Case studySaaS

Defeating stealth ransomware with Deep File Inspection

How Elastio identified the last clean recovery point and restored a SaaS company in hours after fileless ransomware defeated endpoint defenses.

"For a SaaS company, long-term downtime is the kiss of death. If you can't meet your SLAs, it can be an extinction-level event."

Jeff Fudge, Director of Cloud Solutions, JetSweep
Customer profile
Industry
SaaS
Partners
JetSweep, AWS
Environment
AWS Backup, Data Recovery
The attack

Fileless ransomware bypassed every defense

On a Saturday morning, JetSweep received an urgent call from AWS. A SaaS company had been hit by ransomware. Operations were down.

The breach originated from an unpatched firewall. JetSweep secured the entry point quickly. But the deeper problem was recovery: the attackers had deployed fileless ransomware, encrypting data over time while hiding the decryption key in memory.

Operations appeared normal during the attack. Even with endpoint protection in place, the attack went undetected. Worse, the corrupted data had already been copied into backups. The company had no reliable recovery path.

The recovery

Clean backup identified in hours, not weeks

JetSweep deployed Elastio. The Hunt Engine performed Deep File Inspection across every backup, identifying:

  • Which backups contained ransomware artifacts
  • When the infection began
  • The last provably clean recovery point

The company restored operations within hours, avoiding weeks of manual trial-and-error verification.

"Elastio allowed us to see almost immediately which backups were clean. That saved us days, possibly weeks, of trial and error."

Jeff Fudge, Director of Cloud Solutions, JetSweep
Proactive vs. reactive

The case for continuous verification

Elastio is designed to run continuously, verifying data integrity before an attack so organizations always have a provable clean recovery point ready. In this case, Elastio was deployed after the attack to accelerate recovery.

That is not the ideal scenario. Had Elastio been running before the incident, the company would have avoided 11 days of data loss and had an immediate recovery path.

Hours, not weeks
Clean backup identified within hours, eliminating weeks of manual effort
10-day RPO
Most recent clean backup was 10 days old. Without Elastio, recovery may not have been possible.
Zero reinfection
Agentless Deep File Inspection ensured compromised backups were never restored
Continuous protection
Company adopted ongoing Deep File Inspection to prevent recurrence

Details have been anonymized to protect the privacy and security of the organization. Core facts and recovery strategies remain unchanged.

Frequently asked questions

Questions about this engagement

How quickly was the company able to recover with Elastio?

The company restored operations within hours, avoiding weeks of manual trial-and-error verification.

How old was the last clean backup found?

The most recent clean backup was 10 days old. Without Elastio, recovery may not have been possible.

Why did endpoint protection fail to catch this attack?

The attackers deployed fileless ransomware, encrypting data over time while hiding the decryption key in memory. Operations appeared normal during the attack, so endpoint protection did not detect it.

How was Elastio used in this incident?

JetSweep deployed Elastio after the attack. The Hunt Engine performed Deep File Inspection across every backup to identify which backups contained ransomware artifacts, when the infection began, and the last provably clean recovery point.

Is Elastio designed as a reactive tool?

No. Elastio is designed to run continuously, verifying data integrity before an attack so organizations always have a provable clean recovery point ready. In this case it was deployed after the attack to accelerate recovery.

What could have been avoided with proactive deployment?

Had Elastio been running before the incident, the company would have avoided 11 days of data loss and had an immediate recovery path.

How did the attackers get in?

The breach originated from an unpatched firewall. JetSweep secured the entry point quickly, but the deeper problem was that fileless ransomware had already encrypted production data and that corrupted data had been copied into backups.

PROVE YOUR RECOVERY

Ready to see your last known
clean point?

Book a Recovery Assessment