.png)
Business Continuity
Can ransomware affect cloud backups?
By Steve Harper | 8 min read | Last updated:
12 August 2026 at 08:13:08

TL;DR
Yes. Ransomware can affect cloud backups if infected or encrypted files are automatically copied into the backup, or if attackers gain sufficient access to delete, disable or corrupt the stored recovery data.
Cloud backups should use multiple recovery versions, protected administrative accounts, strong authentication, deletion safeguards and monitoring. The business should also regularly test whether clean data can be restored.
Cloud location alone does not make a backup ransomware-resistant.
Key Takeaways
Cloud backups are not automatically protected from ransomware.
File synchronisation is not the same as independent backup.
Attackers may target backup accounts and management consoles.
Earlier recovery versions should remain available if newer copies are corrupted.
Backup administration should be separated from everyday user accounts.
Significant changes and deletion attempts should generate alerts.
Restoration must be tested before an incident occurs.
Would your cloud backups survive an administrator account being compromised?
IT Desk can review your backup coverage, access controls, retention and recovery testing. We can help implement protected cloud backups and practical recovery processes designed to reduce the impact of ransomware, accidental deletion and system failure.
How can ransomware affect a cloud backup?
Ransomware may affect a cloud backup in several different ways.
The malware itself may not directly break into the backup provider. Instead, the damage can reach the recovery environment through connected systems, synchronisation, stolen credentials or administrative access.
Possible scenarios include:
Encrypted files being uploaded during the next backup
Corrupted information replacing good data
Synced cloud files being changed across every connected device
An attacker signing into the backup console
Backup policies being disabled
Recovery points being deleted
Retention periods being reduced
Backup agents being removed from protected systems
Credentials or encryption keys being stolen
The attacker waiting until older clean backups expire
Modern ransomware attacks may deliberately target backups because reliable recovery reduces the attacker’s leverage.
The National Cyber Security Centre states that on-premises and cloud backups are not resistant to ransomware by default.
Can ransomware encrypt files stored in the cloud?
It can affect files available through a synchronised cloud folder.
For example, if a computer synchronises files with a cloud service, ransomware may encrypt the local files. Those encrypted changes can then synchronise to the cloud and other connected devices.
Version history or retention may allow earlier copies to be recovered, but availability depends on the service, its configuration and how quickly the incident is detected.
Cloud file storage should therefore not automatically be treated as an independent backup.
Is OneDrive or SharePoint a backup?
OneDrive and SharePoint provide cloud storage, collaboration, versioning and recovery features. These capabilities can help recover from certain deletions and file changes.
However, they should not automatically be treated as the organisation’s complete backup and disaster-recovery plan.
The business needs to consider:
How long versions and deleted items remain available
Which Microsoft 365 workloads are covered
Whether administrators can delete or alter recovery data
What happens if an account is compromised
How quickly large amounts of data can be restored
Whether recovery meets the business’s required timescale
Whether another independent recovery copy is required
Microsoft offers its own Microsoft 365 Backup service, and third-party backup platforms can also protect supported Microsoft 365 workloads.
Read our guide to Microsoft 365 Backup for Business for a more detailed explanation.
What is the difference between cloud sync and cloud backup?
Cloud synchronisation keeps files consistent across locations and devices.
When a user edits, moves or deletes a synchronised file, that change may be copied everywhere. This is useful for everyday collaboration but can also spread an unwanted or malicious change.
Cloud backup creates separate recovery copies intended to restore information after a problem.
Cloud synchronisation | Cloud backup |
Keeps current files consistent | Retains recovery copies |
Changes are copied quickly | Multiple points in time may be retained |
Supports everyday collaboration | Supports recovery after data loss |
Deletions may synchronise | Deletion safeguards may protect backups |
Not necessarily isolated | Should be separated from live systems |
May provide version history | Should provide defined retention and restoration |
Some cloud services contain elements of both. The business should understand exactly what protection its chosen service provides.
What makes a cloud backup ransomware-resistant?
The NCSC identifies several principles for making cloud backups more resistant to destructive attacks.
A suitable backup service and configuration should help ensure that:
Backups can resist destructive actions.
An attacker cannot remove every method of customer access.
Earlier versions remain recoverable if later versions are corrupted.
Encryption keys are managed robustly.
Significant configuration changes or privileged actions generate alerts.
These controls need to work together. A backup advertised as immutable may still be exposed if an attacker can remove the entire service, change retention settings or take control of every administrator account.
What is an immutable backup?
An immutable backup is a recovery copy that cannot be altered or deleted during a defined retention period.
