If they are at all a competent company, they have immutable backups that can’t be deleted. Where I work our safest backups I cannot even delete. In fact, no one can; they are object locked and literally cannot be deleted. No ransomware, admin, or user can nuke them. (In other words, even a takeover of my highest-level admin account would not be enough to delete these backups. The attacker would actually have to hack AWS itself, a vastly more difficult proposition.)
To delete our backups, as mentioned above someone would have to hack into AWS itself (very, very difficult), and then hack the object lock mechanism (nearly impossible) and then manually delete the data from all 20-30 datacenters it’s replicated across. This is something even a state-level actor with millions in funding would find just about impossible.
Any business that does not do something like the above is operating at clown level as it’s so cheap and easy.