Multi-CloudDetection & ResponseRetrospectives

Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2022, written in 2026 with the benefit of hindsight.

Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.

Signals worth watching

  • Access to backup storage from unfamiliar IPs, devices or identities.
  • Large downloads or copies of backup data.
  • Changes to backup retention, vault lock settings, soft delete or immutability policies.
  • Deletion of recovery points or backup vaults.
  • Privileged backup roles activated outside change windows.

Where the data lives

  • AWS: CloudTrail events for AWS Backup (DeleteRecoveryPoint, DeleteBackupVault, PutBackupVaultLockConfiguration) and S3 (GetObject on backup buckets, PutObjectLockConfiguration).
  • Azure: Azure Activity logs for Recovery Services and Backup vault operations; Defender for Cloud alerts; Azure Backup alerts.
  • Identity logs for administrator sign-ins.

A starting query

AWS Backup deletion and lock changes:

AWSCloudTrail
| where EventSource == "backup.amazonaws.com"
| where EventName in ("DeleteRecoveryPoint", "DeleteBackupVault", "DeleteBackupPlan",
    "PutBackupVaultLockConfiguration", "DeleteBackupVaultLockConfiguration")
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters

Response

  1. Treat unexpected backup deletion or retention changes as a likely ransomware precursor.
  2. Disable the identity and investigate.
  3. Verify backup integrity and immutability.
  4. Check for other signs of ransomware staging across the environment.
detect cloud backup theftLastPass2022

More on this story