Ransomware • Backup Recovery • Cyber Resilience

The Backup Was Right Next To The Fire

Friday afternoon, the phone rang.

Users could no longer open files. Within hours, two servers, fifteen workstations and the on-site backups were encrypted.

Then the ransom note appeared.

Agent Foskett ransomware recovery investigation involving encrypted servers workstations and Azure cloud backup
Briefing summary

A real ransomware incident encrypted the production environment and the local backups. The business recovered because an isolated Azure cloud backup survived outside the attack path.

2 servers encrypted
15 workstations encrypted
Azure cloud backup saved the day

What happened

The incident began with an email click and quickly became a full business recovery operation.
The email was clicked One employee opened an email attachment. That single action gave the ransomware the opening it needed.
The network was encrypted The attack spread across servers, workstations, shared folders and business data until normal operations stopped.
The ransom note appeared The attackers demanded approximately $14,000 in Bitcoin and expected the organisation to have no recovery option left.

The damage spread quickly

This was not a single infected workstation. It became a whole-environment recovery problem.
Two servers were encrypted Critical shared data and business services became unavailable. The recovery effort had to start with infrastructure, not just files.
Fifteen workstations were encrypted The impact reached across the user fleet. Restoring servers was only part of the job; endpoints also had to be rebuilt and validated.
Local backups were encrypted too The safety net was sitting inside the same environment the ransomware could reach. Once the attack spread, the local backup became another victim.

The recovery timeline

When ransomware hits, the investigation becomes a race between containment, recovery and business survival.
ransomware-recovery-timeline.txt
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
Friday afternoon      User reports files will not open
Initial review         Shared files show ransomware behaviour
Scope confirmed        2 servers and 15 workstations encrypted
Backup review          On-site backups also encrypted
Ransom demand          Approximately $14,000 in Bitcoin requested
Recovery option        Azure cloud backup remains intact
Weekend response       Interstate recovery and rebuild begins
Restore process        Servers, data and workstations rebuilt
Monday morning         Business operations resume

The problem with nearby backups

Backups do not automatically create resilience. Their location, access model and isolation decide whether they survive.
A backup can become a victim If ransomware can reach the backup repository, the backup may be encrypted just like the production data.
Attackers expect local backups Modern ransomware activity often targets backup systems because recovery is the organisation's strongest alternative to paying.
Isolation changes the outcome A backup is most valuable when it is stored somewhere the compromised environment cannot directly reach.

The one thing they missed

The attackers found the servers. They found the workstations. They found the local backups. But they did not reach the Azure cloud backup.
Azure backup survived The cloud backup remained separate from the encrypted systems and became the recovery path that mattered.
No ransom was paid The existence of a recoverable, isolated copy changed the conversation from payment to restoration.
The weekend became the recovery window The business needed systems back before Monday morning. The rebuild had to happen quickly and correctly.

Agent Foskett moment

The ransom note looked final. The backup architecture changed the ending.
The attackers thought they had won Production systems were encrypted. Workstations were encrypted. Local backups were encrypted. From their point of view, recovery should have been impossible.
One clean copy remained The Azure backup was not valuable because it was called a backup. It was valuable because the ransomware could not reach it.
Recovery beat ransom The business survived because restoration was still possible without trusting the attackers or paying for a decryption key.

What most environments miss

Most organisations think about creating backups. Fewer think deeply enough about whether those backups can survive an attack.
Backups on the same network are exposed If backup storage is reachable from compromised systems, it may be reachable to the attacker as well.
Untested recovery is a gamble Having backups is not the same as knowing how long recovery will take or whether restoration will actually work under pressure.
Cyber resilience is not just prevention When prevention fails, recovery capability decides whether the organisation can keep operating.

How defenders can prepare

The goal is not just to have backups. The goal is to have recoverable backups that survive compromise.
Keep isolated copies Maintain backup copies that are not directly writable or reachable from normal user workstations and production systems.
Test restores regularly A backup strategy should include restore testing, recovery timing and documented rebuild steps before a crisis occurs.
Plan for full rebuilds Assume servers, endpoints and local backup systems may all be untrusted after ransomware. Recovery plans need to account for that reality.

Questions every organisation should ask

If ransomware encrypted your environment today, would your backup strategy still work?
Could attackers reach your backups? Review whether backup storage, credentials and management consoles are accessible from the same environment users operate in every day.
How long would recovery really take? Recovery time is not theoretical during an incident. It becomes the difference between a bad weekend and a long business outage.
Would you be open on Monday? The real test of backup strategy is whether the organisation can resume operations after the systems everyone depends on are encrypted.

Related investigations

The Browser Spawned PowerShell Email and browser activity can become the start of a much larger execution chain. Read more →
The Child Process Shouldn't Have Existed Follow parent-child process relationships when a normal user action leads to abnormal execution. Read more →
The PowerShell Command Was Base64 Encoded Encoded execution can hide malicious intent inside command-line noise. Read more →
The Storage Account Was Public Cloud configuration and exposure can change the outcome of a security incident. Read more →
The Timeline Told The Story During major incidents, timeline reconstruction turns chaos into evidence. Read more →
Cyber Security Has Moved Beyond Basic Antivirus Modern resilience depends on visibility, identity, recovery and response — not just endpoint protection. Read more →
The backup survived because the ransomware could not reach it.
That difference turned a ransom demand into a recovery operation.
Contact GEMXIT

Final thought

Cybersecurity is often discussed in terms of prevention. But when prevention fails, recovery becomes the business.
At GEMXIT We help organisations think through Microsoft security, backup strategy, cloud recovery, ransomware resilience and practical incident response. If you want to understand how this applies to your environment, see our Cyber Security services.
Agent Foskett mindset Do not ask only whether backups exist. Ask whether they can survive the same incident that destroys production.

The servers were encrypted. The workstations were encrypted. The on-site backups were encrypted too. But one Azure cloud backup remained outside the fire. Explore related investigations including The Timeline Told The Story, The Browser Spawned PowerShell, and Cyber Security Has Moved Beyond Basic Antivirus.

Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD

The Backup Was Right Next To The Fire

This Agent Foskett briefing explains a real-world ransomware recovery where two servers, fifteen workstations and on-site backups were encrypted, but an isolated Azure cloud backup allowed the business to recover without paying the ransom.

Ransomware Recovery Cloud Backup And Business Continuity

Ransomware recovery depends on more than having backups. Organisations need isolated, tested and recoverable backup copies that attackers cannot reach from compromised servers, workstations or local backup systems.

Azure Cloud Backup Saved The Business

When local backups are encrypted during ransomware, a separate cloud backup can become the difference between paying a ransom and rebuilding the environment. Backup survivability, recovery testing and isolation are critical parts of cyber resilience.