The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 09:52 am AEST · 14 August 2026

Akira hackers reboot systems into Safe Mode to disable defenses

Akira hackers reboot systems into Safe Mode to disable defenses
Photograph: BleepingComputer

An Akira ransomware affiliate rebooted a compromised machine into Windows Safe Mode to disable security tools and steal data, cybersecurity firm Huntress reported.

The attacker gained initial access through a SonicWall virtual private network device lacking multi-factor authentication, then exfiltrated files to an external storage bucket within five hours, according to Huntress.

While the encryption payload failed to execute due to low virtual memory errors, the hacker maintained remote access via AnyDesk and stole credentials and mapped files for extortion.

Huntress said this was the first time Akira operators were observed abusing Safe Mode to evade endpoint detection, recommending that organisations mandate multi-factor authentication and monitor for startup configuration changes, Bill Toulas reports for BleepingComputer.

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. bleepingcomputer.com
ransomwarecybersecuritydata-breachmalware

Follow the live coverage →

Akira hackers reboot systems into Safe Mode to disable defenses | The Financial Register Inward Money