Answer
Most ransomware incidents that touch an IBM i environment do not start on IBM i at all. They start on a Windows domain controller or a file server, and the attacker uses harvested credentials to move laterally, sometimes reaching a backup server or an FTP-connected share that has write access to IBM i save files. If that backup infrastructure is online and reachable with the same compromised credentials, an attacker can delete or encrypt the backups right alongside the production data, which turns a recoverable incident into an unrecoverable one. This is exactly why the offline or immutable copy needs to be genuinely out of reach of normal administrative credentials, not just a separate folder or a different login.
When evaluating a vendor's ransomware claim, ask three specific things: can any account, including a domain administrator or an IBM i QSECOFR-equivalent, shorten or delete the retention lock before it expires; does the offline copy require physical media rotation or is it enforced purely through software controls; and has the vendor's own team, or has the customer's IT team, actually performed a full restore from that isolated copy on a schedule. A vendor that cannot answer the credential-bypass question clearly is describing a backup that looks resilient on paper but has not been tested against how real ransomware attacks actually spread.