AI Weekly Malaysia

Back to items Summaries

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

ID
13459
Status
summarized
Published
12 Aug 2026, 9:00 PM
Fetched
12 Aug 2026, 9:33 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/research/2026/08/12/akira-ransomware-scum-blocked-victims-security-tools-and-broke-their-own-encryptor/5286515
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
4.5
Created
12 Aug 2026, 9:35 PM
Tags
Audience
developerssaas_startup_founders

What happened

An Akira ransomware affiliate breached a victim via a SonicWall SSL VPN account that lacked MFA, then rebooted the machine into Safe Mode to kill security tools—but Safe Mode also broke the encryptor due to memory constraints. Huntress analyst James Northey warns this was a lucky break, not a reliable defense, since attackers could retool the encryptor to work in Safe Mode. Data and credentials were already exfiltrated before the encryption failed.

Why it matters

If you run a SonicWall SSL VPN or any VPN endpoint without MFA, you are the exact target profile described here—credential-spray attacks succeeded in seven minutes against an unprotected account. Enforce MFA on all VPN accounts now, and assume that even if encryption fails, attackers will still steal Active Directory data and file-share credentials before they leave.

Discussion angle

The attacker did a full Active Directory property dump of every user and computer—what does that tell us about minimizing blast radius if a single VPN account is compromised, and are Malaysian SMEs running SonicWall VPNs with MFA enforced?

Top