How continuous backup protects data from the latest ransomware attacks.
On May 11, 2026, cybersecurity researchers discovered a new ransomware strain called Prinz Eugen. It targets and encrypts recently modified files before a standard daily backup window can run.
Traditional ransomware encrypts files alphabetically, which takes hours and gives IT teams a chance to pull the plug mid-attack. Prinz Eugen sorts files by their most recent modification timestamp. By encrypting the newest files first, the malware instantly cripples daily operations.
The malware locks data using a military-grade algorithm. Each file is given a unique cryptographic value — unlocking one file does not help unlock any others. The malware mathematically confirms a file is successfully locked before it deletes the unencrypted original.
Continuous backup is highly effective against modern ransomware tactics such as the Prinz Eugen strain. However, continuous backup solves only half of the problem. True protection requires pairing continuous with immutability and point-in-time versioning.
How Continuous Backup Defeats “Recent File” Targeting
Traditional backups run nightly, leaving a 24-hour vulnerability window. Strains that prioritize new or modified files exploit this gap. Continuous data protection (CDP) saves files almost immediately after they are created, shrinking the recovery point objective (RPO) to seconds or minutes.
If ransomware begins a rapid sweep of the newest files, a continuous backup engine uploads the unencrypted versions to the cloud just moments before the local malware reaches them.
However, there’s a catch. “Continuous” isn’t enough on its own.
Tools such as OneDrive will automatically sync files from individual devices to the cloud. However, the tools play into the hands of threat actors. Simple sync tools see the newly encrypted ransomware files as “new changes.” They immediately sync the encrypted version to the cloud, overwriting the good files.
Protecting Backup Data from Ransomware
Continuous backup must also protect backup data to defeat the latest ransomware strains. One solution is immutable retention using write-once, read-many (WORM) storage. Once a file version is sent to the cloud by the continuous agent, it cannot be modified, deleted or overwritten by the ransomware. Protection is enforced at the storage layer, not by user permissions. Not even a system administrator or a hacker with high-level access can delete or encrypt the data before the retention period ends.
Another option is air gapping. Backup data is physically isolated from the network, usually stored on tapes or drives in a secure vault. It provides the highest level of protection because hackers cannot see or reach the data over a network. It also reduces the risk of insider threats because it requires physical access.
However, air gapping is slow. Media must be physically retrieved, mounted and loaded. Immutable storage is fast. Data is online and can be restored immediately over the network. As a result, air gapping should be used for “golden copy” or last-resort backup to protect the most critical data from catastrophe. Immutable storage is better for day-to-day backups. It provides rapid recovery during a cyberattack while ensuring the hacker cannot wipe out backup files.
Why Point-in-Time Versioning Is Essential
Another critical feature is point-in-time versioning. When an attack occurs, it gives organizations the ability to roll back the clock.
Point-in-time versioning automatically preserves earlier versions of files. Each version is tagged with a date and time stamp. Instead of just reverting to “yesterday’s backup,” administrators can roll back a single file, database or entire file system to a specific minute.
The primary use of point-in-time versioning is recovery from user error. If a user accidentally deletes a file or a folder, administrators can navigate back in time to the moment before the deletion and restore it. If a document is saved with major mistakes, administrators can open a previous version to recover the lost work.
However, point-in-time versioning also aids in ransomware recovery. If ransomware strikes, administrators can roll back the entire system to one minute before the infection started. This allows them to restore the most recent, unencrypted versions of the files.
Continuous Backup from Datto
Datto offers robust protection against ransomware in automated, easy-to-administer platforms. The Datto product line includes both real-time syncing and frequent, automated snapshots.
Datto File Protection provides true continuous backup. The background agent constantly monitors the designated folders for data adjustments. The moment a file changes, it automatically uploads the updated version to the secure cloud. Built-in ransomware detection alerts administrators if there’s a sudden wave of file modifications. Administrators can restore older, unencrypted versions of those files.
Datto SIRIS & ALTO appliances use a near-continuous schedule, executing block-level incremental backups as frequently as every five minutes. This approach reduces potential data loss to a negligible window while avoiding system performance lag. Inverse Chain Technology stores each snapshot as a fully constructed, independent recovery point. This eliminates long, fragile dependency chains and guarantees rapid restoration.
Datto Endpoint Backup is built specifically for PCs and laptops. It copies continuous, image-based snapshots of the operating system, applications and files directly to the cloud. Like Datto’s server solutions, it spins up the PC image in the cloud to verify the backup is uncorrupted and bootable, alerting admins if a check fails. If a device is infected with ransomware, administrators can roll back the entire PC to a clean snapshot from right before the attack.




