top of page
it support sheffield

Business Continuity

Can ransomware affect cloud backups?

By Steve Harper  |  8 min read  | Last updated:

12 August 2026 at 08:13:08

Can Ransomware Affect Cloud Backups?

TL;DR

Yes. Ransomware can affect cloud backups if infected or encrypted files are automatically copied into the backup, or if attackers gain sufficient access to delete, disable or corrupt the stored recovery data.


Cloud backups should use multiple recovery versions, protected administrative accounts, strong authentication, deletion safeguards and monitoring. The business should also regularly test whether clean data can be restored.


Cloud location alone does not make a backup ransomware-resistant.


Key Takeaways

  • Cloud backups are not automatically protected from ransomware.

  • File synchronisation is not the same as independent backup.

  • Attackers may target backup accounts and management consoles.

  • Earlier recovery versions should remain available if newer copies are corrupted.

  • Backup administration should be separated from everyday user accounts.

  • Significant changes and deletion attempts should generate alerts.

  • Restoration must be tested before an incident occurs.

Would your cloud backups survive an administrator account being compromised?


IT Desk can review your backup coverage, access controls, retention and recovery testing. We can help implement protected cloud backups and practical recovery processes designed to reduce the impact of ransomware, accidental deletion and system failure.



How can ransomware affect a cloud backup?

Ransomware may affect a cloud backup in several different ways.


The malware itself may not directly break into the backup provider. Instead, the damage can reach the recovery environment through connected systems, synchronisation, stolen credentials or administrative access.


Possible scenarios include:

  • Encrypted files being uploaded during the next backup

  • Corrupted information replacing good data

  • Synced cloud files being changed across every connected device

  • An attacker signing into the backup console

  • Backup policies being disabled

  • Recovery points being deleted

  • Retention periods being reduced

  • Backup agents being removed from protected systems

  • Credentials or encryption keys being stolen

  • The attacker waiting until older clean backups expire


Modern ransomware attacks may deliberately target backups because reliable recovery reduces the attacker’s leverage.


The National Cyber Security Centre states that on-premises and cloud backups are not resistant to ransomware by default.


Can ransomware encrypt files stored in the cloud?

It can affect files available through a synchronised cloud folder.


For example, if a computer synchronises files with a cloud service, ransomware may encrypt the local files. Those encrypted changes can then synchronise to the cloud and other connected devices.


Version history or retention may allow earlier copies to be recovered, but availability depends on the service, its configuration and how quickly the incident is detected.


Cloud file storage should therefore not automatically be treated as an independent backup.


Is OneDrive or SharePoint a backup?

OneDrive and SharePoint provide cloud storage, collaboration, versioning and recovery features. These capabilities can help recover from certain deletions and file changes.


However, they should not automatically be treated as the organisation’s complete backup and disaster-recovery plan.


The business needs to consider:

  • How long versions and deleted items remain available

  • Which Microsoft 365 workloads are covered

  • Whether administrators can delete or alter recovery data

  • What happens if an account is compromised

  • How quickly large amounts of data can be restored

  • Whether recovery meets the business’s required timescale

  • Whether another independent recovery copy is required


Microsoft offers its own Microsoft 365 Backup service, and third-party backup platforms can also protect supported Microsoft 365 workloads.


Read our guide to Microsoft 365 Backup for Business for a more detailed explanation.


What is the difference between cloud sync and cloud backup?

Cloud synchronisation keeps files consistent across locations and devices.


When a user edits, moves or deletes a synchronised file, that change may be copied everywhere. This is useful for everyday collaboration but can also spread an unwanted or malicious change.


Cloud backup creates separate recovery copies intended to restore information after a problem.

Cloud synchronisation

Cloud backup

Keeps current files consistent

Retains recovery copies

Changes are copied quickly

Multiple points in time may be retained

Supports everyday collaboration

Supports recovery after data loss

Deletions may synchronise

Deletion safeguards may protect backups

Not necessarily isolated

Should be separated from live systems

May provide version history

Should provide defined retention and restoration


Some cloud services contain elements of both. The business should understand exactly what protection its chosen service provides.


What makes a cloud backup ransomware-resistant?

The NCSC identifies several principles for making cloud backups more resistant to destructive attacks.


A suitable backup service and configuration should help ensure that:

  • Backups can resist destructive actions.

  • An attacker cannot remove every method of customer access.

  • Earlier versions remain recoverable if later versions are corrupted.

  • Encryption keys are managed robustly.

  • Significant configuration changes or privileged actions generate alerts.


These controls need to work together. A backup advertised as immutable may still be exposed if an attacker can remove the entire service, change retention settings or take control of every administrator account.


What is an immutable backup?

An immutable backup is a recovery copy that cannot be altered or deleted during a defined retention period.


