Protecting Backups From Attackers: Credentials and Access

Attackers often hunt for backups before launching ransomware. Learn how to separate credentials and lock down access so your recovery copies survive.

3 min readBy Ironfield Cyber Team

Modern ransomware operators know that backups are the thing standing between them and a payout. Before they encrypt anything, many attackers spend time inside a network searching for backup servers, stolen administrator credentials, and cloud storage keys. If they can delete or corrupt your recovery copies first, your options shrink dramatically.

Protecting backups is as much about credentials and access as it is about technology. Here is how to make it much harder for an intruder to reach your safety net.

How attackers go after backups

Typical tactics include:

  • Using stolen domain administrator credentials to log into the backup server
  • Deleting backup jobs, restore points, or snapshots
  • Encrypting backup repositories reachable over the network
  • Stealing cloud storage keys or console logins and removing data
  • Disabling backup software services before launching encryption
  • Targeting virtualization hosts where backups and servers share an environment

Most of these succeed when backup systems share accounts, networks, and trust with the rest of the environment.

Separate the credentials

Do not use domain admin accounts for backups

If the backup server is joined to your main domain and administered with the same accounts, an attacker who captures one set of credentials owns both. Use dedicated accounts for backup administration, unique and long, and keep them out of everyday use. Where feasible, keep the backup infrastructure outside the main authentication system.

Require multifactor authentication

Protect the backup console and any cloud backup portal with multifactor authentication. Use phishing-resistant methods for administrators if available.

Limit who has access

Keep the list of backup administrators short, and review it regularly. Remove people who have changed roles. Use named accounts so actions are traceable.

Protect service accounts and keys

Service accounts and API keys used by backup software should have only the permissions they need. Store secrets in a protected vault, rotate them when staff leave, and never embed them in scripts that sit on shared drives.

Separate the network

  • Place backup servers and storage on a segmented network with tightly limited access from the rest of the environment.
  • Block remote desktop and other administrative protocols from general user machines to the backup network.
  • Restrict outbound access from backup systems to what is needed.
  • Avoid mapping backup storage as a regular drive that user machines can see.

Keep a copy attackers cannot change

At least one copy of your data should be protected from alteration or deletion, even by an administrator.

  • Immutable storage can prevent changes for a set retention period.
  • Offline or air-gapped copies, such as rotated media stored securely, are out of reach of network attackers, though they require discipline.
  • Separate cloud accounts with distinct credentials and no shared identity provider reduce the chance that one compromise reaches both.

Test that these protections work as described, and understand the retention and deletion rules your vendor applies.

Detect tampering

Set alerts for events that suggest an attack on backups.

  1. Deletion or modification of backup jobs and restore points
  2. Changes to retention settings
  3. Failed or unusual logins to the backup console
  4. Backup services stopped or disabled
  5. Sudden changes in backup size or duration

Send alerts somewhere that an attacker cannot silence from the same compromised system, and have a defined response.

Secure the supporting pieces

  • Apply security updates to backup software promptly, since attackers exploit known flaws in popular products.
  • Encrypt backups in transit and at rest, and protect the encryption keys separately. Remember that losing keys can mean losing the data.
  • Secure the physical location of any local backup devices, and keep them out of unlocked trailers or shared closets.

Practice recovery under pressure

Test restores assuming the main environment is gone. Can you log in to the backup system without the domain? Do you know where the keys and documentation are? Is the recovery procedure stored somewhere you can reach during an outage, including offline? These questions are easy to answer in calm conditions and painful to answer during an incident.

A quick checklist

  • Dedicated backup administrator accounts with multifactor authentication
  • Segmented backup network
  • At least one immutable or offline copy
  • Alerts on deletion and configuration changes
  • Prompt patching of backup software
  • Documented, tested recovery steps

Where Ironfield Cyber fits

Ironfield Cyber designs and monitors backup environments for contractors and energy companies, with separated credentials and protected copies as a standard. If you want to know whether an attacker could reach your backups today, we can review it with you.