Backups in a safe

The Rise of Credential Theft and Why It Matters for Your Backups

For years, ransomware attacks typically began with attackers exploiting unpatched software or exposed network services. While those techniques are still common, security researchers have observed another trend becoming increasingly important: attackers are logging in instead of breaking in.

According to Google's Mandiant threat intelligence team, approximately 21% of ransomware investigations began with stolen credentials, making compromised accounts one of the most common ways ransomware operators gain initial access. More broadly, Mandiant's annual incident response report found credential theft has become the second most common initial infection vector across all of the incidents they investigate.

That's a significant shift in how modern cyberattacks unfold.

Why Credential Theft Is Increasing

Stealing passwords has become easier than ever.

Phishing attacks remain effective, but today's attackers also rely heavily on "infostealer" malware. These programs quietly collect saved browser passwords, authentication cookies, password manager databases, autofill information, and other credentials from infected computers.

Instead of conducting their own phishing campaigns, ransomware groups can often purchase these stolen credentials from criminal marketplaces, giving them immediate access to thousands of compromised accounts.

Artificial intelligence is accelerating this trend even further. Security researchers have observed attackers using AI to generate convincing phishing emails, automate reconnaissance, write malicious code, and dramatically increase the scale of credential theft campaigns.

Why This Changes the Backup Conversation

When people think about backups, they often imagine hardware failures or accidental deletion.

Modern ransomware changes the equation.

If an attacker successfully gains access to your accounts, they may be able to:

  • Delete backup jobs.
  • Delete backup repositories.
  • Encrypt synchronized files.
  • Modify cloud-hosted data.
  • Disable automated backup schedules.
  • Steal sensitive information before deploying ransomware.

The important point isn't that every online backup service is vulnerable to every one of these attacks. Many providers have added immutable storage, version history, MFA protection, and other safeguards.

The larger issue is that any backup system which remains continuously accessible through compromised credentials shares some degree of risk with the systems it's protecting.

Cloud Storage Is Not the Same as an Offline Backup

Cloud storage platforms such as Dropbox, OneDrive, and Google Drive are excellent tools for collaboration and file synchronization.

They are designed to make your data accessible.

An offline backup is designed to make your data recoverable.

Those are different goals.

If ransomware encrypts files inside a synchronized folder, cloud storage may faithfully synchronize the encrypted versions. Version history often provides an important safety net, but recovery depends on discovering the problem before historical versions expire.

An offline copy behaves differently because it is no longer connected to the compromised account.

Why Physical Separation Still Matters

One of the oldest principles in computer security is separating critical systems from everyday access.

A backup that is physically disconnected from the internet cannot be encrypted through a compromised cloud account. It cannot be deleted through stolen credentials. It cannot be modified by malware running on an infected workstation after the backup has been completed.

That physical separation creates a boundary that software alone cannot provide.

Building a Layered Defense

No single security measure is enough on its own.

A modern backup strategy should include multiple layers of protection:

  • Strong, unique passwords.
  • Multi-factor authentication.
  • Employee awareness training.
  • Regular software updates.
  • Independent backups.
  • At least one backup that is not continuously connected to your online accounts.

Each layer protects against a different type of failure.

Where Mail a Backup Fits

Mail a Backup isn't intended to replace your existing cloud backups or synchronization services.

Instead, it adds another layer to your recovery strategy.

Your website or cloud files are encrypted, copied to a USB drive, and mailed to you. Once that process is complete, the backup is no longer connected to your Dropbox account, OneDrive account, hosting provider, or local network.

If your online accounts are ever compromised, that physical copy remains exactly as it was when it was created.

No backup strategy can eliminate every risk. But as credential theft continues to rise, maintaining at least one copy of your data outside the reach of your online accounts has become an increasingly valuable part of a layered security strategy.