They deleted the backups at both data centres
Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.