Backups Are Not a Ceiling on Ransomware Loss
The most model-relevant finding in Mandiant M-Trends 2026 has no number attached, and it changes the shape of the ransomware loss magnitude distribution rather than a parameter in it.
A New Group, a Familiar Threat, a Different Objective
Infosecurity Magazine reported on 24 September 2026, drawing on research published by CyberXTron the day before, that a newly formed ransomware group calling itself n0n was first observed on 18 September and had, by 22 September, published information on over a dozen victims on its Tor-hosted leak site. The group runs double extortion in the conventional sense, stealing data and threatening to publish it. What distinguishes the reporting is the second threat: explicit promises to encrypt or destroy backups and shadow copies, framed so that victims believe they cannot recover their networks at all unless they pay.
Two details in the CyberXTron account deserve attention. Countdown timers on some victims have already reached zero and stolen data was released, which suggests that some victims declined to pay. And the intrusion path begins with compromised credentials sourced from third-party infostealer malware, with privileges escalated afterward to seize administrative tools. That path matters for what follows, because administrative tooling is precisely where backup infrastructure, identity services and virtualization management planes are administered.
The reason to write now is not the arrival of another group. It is that the reporting describes an attacker objective that most risk registers are not structured to represent.
The Finding Without a Number
Mandiant M-Trends 2026, covering 2025 incident response investigations and publicly released by Mandiant and Google, tends to be quoted for one statistic: global median dwell time of 14 days, up from 11 days the prior year, with the increase driven by long-running espionage operations and North Korean IT worker schemes. That figure is real and it is useful. It is also not the finding that should restructure a quantitative risk model.
The defining ransomware shift described in the report is qualitative: the primary objective moved from data theft to deliberate recovery denial. The named targets are backup infrastructure, identity services and virtualization management planes. The commercial logic is stated plainly in the reporting. Destroying backups removes the alternative to payment.
A benchmark statistic updates a parameter. A change in attacker objective updates the structure of the scenario. In a quantitative cyber risk management methodology, risk is the combination of loss event frequency and loss magnitude, each treated as a distribution and combined through Monte Carlo simulation. If the objective behind a loss event changes, the loss magnitude distribution behind that event changes shape, not merely location. Averaging across objectives produces a distribution that describes no actual scenario and, critically, understates the tail that a single objective can produce.
There is a caveat that belongs in the model documentation as well as the prose. The M-Trends data reflects one firm’s incident response caseload, heavily enterprise and sophisticated targeted intrusions. It is not population-representative. It is evidence about the direction of attacker objectives, not a frequency.
Two Magnitude Shapes, Not One Line
Most risk registers carry a single ransomware line, with backups listed as the control that caps loss magnitude. The recent evidence pulls in two directions at once, and the tension is instructive.
NCC Group’s Cyber Threat Intelligence Report for August 2026, as reported by Infosecurity Magazine on 23 September, records 1,073 organizations falling victim to ransomware in that month, a record high for 2026 and a 12 percent increase on 973 in July. The industrial sector was the most targeted, at 31 percent of incidents. The report also notes that some cyber-criminal groups have moved away from encryption in favor of going straight for outright data theft and extortion. NCC recommended tabletop exercises to prepare for real incidents and identify gaps.
Set that beside M-Trends and beside the n0n reporting, which threatens both data theft and backup destruction in the same campaign. “Ransomware” is not one scenario. It is at least two loss magnitude shapes, plus a combined case.
The first is a disclosure-extortion branch. Loss magnitude here is dominated by secondary loss: fines and judgments, reputation damage, competitive advantage effects, and secondary response cost, each weighted by a secondary loss event frequency. In this branch backups do almost nothing. The data is already gone; the ability to restore systems is beside the point.
The second is a recovery-denial branch. Loss magnitude here is dominated by primary loss: productivity loss while systems are unavailable, response cost, and replacement cost where rebuild is required. In this branch the backup is not a ceiling on loss. It is the attacker’s target.
The third is the combined case that n0n is advertising, where both shapes apply to the same event.
Survival Is a Probability, Not an Attribute
In the recovery-denial branch, what backups buy is conditional on whether the recovery infrastructure survives an intruder who holds administrative privilege. That makes backup survival a resistance strength question with its own probability, not a yes/no attribute in a control inventory. Resistance strength, properly understood, is the strength of controls relative to the force an attacker can apply. Against an operator who has escalated to administrative tooling and is deliberately hunting the recovery plane, the relevant comparison is not “are backups configured” but “can backup administration be reached from the identity plane the attacker will land on.”
This is where the phrase “backups tested” quietly misleads. A restore test usually means a restore succeeded in a calm environment with identity services up and virtualization management intact. The scenario that matters is a restore attempted when identity and virtualization layers are themselves compromised. Those are different events with different probabilities and different magnitudes.
The modeling fix follows directly. Split the ransomware line by attacker objective into disclosure extortion, recovery denial, and the combined case. Give each branch its own loss magnitude distribution. Model recovery-denial magnitude as a mixture conditional on the probability that recovery infrastructure survives. Then run the result through Monte Carlo simulation so the loss exceedance curve shows the tail that a single averaged line hides.
Estimating that survival probability is not a benchmark exercise. It comes from evidence the organization already has or can create: whether backup administration shares the identity plane the attacker will reach, whether restoration has been exercised with identity services assumed unavailable, how long a full rebuild without backups would take. These are questions that only the backup, identity and infrastructure owners can answer, working alongside whoever builds the model, because they are the ones who know which console shares which credentials and which recovery runbook assumes a functioning directory.
The broader lesson is worth stating plainly. A benchmark’s qualitative finding can carry more model-relevant information than its headline statistic, because it changes the shape of the distribution rather than a parameter. The 14-day dwell time figure is the number that gets quoted. The shift to recovery denial is the finding that should change the model.