🔐
Security 📅 2026-08-14 · 04:59 AM IST ⏱ 3 min read

Government Email System Infiltrated as Criminals Exploit Security Vulnerabilities for Dual Attack

Cybercriminals breached government email systems while simultaneously running cryptocurrency scams, using basic restart techniques to bypass security tools.

A Two-Front Attack on Government Systems

Criminals working with the Akira ransomware group have successfully penetrated a government email system while orchestrating a separate cryptocurrency fraud scheme. The attackers exploited a surprisingly simple weakness: they restarted a compromised computer into Safe Mode with Networking, a Windows feature that loads only essential programs. This allowed them to bypass endpoint detection and response (EDR) tools—think of these as digital security guards that watch for suspicious behavior on computers.

The breach represents a troubling combination of threats. While maintaining access to government communications, the same criminal network was simultaneously running financial scams involving digital currencies. This dual operation suggests a sophisticated, organized group with multiple revenue streams and diverse technical capabilities.

Understanding the Technical Weakness

The method used here is deceptively straightforward. Modern computers have a "Safe Mode" option that starts up with minimal software running. It's designed for troubleshooting, but criminals discovered it also disables many security programs. By restarting into this mode, attackers essentially put their security monitoring systems to sleep, creating an unguarded window to operate freely on the system.

It's like a security guard stepping away from their post—the building is still there, but nobody's watching for intruders. Once the guard leaves, criminals can take what they want without immediate detection.

Why You Should Care

Government email systems contain sensitive information about policies, citizen data, and potentially classified communications. A breach of this magnitude affects public trust and national security. Additionally, the fact that criminals are simultaneously running cryptocurrency fraud suggests they're building financial resources to fund even larger operations.

Three reasons this matters to ordinary people:

The parallel cryptocurrency scheme is particularly concerning because it shows how criminal organizations are diversifying. They're not just stealing data anymore—they're monetizing their access through financial fraud, making them wealthier and more dangerous.

What Organizations Need to Do Immediately

Government agencies and private companies should review how their EDR solutions function during system restarts and Safe Mode scenarios. Security tools need stronger protections that prevent attackers from simply bypassing them through basic computer functions.

Critical steps include:

What You Can Do

If you work in government or handle sensitive information, assume your systems may be vulnerable in similar ways. Report any unusual computer behavior to your IT department immediately. For everyone else, this is a reminder to use strong, unique passwords for government portals and enable two-factor authentication wherever available.

Watch for unusual account activity and be skeptical of unexpected requests for personal information, especially regarding finances or identity verification.

This attack demonstrates that sometimes the biggest security vulnerabilities aren't complex hacking techniques—they're simple features that security teams overlooked.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →