N-able, Inc. expanded its Anomaly Detection capabilities in Cove Data Protection to combat the surge in identity-driven cyberattacks targeting backup environments. The new functionality delivers real-time alerts when suspicious or unauthorized changes to backup policies are detected - giving customers an early warning system against the credential-based tactics attackers use to disable or corrupt backups before deploying ransomware. Identity-based attacks have become a major driver of successful cyberattacks, with AI making these schemes even more convincing.

With stolen or phished credentials, attackers can gain access to backup software and weaken backup policies. The 2025 Verizon Data Breach Investigations Report found that roughly 88% of basic web application breaches involved stolen credentials, making it clear how widespread this tactics has become. Once inside, attackers - and sometimes well- intentioned employees - can alter retention policies, exclude critical data from backups, and delete protected devices.

These are subtle changes that can go unnoticed for weeks or even months before the attacker triggers the final ransomware event. To give IT teams real-time visibility, Anomaly Detection introduces a vital layer of protection through event-based notifications that highlight these indicators of compromise. This capability notifies users of potential cyberattack signals or misconfigurations before they escalate, allowing organizations to take just-in-time action to safeguard their recovery posture and maintain data resilience.

This new capability builds on last year's Anomaly Detection feature, Honeypots, an always-on defense mechanism designed to detect branch-force attacks on backup infrastructure.