Hackers are using a normal Windows tool to steal data and make recovery harder
Attackers are misusing a normal Windows feature to quietly copy sensitive business information and remove backup restore points, making it harder for organizations to recover after an attack. Because this activity can look like routine system work, it may be difficult to notice until damage is already done.
Who is at risk
Businesses, schools, government offices, and any organization using Windows servers are most at risk, especially those managing employee logins and shared network systems.
What to watch for
Watch for missing restore points, unexpected backup changes, unusual administrator activity, or systems suddenly becoming harder to recover after suspicious behavior or file locking incidents.
What to do
Immediately review and limit who has administrator access on Windows servers, verify backups are protected and still available, and have your IT team investigate any unexpected changes to recovery or backup settings.
