Protecting Backups from Ransomware
Ransomware can encrypt or delete files that the infected computer can reach. That may include files on a connected USB drive or an accessible network backup.
How Ransomware Reaches Backups
Ransomware runs on an infected computer and searches for writable files it can reach. It may attack the computer's own files, connected USB drives and accessible network locations. A backup is therefore most exposed while its drive is connected and available to Windows.
Keep a Removable Backup Offline
A disconnected drive cannot be reached by ransomware running on the computer. Keep a removable backup drive disconnected except while a backup is actually being updated.
- Connect the USB drive only when you are ready to run the backup.
- Start Fast-Backup and allow the backup to finish.
- Check that the backup completed successfully.
- Safely eject the drive and disconnect it straight away.
Keeping the connection time short reduces the opportunity for malware to reach the backup, but it cannot guarantee protection.
Let Fast-Backup Eject the Drive
Select Eject when finished in Options, or use
If another program is using the drive, Fast-Backup keeps trying. Close any files or programs using the drive, and change any command sessions to another drive. When using Fast-Backup-CLI with
The Windows version is recommended for automatic ejection. It remains visible while Windows safely removes the drive and clearly reports a problem or successful ejection. The command-line version uses the same Windows safe-removal mechanism, but its command session can introduce additional complications.
Automatic ejection does not physically unplug the cable, detect ransomware or make a connected drive immune to attack. Disconnect the drive after Windows has ejected it, and do not connect it at all if you suspect the computer is infected.
Watch for an Unexpected Increase in Changed Files
Ransomware comes in many forms and does not always change files in an obvious way. A sudden increase in changed files can be a warning sign, but it is not proof of ransomware.
If an ordinary backup normally takes only a few minutes but suddenly starts replacing a large number of files, stop the backup and investigate. After Fast-Backup has stopped, safely eject and disconnect the removable backup drive. An unusually large number of changed files can have legitimate causes, but it may also indicate corruption or ransomware.
Do not reconnect the backup drive until you are satisfied that the computer is safe. If you suspect ransomware, disconnect the computer from the network and obtain appropriate security help. Fast-Backup cannot determine from the number of changed files alone whether ransomware is present.
Do Not Connect a Backup to a Suspect Computer
If files have unexpected names or extensions, will not open, a ransom message appears, or you otherwise suspect an infection, do not connect an offline backup drive. Disconnect the computer from the network and obtain appropriate security help before using the backup.
Rotate Two Backup Drives
Where possible, alternate between two removable drives. One can remain safely disconnected while the other is being updated. Keeping one copy in another secure location also protects against theft, fire and other events affecting everything in one place.
Keep Earlier Versions
Fast-Backup can retain earlier versions of changed and deleted files. This may help if damaged or encrypted files are backed up before the problem is noticed. However, Keep Old history cannot protect a backup drive while ransomware has access to that drive.
Independent Security Guidance
Both the United States Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) advise keeping removable backup media disconnected when it is not being used.