# Security Concerns with Duplicati, Cryptomator, and Google Drive

**URL:** https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578
**Category:** Support
**Created:** [July 25, 2026, 10:43am UTC](https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578 "2026-07-25T10:43:34Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![jack\_tiner](https://forum.duplicati.com/user_avatar/forum.duplicati.com/jack_tiner/32/12761_2.png) [@jack\_tiner](https://forum.duplicati.com/u/jack_tiner)
#### Post date: [July 25, 2026, 10:43am UTC](https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578/1 "2026-07-25T10:43:34Z")

</div>

I want to set up a backup system for my data using Duplicati, Cryptomator, and Google Drive, but I still have some unanswered security questions.

1. First, I have two types of usage. 1. My first is a folder I use for important data (account information, photos, etc.), which I rarely open. 2. My second is a folder I use daily, where I almost always add, modify, and update files, such as my projects and notes. In short, we can divide them into personal and projects/notes folders.

What I plan to do is encrypt both of these areas with Cryptomator (my personal files will be stored in the cloud, not on my computer) and use Duplicati to incrementally back up my current project/notes folder to Google Drive. (I think it connects via something like an API connection, that’s why we don’t open the account in the browser, as far as I know…)

BUT

Could my account and files, which I backed up to Google Drive with Duplicati, be damaged or accessed by viruses, ransomware, or similar threats?

Even though I use 2-factor authentication, secure passwords, and haven’t been caught by phishing attacks so far, just in case I ever encounter such a threat, could this setup I’m trying to do cause me problems? I await your suggestions.

---

<div class="post-metadata">

### Author: ![kenkendk](https://forum.duplicati.com/user_avatar/forum.duplicati.com/kenkendk/32/5305_2.png) [@kenkendk](https://forum.duplicati.com/u/kenkendk)
#### Post date: [July 26, 2026, 3:32pm UTC](https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578/2 "2026-07-26T15:32:03Z")

</div>

> [@jack\_tiner](#):
>
> Could my account and files, which I backed up to Google Drive with Duplicati, be damaged or accessed by viruses, ransomware, or similar threats?

That depends on your threat scenario. If you consider a dedicated attacker got access to your machine, they would (potentially) be able to gain Administrator / root access to your machine and read any file and any memory on the machine. That means that any secret (key, passphrase, token, login, etc) is accessible to an attacker. With that information, they would most likely be able to access and destroy anything stored in a cloud account (as you would have the information on the compromised machine).

If you are only worried about generic threats, such as encrypting ransomware, they do tend to try to destroy or deactivate backups, but you may be able to recover by using Google’s retention tools.

> [@jack\_tiner](#):
>
> Even though I use 2-factor authentication, secure passwords, and haven’t been caught by phishing attacks so far, just in case I ever encounter such a threat, could this setup I’m trying to do cause me problems? I await your suggestions.

The problem is that you do not want to enter your 2FA for **every** request to Google or another cloud service. So all apps, webpages, etc. will store a token that is already authenticated with 2FA and is approved without needing 2FA. If your machine is compromised, attackers will have access to such tokens as well. There are _many_ mitigations applied by Google and other providers to prevent this, but 2FA does not guards against device compromise.

---

<div class="post-metadata">

### Author: ![jack\_tiner](https://forum.duplicati.com/user_avatar/forum.duplicati.com/jack_tiner/32/12761_2.png) [@jack\_tiner](https://forum.duplicati.com/u/jack_tiner)
#### Post date: [July 26, 2026, 4:37pm UTC](https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578/3 "2026-07-26T16:37:33Z")

</div>

Thank you for the information. So, as I understand it, the security measures I can take with Duplicati against computer-accessing threats are limited. The strongest measure against these threats is a storage device that is not physically connected to the internet. Is that correct?

---

<div class="post-metadata">

### Author: ![ts678](https://forum.duplicati.com/letter_avatar_proxy/v4/letter/t/8491ac/32.png) [@ts678](https://forum.duplicati.com/u/ts678)
#### Post date: [August 2, 2026, 2:06am UTC](https://forum.duplicati.com/t/security-concerns-with-duplicati-cryptomator-and-google-drive/22578/4 "2026-08-02T02:06:01Z")

</div>

> [@jack\_tiner](#):
>
> I think it connects via something like an API connection

“Google Drive” on Duplicati uses that API. Although I don’t recommend it, you can also have Duplicati use the file interface that your Google Drive probably provides.

The security issue either way is that malware that gets on your machine could harm any files visible on system, including ones easily accessed as files on Google Drive.

What makes it worse is the multiple-machine convenience of Google Drive provides many potential access paths. Easy for you, but also easy for anything getting in one.

Using a less easily accessed online destination means malware will have a tougher time destroying backups. Fully offline is hard on malware, but also hard on your use.

[Using remote file locking](https://docs.duplicati.com/security-and-secrets/using-remote-file-locking) is almost as good as online gets, but takes some setup.

> [@jack\_tiner](#):
>
> encrypt both of these areas with Cryptomator (my personal files will be stored in the cloud

Which cloud? If you mean Google Drive, and the backup will go to the same area, that’s almost never a safe plan, as damage to that area can wipe out both at once.

Avoid getting into situations where all the copies can be simultaneously destroyed. Unfortunately, this works against local offline (better against malware, but not fires).

You should decide how much it’s worth to reduce risk of losing data. More backups stored in separate places can reduce loss risks. See “3-2-1 rule” and its variations.

You can occasionally sync a cloud to a usually-offline USB drive to increase safety.  
[SyncTool](https://docs.duplicati.com/duplicati-programs/command-line-interface-cli-1/synctool#usage) can help with that. Cryptomator use might use Google Drive mirroring, so  
you just make your own manual mirror with any tool sometime when state is stable.

Or you could run occasional separate backup to reduce danger from software error.

This has spoken mostly about damage to destination. Except for file locking, that’s  
not something Duplicati can solve. Its encryption can reduce risks from file reading,  
however if there’s already malware on your machine as you, I think it can read files.

I’m not a Cryptomator expert, but they have their own forum where you can discuss.

> [@jack\_tiner](#):
>
> The strongest measure against these threats is a storage device that is not physically connected to the internet. Is that correct?

It shouldn’t be connected to anything, especially attacker-controlled computer,  
which might be your computer. A totally compromised computer is bad news.

[What Cryptomator Is Not](https://docs.cryptomator.org/security/security-target/#what-cryptomator-is-not) has similar warning about having infected computer.

Since you said “strongest”, a question is how far towards that is it worth going?

Perfection is impossible, and sometimes malware is just going after easy attack  
such as ransomware encrypting all files it finds. Skilled humans could do worse,  
however they are scarcer, so probably will go after targets that are worth hitting.

In my view, attacker needs to be cost-effective. Same for you on defensive side.
