What's happening in data protection: September 2026
What's happening in data protection: September 2026
Attackers and defenders both put AI to work this month. On offense, AI agents broke into a company network in under 10 hours. On defense, backup platforms now plug into tools that detect attacks and launch recovery automatically. The weak spot hasn’t moved: recovery only works if the backup actually ran.
Druva uses backup snapshots to confirm ransomware
Druva rolled out AI-driven ransomware detection that scans backup snapshots for attack patterns such as ransom notes, suspicious file extensions, and mass file renaming. The platform runs forensic checks to filter out false alarms, then identifies the clean snapshot to restore. Druva also maps how a compromised identity moved through Entra ID, Active Directory, and Okta. The company says this can cut investigation time from days to hours.
Backup data now doubles as forensic evidence, which raises the stakes on knowing every job actually completed.
HYCU adds Azure DevOps to its SaaS coverage
HYCU extended its Microsoft SaaS protection to Azure DevOps. That adds another developer workload to the growing list of SaaS data that needs its own backup.
Every new SaaS workload brings a new job, a new policy, and one more place for a failure to hide.
Rubrik opens its resilience data to AI agents
Rubrik now gives customers’ own AI agents access to its protection and resilience data. Backup status is becoming an input for automated operations, not just something people read on a dashboard.
Once agents act on backup status, a stale or incomplete record stops being a reporting problem and becomes an operational one.
45Drives builds a central console for MSPs
45Drives expanded its SnapShield platform with two additions:
- Exfiltration detection that flags suspicious file-access behavior that may signal data theft.
- A centralized management system that lets enterprises and MSPs protect and monitor many servers, locations, and customer environments from one interface.
Vendors keep building single-pane views for their own products, but most MSPs run more than one product.
Silent failures remain an MSP pain point
A NovaBackup look at MSP and SMB backup operations argues that missed notifications, silent failures, and untested restores still plague multi-tenant backup services. The piece says customers now treat two things as the baseline: automated alerts that create actionable tickets, and scheduled restore testing.
When clients assume verification happens by default, the MSP that can’t show proof carries the risk.
CrowdStrike agents can now trigger backup recovery
At Fal.Con 2026, CrowdStrike connected its Charlotte Agentic SOAR to Commvault and Rubrik recovery actions.
- With Commvault, the workflows can:
- lock down backup systems during an attack
- suspend data aging policies to preserve clean recovery points
- restore suspect assets into a cleanroom for forensic review
- With Rubrik, they can undo malicious Active Directory changes or trigger automated forest recovery.
Security tools now act directly on backup systems, so both teams need an accurate shared picture of what’s protected before an incident starts.
AI agents become the next target
Bugcrowd’s CEO told Axios he expects attackers to start hacking AI agents rather than people. The security industry has warned for more than a year that agent identities represent the newest form of insider threat.
Every agent you grant access to backup data is also a new identity to watch.
AI agents breach a network in under 10 hours
Palo Alto Networks’ Unit 42 investigated a ransomware intrusion in which a human attacker handed the tactical work to AI agents. The agents breached an enterprise network in under 10 hours, work Unit 42 estimates would take human operators about two weeks. They relied on more than 50 known techniques and no zero-days. On the way out, they left the victim an 80-page report on its own security gaps.
When attacks move this fast, a backup failure you find in next week’s report is a failure you found too late.
Gentlemen ransomware hits a Canadian airline
AhnLab’s weekly dark web roundup flagged a Gentlemen ransomware attack on a Canadian airline. The same report noted LAPSUS$ resuming activity and new data extortion attacks on organizations in South Korea, Germany, and Argentina.
Transportation belongs on the list of sectors where downtime hits customers immediately and recovery speed becomes the headline.
Boston Scientific’s recovery drags into September
TechCrunch’s updated roundup of 2026’s worst hacks notes that Boston Scientific’s August cyberattack disrupted the company’s global operations. The medical device maker needed two weeks to clear the immediate outage, and its recovery has stretched into September.
Bringing systems back online takes days, but getting back to normal takes much longer, which makes recovery readiness a business metric and not just an IT one.
That’s your September 2026 data protection roundup. We’ll be back next month with another look at what’s making news in backup, storage, and cyber resilience.