Skip to content
CIM-180 Cyber Incidents & Offender Methods

What evidence may show backup targeting?

The practical answer

Backup targeting is activity directed towards preventing recovery or obtaining access to backup data.

The key evidential caution

The dangerous assumption is that unavailable backups prove the offender deliberately destroyed them.

They may be unavailable because of configuration, retention, technical failure or response actions.

Possible evidence includes:

Key points

  • backup-console logins
  • administrative changes
  • deletion commands
  • retention changes
  • snapshot removal
  • encryption of backup repositories
  • credential use
  • service stoppage
  • access to recovery keys
  • security alerts
  • provider audit records

What investigators should establish

Investigators should identify:

Key points

  • which backup system was affected
  • which account or application acted
  • what changed
  • when it changed
  • whether deletion or encryption completed
  • whether immutable or offline copies remained
  • what legitimate maintenance occurred

Backup systems may be managed by third parties or cloud providers, so relevant evidence may sit outside the affected organisation.

Evidential limits

Do not assume the named administrator performed the action.

Accounts may be compromised, shared or automated.

Backup targeting may also involve obtaining backup credentials, disabling alerts or reducing retention before deletion occurs. Preserve configuration history and failed attempts, not just the final unavailable state. These preparatory actions may show intent even where some backups survived.

Also establish whether backup copies were offline, immutable, replicated or controlled through separate credentials. The existence of one surviving copy does not prove all backups were unaffected, while one failed repository does not prove complete recovery loss.

Record each backup tier and recovery path separately and explicitly.

Operational takeaway

Establish whether backup availability changed through deliberate unauthorised action, and preserve console, account, provider and configuration records before recovery alters them.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.