Yes. They are often targeting IT providers of SMBs by phishing/otherwise compromising their credentials, and deleting backups before encrypting. It works sometimes, 2FA hygiene and secondary site redundancy are usually good enough to protect you.
I'm not sure if it's feasible to have ransomware lock backups as they're restored, however.