Same issue here today.
Was seeding a job to our offsite data-center. Different Cluster and Different DataStores.
Started restoring files for 3 VM's and then just after the job started our production systems became unavailable. Stopped the job immediately after seeing the log files state the VM's were deleted which saved the 3rd VM from getting hosed.
I'm in the process of going through the user account settings that run the job to remove delete access from the service account. I have done this in the past to our other data-center without changing or appending the name, I have a VM right now named the same living on our production and backup data-centers.
Very frustrating. Please build in a fail-safe or acknowledgment to the product for deletes.