Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What evidence may show backup targeting?

Backup targeting is unauthorised activity intended to prevent recovery or obtain backup data. An unavailable repository may instead reflect retention, failure, maintenance or response action.

Preserve configuration and preparatory changes

Collect console authentication, provider audits, deletion and snapshot events, retention changes, service stops, encryption, recovery-key access and alert configuration. Identify the acting account or application, exact change, time and completion result.

Targeting can begin with stolen backup credentials, disabled alerts or shortened retention before deletion. Failed attempts and historical configuration can therefore show preparation even where copies survive.

Assess each recovery tier

Map online, offline, immutable and replicated copies and their separate credentials. One surviving tier does not prove all backups were unaffected; one failed repository does not prove recovery was completely lost.

Third-party or cloud providers may hold the strongest evidence. Preserve it before restoration changes state, and do not attribute account activity automatically to the named administrator.

Key takeaway

Prove backup targeting through unauthorised account, configuration and repository actions, and assess each independent recovery tier separately.

Reference: CIM-180Cyber Incidents & Offender Methods