Island and the Tri-State area for over 10 years. We can review how your data is backed up today, set up onsite and offsite backup with offsite replication, and help you recover data when something goes wrong through our data backup and recovery services. Our security management covers firewalls, managed antivirus, patch management, ransomware protection and monitoring. If you are not sure where your gaps are, an IT assessment is a good place to start.
Want to know whether your backups would survive an attack? Call Rise Technologies at (516) 545-0065 or request a free quote, and one of our certified engineers will walk you through your options.



