Ncerio News blogCVE feed
What we measure across the estates we audit

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

BleepingComputer reports an Akira affiliate bypassed endpoint security by rebooting into Safe Mode.
13 August 2026

Security researchers at BleepingComputer have reported that members of the Akira ransomware gang compromised a corporate environment and successfully exfiltrated sensitive data. The incident highlights a specific evasion technique used to neutralize defensive controls before data theft occurred.

According to the report, the attackers managed to disable the endpoint detection and response (EDR) solution active on the targeted system. This was achieved by restarting the infected machine into Safe Mode with Networking. By operating within this specialized boot environment, the group bypassed the standard monitoring capabilities of the EDR software installed on the host.

Following the disabling of these protective measures, the threat actors proceeded to steal data from the victim's network. The source confirms that files were successfully extracted and taken off-premises. However, the operation did not result in encryption of the stolen or remaining data. Unlike typical ransomware incidents where files are locked for extortion, this specific campaign focused solely on theft without applying cryptographic locks to the affected systems.

The incident was listed and discussed on BleepingComputer. The publication detailed how the attackers exploited the Safe Mode feature to evade detection mechanisms that would normally monitor process execution and system changes in real time. This method underscores the risk of relying solely on endpoint security tools that may not maintain visibility during alternate boot states.

BleepingComputer provides regular updates on ransomware activities and threat actor tactics. The organization tracks incidents across various sectors, noting how different groups adapt their methods to bypass modern security architectures. This case illustrates a technical workaround used by the Akira affiliate to achieve their objective of data theft without triggering standard alerts or encryption protocols.

The scope of the attack was limited to the specific system compromised and its immediate network access. There is no public information suggesting the incident affected a broader industry segment beyond the direct victim. The focus of the reporting remains on the technical details of how EDR defenses were circumvented through boot configuration changes rather than software vulnerabilities or misconfigurations in other network layers.

Source: Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — BleepingComputer
← all posts  ·  CVE feed