Immutability can help protect backups from:
Ransomware
Malicious administrators
Accidental deletion
Unauthorised retention changes
Corruption of recent recovery points
The strength of the protection depends on how the service implements and administers immutability.
Businesses should ask:
Who can enable or disable it?
Can an administrator shorten the protected period?
Can the backup account or subscription be deleted?
What happens if the attacker compromises the highest-level account?
Are configuration changes delayed or separately authorised?
Are deletion attempts logged and reported?
The word “immutable” should not be accepted without understanding the controls around it.
Should backup accounts be separate from normal administrator accounts?
Yes, where the system allows it.
An everyday Microsoft 365 or network administrator account should not automatically provide unrestricted control over every backup and recovery copy.
Separating backup administration can limit the damage if a normal administrator account is compromised.
Backup access should use:
Separate named administrator accounts
Strong multi-factor authentication
Least-privilege permissions
Restricted access locations or devices where appropriate
Alerts for unusual sign-ins
Approval for destructive changes
Logged administrative actions
Secure emergency-access arrangements
Shared administrator credentials make activity harder to attribute and should be avoided.
Can infected files be stored inside a backup?
Yes.
A backup may contain malware or already-encrypted files if it captures the system after the compromise occurred.
This does not necessarily make the entire backup unusable. Multiple recovery points can allow the organisation to return to a version created before the damage began.
However, the attack may have started days or weeks before ransomware was finally activated. The most recent backup is not automatically the cleanest one.
Before restoration, the business should investigate:
When initial compromise occurred
When malicious tools were introduced
Which systems and accounts were affected
Whether the chosen recovery point contains malware
Whether vulnerabilities and stolen credentials have been addressed
Whether the recovery environment is isolated and clean
The NCSC advises organisations to restore only when they are confident that both the backup and the receiving device are clean.
How many backup versions should a business keep?
There is no universal number.
Retention should account for how long an attacker might remain undetected and how frequently the underlying data changes.
Keeping only one recent recovery point creates a risk that good data will be replaced by an encrypted or corrupted version.
The backup policy should consider:
The business’s recovery-point objective
How quickly incidents are normally detected
Available daily, weekly and monthly recovery points
Legal and contractual retention requirements
Storage costs
Data-protection obligations
The importance of historical records
Longer retention is not automatically better. The organisation should retain enough recovery history to meet a defined need while managing old data appropriately.
How often should cloud backups be tested?
Backups should be tested regularly and following significant changes to systems, data or the backup service.
A test should confirm more than whether the backup job displays a successful status. It should establish whether:
The expected information is present
The data can be restored
The restored information is usable
Permissions and configurations can be recovered
The process can be completed within the required time
The correct people know how to start recovery
Clean recovery copies can be identified
Dependencies between applications have been considered
Testing a small file may be useful, but it does not prove that a complete server, database or Microsoft 365 environment can be restored at scale.
Does an offline backup still matter?
An offline or otherwise isolated recovery copy can provide valuable protection because it is not continuously accessible from the live environment.
This might involve removable storage that is disconnected and stored securely, or a cloud backup service designed to prevent destructive changes from reaching every recovery copy.
A physical drive that remains permanently connected to the network is not meaningfully offline. Ransomware may encrypt connected USB drives and network storage alongside the original data.
Offline copies also need:
Physical security
Encryption
Appropriate retention
Clear ownership
Regular updates
Restoration testing
Secure disposal when no longer required
A business may use cloud, offline and on-premises backups together rather than relying on only one type.
What should we check in our cloud backup service?
Ask the provider or IT team:
Which systems and data are backed up?
How frequently are backups created?
How many recovery versions are retained?
Can protected copies be altered or deleted?
Who has administrative access?
Is strong MFA enforced for backup administrators?
Are backup credentials separate from normal accounts?
What alerts are generated for failed jobs and policy changes?
Can administrators remove the entire backup service immediately?
How are encryption keys protected?
How quickly can data be restored?
When was the last successful recovery test?
What happens if the backup provider itself is unavailable?
The answers should be documented as part of the organisation’s business-continuity and disaster-recovery planning.
What should a business do if ransomware is happening now?
Do not begin deleting files, reconnecting backups or restoring systems without an incident-response plan.
Immediate actions may include isolating affected devices, protecting unaffected systems, preserving evidence, securing accounts and contacting the organisation’s IT or cybersecurity provider.
The correct response depends on the scale and nature of the attack.
See our guide explaining what to do when a ransomware attack happens for incident-response guidance.
Related Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.
Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.












