Your immutable backup has a permission that deletes it
"Our backups are immutable" is an incomplete sentence, and Amazon's documentation proves it. Object Lock has two modes: in compliance mode nobody can delete anything, not even the root user, and the only documented way out is closing the AWS account; in governance mode anyone holding the s3:BypassGovernanceRetention permission can delete. Both are called immutability. And AWS adds a note almost nobody has read: the web console includes the header needed to override the lock by default, so the friction exists in the API and vanishes in the interface. Also: why the intuitive test (trying to delete an object) returns 200 OK and misleads you in both directions, why Veeam adds 30 days to the immutability you configured on S3, and what that 93% / 16% study doing the rounds in September actually says —including a sample that looks nothing like your company—. And at the end, a sentence with four blanks that whoever runs your backups has to be able to finish.