The Attack That Destroys Both Your Data AND Your Backups
Here is a nightmare scenario that is happening right now to small businesses across the country: a business buys a NAS device β a QNAP, Synology, or WD My Cloud β to serve as their central file server and backup target. They set it up, plug it into the network, and forget about it. Years pass. The firmware is never updated. The default admin password is never changed. The admin panel is accessible from the internet because someone wanted remote file access.
Then an attacker finds the NAS on an automated scan. They log in with the default credentials. And they deploy ransomware that encrypts everything on the NAS β the live data, the backups, the archives. The business discovers they have lost everything when they come in on Monday morning and find a ransom note on every shared drive.
This is not hypothetical. Ransomware gangs have shifted focus to NAS devices specifically because small businesses use them as backup targets. Encrypting the NAS means there is no backup to restore from. The victim has no choice but to pay β or lose everything.
NAS Vulnerabilities Added to CISA KEV in 2026
Step 1: Check If Your NAS Is Exposed to the Internet
The single most important question: is your NAS admin panel reachable from the public internet? If yes, you are in immediate danger.
How to check:
- Open your NAS admin panel. Go to Network Settings or Remote Access.
- Look for any feature labeled "Remote Access," "Cloud Access," "myQNAPcloud," "QuickConnect," or "My Cloud."
- If any of these are enabled, your NAS is almost certainly reachable from the internet.
- Also check: did you set up port forwarding on your router to make the NAS accessible from outside? If so, disable it.
π‘οΈ Immediate Steps to Lock Down Your NAS
- 1. Disable internet access to the admin panel. Turn off cloud access features. Remove port forwarding rules. The NAS admin interface should only be accessible from your local network β nowhere else.
- 2. If you genuinely need remote file access: Use a VPN to connect to your local network first, then access the NAS. Never expose the NAS directly to the internet. Cloudflare Tunnel (free) and Tailscale (free) are better alternatives to port forwarding.
- 3. Change ALL default passwords. Admin accounts, user accounts, service accounts β every password on the NAS must be unique and strong. Use your password manager.
- 4. Update the firmware. Download and install the latest firmware from the manufacturer. Enable automatic updates if available.
- 5. Disable any services you do not use. FTP, Telnet, SSH, DLNA media server, iTunes server β if you are not actively using it, turn it off. Each one is an attack surface.
- 6. Enable firewall rules on the NAS. Block connections from countries you do not do business with. Rate-limit login attempts. Enable IP blocking after repeated failures.
Step 2: Your NAS Backup Is Not a Backup
Many small businesses set up their NAS and think "great, we have backups." Then ransomware hits, encrypts the NAS, and they realize they had no off-site backup at all. A NAS sitting in the same building as your computers is not an off-site backup β it is just a second copy on the same power grid, in the same fire zone, connected to the same network.
The 3-2-1 backup rule exists for exactly this reason:
- 3 copies of your data (production + 2 backups)
- 2 different types of media (NAS + cloud, or NAS + external drive)
- 1 copy off-site (cloud backup, or a drive stored at a different location)
If your NAS is your only backup location, you are a single ransomware attack away from complete data loss. Add a cloud backup layer: Backblaze ($7/month/computer, unlimited), IDrive, or Wasabi + a backup tool. The cloud copy is air-gapped from your network β even if ransomware encrypts everything on-premises, your cloud backup is untouched.
NAS Brands β What to Do for Each
Bottom Line
NAS devices are powerful, affordable, and easy to set up β which is exactly why they have become a prime target. Do these three things today:
- Disconnect your NAS admin panel from the internet. If you need remote access, use a VPN.
- Update the firmware and change all default passwords.
- Add an off-site cloud backup. Your NAS backup is not a backup if it sits in the same building.
Small Business Backup Strategy Guide
Set up a ransomware-proof 3-2-1 backup strategy. Exactly what to back up, which tools to use, and how to test that restores actually work.
Read Backup Strategy Guide β