Immutability can help protect backups from:

  • Ransomware

  • Malicious administrators

  • Accidental deletion

  • Unauthorised retention changes

  • Corruption of recent recovery points


The strength of the protection depends on how the service implements and administers immutability.


Businesses should ask:

  • Who can enable or disable it?

  • Can an administrator shorten the protected period?

  • Can the backup account or subscription be deleted?

  • What happens if the attacker compromises the highest-level account?

  • Are configuration changes delayed or separately authorised?

  • Are deletion attempts logged and reported?


The word “immutable” should not be accepted without understanding the controls around it.


Should backup accounts be separate from normal administrator accounts?

Yes, where the system allows it.


An everyday Microsoft 365 or network administrator account should not automatically provide unrestricted control over every backup and recovery copy.


Separating backup administration can limit the damage if a normal administrator account is compromised.


Backup access should use:

  • Separate named administrator accounts

  • Strong multi-factor authentication

  • Least-privilege permissions

  • Restricted access locations or devices where appropriate

  • Alerts for unusual sign-ins

  • Approval for destructive changes

  • Logged administrative actions

  • Secure emergency-access arrangements


Shared administrator credentials make activity harder to attribute and should be avoided.


Can infected files be stored inside a backup?

Yes.


A backup may contain malware or already-encrypted files if it captures the system after the compromise occurred.


This does not necessarily make the entire backup unusable. Multiple recovery points can allow the organisation to return to a version created before the damage began.


However, the attack may have started days or weeks before ransomware was finally activated. The most recent backup is not automatically the cleanest one.


Before restoration, the business should investigate:

  • When initial compromise occurred

  • When malicious tools were introduced

  • Which systems and accounts were affected

  • Whether the chosen recovery point contains malware

  • Whether vulnerabilities and stolen credentials have been addressed

  • Whether the recovery environment is isolated and clean


The NCSC advises organisations to restore only when they are confident that both the backup and the receiving device are clean.


How many backup versions should a business keep?

There is no universal number.


Retention should account for how long an attacker might remain undetected and how frequently the underlying data changes.


Keeping only one recent recovery point creates a risk that good data will be replaced by an encrypted or corrupted version.


The backup policy should consider:

  • The business’s recovery-point objective

  • How quickly incidents are normally detected

  • Available daily, weekly and monthly recovery points

  • Legal and contractual retention requirements

  • Storage costs

  • Data-protection obligations

  • The importance of historical records


Longer retention is not automatically better. The organisation should retain enough recovery history to meet a defined need while managing old data appropriately.


How often should cloud backups be tested?

Backups should be tested regularly and following significant changes to systems, data or the backup service.


A test should confirm more than whether the backup job displays a successful status. It should establish whether:

  • The expected information is present

  • The data can be restored

  • The restored information is usable

  • Permissions and configurations can be recovered

  • The process can be completed within the required time

  • The correct people know how to start recovery

  • Clean recovery copies can be identified

  • Dependencies between applications have been considered


Testing a small file may be useful, but it does not prove that a complete server, database or Microsoft 365 environment can be restored at scale.


Does an offline backup still matter?

An offline or otherwise isolated recovery copy can provide valuable protection because it is not continuously accessible from the live environment.


This might involve removable storage that is disconnected and stored securely, or a cloud backup service designed to prevent destructive changes from reaching every recovery copy.


A physical drive that remains permanently connected to the network is not meaningfully offline. Ransomware may encrypt connected USB drives and network storage alongside the original data.


Offline copies also need:

  • Physical security

  • Encryption

  • Appropriate retention

  • Clear ownership

  • Regular updates

  • Restoration testing

  • Secure disposal when no longer required


A business may use cloud, offline and on-premises backups together rather than relying on only one type.


What should we check in our cloud backup service?

Ask the provider or IT team:

  • Which systems and data are backed up?

  • How frequently are backups created?

  • How many recovery versions are retained?

  • Can protected copies be altered or deleted?

  • Who has administrative access?

  • Is strong MFA enforced for backup administrators?

  • Are backup credentials separate from normal accounts?

  • What alerts are generated for failed jobs and policy changes?

  • Can administrators remove the entire backup service immediately?

  • How are encryption keys protected?

  • How quickly can data be restored?

  • When was the last successful recovery test?

  • What happens if the backup provider itself is unavailable?


The answers should be documented as part of the organisation’s business-continuity and disaster-recovery planning.


What should a business do if ransomware is happening now?

Do not begin deleting files, reconnecting backups or restoring systems without an incident-response plan.


Immediate actions may include isolating affected devices, protecting unaffected systems, preserving evidence, securing accounts and contacting the organisation’s IT or cybersecurity provider.


The correct response depends on the scale and nature of the attack.


See our guide explaining what to do when a ransomware attack happens for incident-response guidance.

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

bottom of page