What evidence may show backup targeting?¶
Backup targeting is unauthorised activity intended to prevent recovery or obtain backup data. An unavailable repository may instead reflect retention, failure, maintenance or response action.
Preserve configuration and preparatory changes¶
Collect console authentication, provider audits, deletion and snapshot events, retention changes, service stops, encryption, recovery-key access and alert configuration. Identify the acting account or application, exact change, time and completion result.
Targeting can begin with stolen backup credentials, disabled alerts or shortened retention before deletion. Failed attempts and historical configuration can therefore show preparation even where copies survive.
Assess each recovery tier¶
Map online, offline, immutable and replicated copies and their separate credentials. One surviving tier does not prove all backups were unaffected; one failed repository does not prove recovery was completely lost.
Third-party or cloud providers may hold the strongest evidence. Preserve it before restoration changes state, and do not attribute account activity automatically to the named administrator.
Key takeaway
Prove backup targeting through unauthorised account, configuration and repository actions, and assess each independent recovery tier separately.