If they'd had a backup, we wouldn't be hearing about this.
They'd just stop everything, disconnect, restore, and figure out how the entry happened before going live again.
Yeah but the scammers are getting wise to this and are leaving their stuff on the compromised machines long enough that you end up backing up the ransomware. So you nuke everything and restore and the timer goes off and it crypto locks everything again.
Not saying that's what happened here, just that that is becoming the routine practice now. Gotta make sure you're keeping backups back a year or so to make sure you don't get totally fucked.
(post is archived)