Your Backups Won’t Save You Anymore: Ransomware Steals First

Sep 16, 2026Incognito CyberSecurity

Your Backups Won’t Save You Anymore: Ransomware Steals First

🇲🇭 Leer en Español →

For about ten years my answer to ransomware was short, and it worked. Keep clean backups. Test them. Keep one copy somewhere the attacker cannot reach. Do that, and you could tell a criminal exactly where to go, restore your servers over a long weekend, and be back at work Monday morning.

That advice is now only half an answer. And the missing half is the part that costs small businesses the most money.

What Actually Changed

Ransomware crews figured out something uncomfortable for them: businesses finally got decent at backups. Encryption by itself stopped paying the bills. So they changed the order of operations.

Today they break in quietly, walk around your network for a while, find the files that would hurt you most if they got out, copy those files to their own servers, and only then lock anything up. By the time you see a ransom note, the theft already happened. The lock is just the announcement.

Security firm Huntress put the average time from break-in to ransom screen at roughly 20 hours in its 2026 threat research, up from 17 the year before. That sounds like good news. It is not. They are taking longer on purpose, and those extra hours are spent doing exactly one thing: shopping.

They know what is worth taking

They are not grabbing random spreadsheets. They go after payroll files, client lists, signed contracts, scanned driver’s licenses, tax returns, bank letters, anything with a Social Security number attached. If you run a CPA firm, a law office, a clinic, or a construction company holding customer financial data, you are carrying precisely the material they came for.

Your backups are on their list too

Before they pull the trigger, they go looking for your backup system. If your backups sit on the same network, reachable with the same administrator password as everything else, they get deleted first. That is not a theoretical risk, it is standard procedure now, and it is why how your backups are stored matters as much as whether you have them.

Infographic with three cards: they steal before they lock, restoring does not erase, plan the phone calls.

What “We Have Backups” Protects You From Now

Please do not read this as backups being pointless. Nothing could be further from the truth. Good backups are still the line between a rough week and a business that never reopens, and I will keep pushing every client I have to test them.

But be honest about what they do. Backups solve availability. They get your phones, your files, and your invoicing working again. They do not solve confidentiality. Once a copy of your client list is sitting on a stranger’s server, restoring your own copy changes nothing about that. You cannot restore a secret back into being a secret.

The Part Nobody Plans For

Here is what actually happens in the week after, and it is rarely the technology that hurts. It is the phone calls.

Arizona, like most states, requires you to notify people when their personal information is exposed. So you are calling your attorney to find out who has to be told and how fast. You are calling your insurance carrier, who will want to know what controls you actually had in place, not what you meant to have. You are calling clients to tell them their information was taken while you were the one holding it. And you are answering the question every one of them asks: how did this happen, and why did it take you so long to notice?

I have watched owners handle the server rebuild fine and get completely flattened by that last conversation. Which is the whole argument for catching an intruder during those 20 hours instead of finding out afterward.

What You Can Do This Week

  1. Find out where your backups actually live. Ask whoever handles your IT one question: if someone got full admin access to our network tonight, could they reach and delete our backups? If the answer is yes, or nobody knows, fix that before anything else on this list.
  2. Write down what you hold. Fifteen minutes on a legal pad. What customer information is on your systems right now? Social Security numbers, bank details, medical records, ID scans? You cannot judge your exposure until you know what is sitting there.
  3. Make the call list before you need it. IT provider, insurance agent, attorney, bank. Names and cell numbers, printed, in a drawer. When you are locked out, you will not have email to look them up.
  4. Pull your cyber insurance policy out and read the conditions. Many now require multi-factor authentication and tested backups. If you do not have what you promised, your claim can be denied at the worst possible moment.
  5. Ask if anything would flag unusual data leaving your network. Twenty hours of quiet copying looks like something. Somebody should be watching for it, and your staff should know what a break-in looks like in its early hours.

Bottom Line

Backups keep your doors open. They do not keep your secrets. The businesses handling this well in 2026 are the ones that stopped treating ransomware as a data recovery problem and started treating it as a theft problem, which means the goal moved from “can we restore?” to “would we even notice someone copying our files?”

If you cannot answer that second question today, that is the gap worth closing. Most of the fixes above cost time, not money. And if you would rather not guess, we do this every day for Tucson-area businesses. Related reading: what happens when your vendor gets breached, or browse the rest of the blog.

Free, no obligation

Not sure if your backups could survive an attack?

We will walk your setup with you, tell you plainly what an attacker could reach, and give you a short list of what to fix first. No sales pitch, no jargon.

Book a complimentary visit

We also handle spam and virus filtering, since most of these break-ins still start with one email nobody thought twice about.

Send us a message

Questions about anything in this article? Send them over and I will answer personally.

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

— Nemuel Cruz, Incognito Cyber Security

About the author

Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News