ALPHV/BlackCat and Change Healthcare: backups failed at the first breach
In February 2024 the ALPHV/BlackCat ransomware group breached a remote access portal that had no multi-factor authentication and then encrypted Change Healthcare’s systems. The source material says the backups were not isolated or robust enough to restore operations quickly. UnitedHealth, which owns Change Healthcare, paid $22 million in ransom and nevertheless did not recover the data — total recovery costs were later estimated at $1.6 billion. That sequence is the clearest illustration of the simple, brutal logic driving recent ransomware tradecraft: if attackers can remove the recovery path, victims lose leverage and options.
BlackMatter’s playbook: locate, wipe, then encrypt
The BlackMatter group made backup destruction a routine part of their operations. In 2021, when they struck NEW Cooperative and Crystal Valley, they used compromised admin credentials to identify every backup data store and appliance on the network and then wiped or reformatted them before encrypting production systems. Because the backups lived on the same network as production, they were straightforward targets. CISA, the FBI, and the NSA jointly documented BlackMatter’s approach and noted ransom demands in prior incidents ranged from $80,000 to $15 million in Bitcoin and Monero.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildGunra and the collapse of disaster recovery: one credential reached both sites
A joint CISA and FBI advisory in August 2026 described a Gunra ransomware incident that pushed the logic further. In one confirmed case attackers deleted backup and archived data at both an organization’s primary data center and its disaster recovery site. “A single set of stolen credentials was all it took to reach both,” the advisory recounts. The advisory adds the stark lesson: having two copies in two locations meant nothing because both locations trusted the same key.
Four technical failures that keep enabling these attacks
- Shared networks and credentials: When the same administrator accounts and network access touch production and backups, compromise of one surface permits access to both; true isolation requires deliberate architecture.
- Backup platforms patched last: The Akira airline attack exploited a vulnerability that had a patch available for over a year. Backup servers are frequently treated as appliances and updated last, or not at all, leaving attackers with a menu of unpatched targets.
- Limited monitoring of backup infrastructure: Security teams concentrate detection on production. Backup servers often carry minimal logging, weaker access controls and slower response processes, making them quieter places for attackers to operate.
- Resource constraints: Knowing what good backup security looks like and having the budget, trained staff and operational bandwidth to implement it are separate problems. Many IT teams and MSPs operate with all three in short supply.
What this means for technologists, MSPs, and executives
Technologists and security teams: The source recommends treating the recovery environment as critical infrastructure — use immutable storage as a baseline, enforce true network and credential isolation, put backup software on the same patch cadence as production, and test restores rather than assuming backups work. Immutable, write-once storage and role-based access controls are cited as minimum expectations.
Managed service providers (MSPs): The report draws on survey data showing 65% of MSPs say their clients are underinvesting in cybersecurity. That gap helps explain why many backups remain exposed and why attackers continue to target recovery paths directly.
Executives and procurement leaders: The financial calculus is stark. IBM’s 2025 Cost of a Data Breach Report put the average cost of a ransomware incident at $5.08 million; IBM’s 2026 research found 41% of ransomware incidents also involved threats to damage brand reputation. The UnitedHealth/Change Healthcare aftermath — $22 million paid with no data returned and $1.6 billion in recovery costs — underlines how quickly recovery failures can escalate into existential, balance-sheet-level damage.
A focused security pivot with outsized consequences
Ransomware groups are now targeting backups first — wiping recovery points before encrypting everything else. The practical prescription in the source is straightforward and specific: isolate backup environments from production networks and credentials; adopt immutable storage features; treat backup systems as software that must be patched promptly; and exercise restore plans through regular tests and scenario simulations. The gap between awareness and action, the report says, is mostly operational: almost 77% of IT organizations surveyed for the report Building Security That Survives Human Error say their cybersecurity investment is not keeping pace with the threats they face, and more than 1,100 IT and cybersecurity professionals contributed responses that shaped the analysis.
If an attacker can erase the way back, the decision to pay shifts from a tactical choice to a survival calculation. The remedy is less novel technology than disciplined execution: hardening recovery, reducing shared trust, and removing single points of failure so that a single stolen credential cannot sever every recovery path.




