Criminal hackers find workaround to disable protective software, successfully stealing data while encryption attack fails.
A cybercriminal group known as Akira has discovered a troubling technique to break through one of the most important defenses companies use to protect their computers. By forcing systems into a special startup mode called Safe Mode, these attackers managed to turn off protective software that normally catches and stops malicious activity. In these recent incidents, they successfully grabbed sensitive information from their targets but unexpectedly failed to lock down the systems with ransomware—the final step that typically forces victims to pay large sums of money.
This development reveals a significant gap in how organizations defend themselves against sophisticated digital thieves. It's similar to a burglar discovering that a home's alarm system shuts down during maintenance hours, allowing them to enter undetected and steal valuables, though they accidentally leave before locking the owners inside.
Security professionals rely on special monitoring tools called Endpoint Detection and Response systems—think of them as security guards watching every computer in an organization. These tools catch suspicious behavior in real time. The Akira group found that by moving computers into Safe Mode (a basic startup condition that only runs essential programs), they could disable these watchful guardians temporarily.
Once the protective systems were offline, the criminals had free access to steal company files, customer information, and confidential documents. However, something went wrong during their final step: they were unable to deploy the encryption attack that would have locked all the stolen data and made systems unusable until payment arrived.
This incident highlights that no single security tool provides complete protection. Companies that relied too heavily on one defensive system found themselves exposed. The attack shows that:
The incomplete attack also suggests these criminals are still learning and improving their methods, making future attempts potentially more dangerous.
If you work at any business that stores customer information, financial records, or proprietary details, this affects you directly. A successful data theft can lead to stolen identities, financial fraud, leaked trade secrets, and damaged reputation—even without the dramatic encryption that makes news headlines. Organizations across industries from healthcare to finance to manufacturing rely on the same types of protective systems the Akira group bypassed.
The real threat isn't just the obvious ransomware demand—it's the quiet theft of your private information.
The lesson here is clear: as attackers find new methods to bypass our defenses, we must continuously strengthen our security approach from multiple angles.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →