← Back to Feed

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

August 13, 2026 · BleepingComputer · Severity: CRITICAL

An Akira ransomware affiliate bypassed endpoint detection by restarting a compromised system into Safe Mode with Networking, disabling the EDR solution. While the attackers successfully exfiltrated data, the encryption phase of the ransomware attack ultimately failed.

Key Takeaways

  • Akira affiliate rebooted into Safe Mode to disable EDR before data theft.
  • Attackers successfully stole data but failed to encrypt the target system.
  • Defenders must monitor for Safe Mode reboots as an EDR bypass technique.
☕ Buy a Coffee