HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Akira Ransomware Affiliate Bypasses EDR via Safe Mode, Exfiltrates Data After VPN Credential Theft

An Akira ransomware affiliate accessed a network through an exposed SonicWall VPN lacking MFA, disabled endpoint detection by booting into Safe Mode, and stole files to an attacker‑controlled S3 bucket. The incident underscores gaps in access‑control and continuous‑monitoring controls required for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Akira Ransomware Affiliate Bypasses EDR via Safe Mode, Exfiltrates Data After VPN Credential Theft

What Happened — An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN that lacked multi‑factor authentication. After logging in, the attacker used RDP to reach the domain controller, harvested AD data, and moved laterally to an application server. By forcing the host into Windows Safe Mode with Networking, they disabled both the Huntress MDR agent and Microsoft Defender, exfiltrated files to an attacker‑controlled S3 bucket, and attempted—but failed—to launch the ransomware payload.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how weak VPN authentication can bypass SOC 2 CC6.1 (Logical Access Controls) and leave organizations without verifiable evidence of credential hygiene.
  • Shows the need for continuous monitoring of endpoint protection status (CC7.2) and the ability to produce audit‑ready logs when security tools are disabled.
  • Highlights the importance of documented Safe Mode change‑detection as part of a defensible incident‑response control set.

Who Is Affected — Enterprises that expose VPN gateways to the internet, especially those relying on third‑party MDR/EDR solutions for endpoint visibility.

Recommended Actions

  • Enforce MFA on all VPN accounts and regularly audit VPN configurations.
  • Implement SOC 2‑aligned monitoring for Safe Mode boot changes and unauthorized remote‑access tool registry modifications.
  • Validate that EDR agents generate immutable logs that survive Safe Mode sessions for audit evidence.

Technical Notes – Attack vector: stolen VPN credentials → RDP → Safe Mode boot → EDR/AV disable. Tools used: WinRAR, s5cmd (S3 upload), AnyDesk. No ransomware encryption succeeded; data exfiltration achieved. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →