No—not yet. A backup drive connected to a device or network during a ransomware attack may be infected, so you cannot presume it is trustworthy. Ransomware encrypts or damages files and may also target backups. Treat the drive as potentially exposed until it has been checked in a clean environment.
Table of Contents
- Why a Connected Backup Is at Risk
- What to Do Immediately
- When Can You Use the Drive?
- Does Having a Backup Prove You Can Recover?
Why a Connected Backup Is at Risk
A connected backup can be reached through the infected computer or network. The Australian Cyber Security Centre says a backup connected during a ransomware incident may itself be infected. ASD's Australian Cyber Security Centre explains the risk.
Attackers often target connected backup devices because damaging them makes recovery harder. The UK National Cyber Security Centre advises against leaving external drives and USB backups permanently connected. The NCSC describes this ransomware risk. The drive may still contain usable files, but its connection history means it needs investigation before restoration.
What to Do Immediately
Disconnect the affected computer from wired, wireless, and mobile networks. Isolation helps prevent ransomware from reaching other devices or continuing across the environment, according to the NCSC's response guidance. Do not reconnect the backup to another computer simply to see whether the files open.
That computer could become exposed, and opening files can make it harder to preserve evidence or contain the incident. If the attack is active or the backup may be infected, seek qualified IT or incident-response help before accessing it. The Australian Cyber Security Centre specifically advises professional assistance when a backup may be compromised.
When Can You Use the Drive?
Use the backup only after both the backup and the device used to connect it are known to be clean. The backup should also be checked for malware before restoration.
The NCSC sets out these restoration conditions. A safe recovery decision should include these checks: Restoration should wait until ransomware has been removed from affected drives or the network. Otherwise, reconnecting the drive can reintroduce the attack.
- The affected drives and network have been cleared of ransomware.
- The computer used to inspect the backup has been cleaned or rebuilt.
- The backup has been scanned and reviewed for signs of tampering.
- The files can be restored without reconnecting the backup to an infected environment.
Does Having a Backup Prove You Can Recover?
No. A backup exists only in theory until you can restore usable files from it. CISA recommends regularly testing restoration and checking backup integrity, because an untested backup may be incomplete, damaged, encrypted, or otherwise unsuitable. CISA's ransomware guide covers backup testing.
Cloud storage does not automatically solve the problem. Synchronization can copy encrypted files to the cloud, so recovery depends on version history or a ransomware-recovery feature that can return files to an earlier clean state. For future protection, keep multiple copies on different media and in different locations. At least one copy should remain offline and disconnected except during backup operations.
You Might Also Like
- Ransomware Attack: Common Scams and Follow-Up Threats
- What Is New With Ransomware Attacks in August 2026? Latest breach notices and security advisories and Key Takeaways
- Ransomware Update 2026: Disclosure, Response, and Open Questions