CYBERSECURITYTRACKER
TRACKING4,077 stories764 vuln stories
Permanent story citation

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4414

As cited

Citation snapshot as of .

ransomware

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled endpoint detection and response (EDR) protection by booting a compromised system into Safe Mode with Networking, then exfiltrated data but did not complete encryption of the target environment.

Why it matters: Organizations using Akira as a threat model need to ensure EDR solutions remain active across all boot modes and implement detection for Safe Mode restarts; this incident demonstrates a bypass technique that defenders should monitor for.

Source published
First seen by Cybersecurity Tracker

Source attribution