🔐
Security 📅 2026-08-14 · 04:59 AM IST ⏱ 3 min read

Akira Gang Bypasses Security Tools, Steals Files but Leaves Systems Unencrypted

Criminal hackers find workaround to disable protective software, successfully stealing data while encryption attack fails.

A New Attack Method Leaves Businesses Vulnerable

A cybercriminal group known as Akira has discovered a troubling technique to break through one of the most important defenses companies use to protect their computers. By forcing systems into a special startup mode called Safe Mode, these attackers managed to turn off protective software that normally catches and stops malicious activity. In these recent incidents, they successfully grabbed sensitive information from their targets but unexpectedly failed to lock down the systems with ransomware—the final step that typically forces victims to pay large sums of money.

This development reveals a significant gap in how organizations defend themselves against sophisticated digital thieves. It's similar to a burglar discovering that a home's alarm system shuts down during maintenance hours, allowing them to enter undetected and steal valuables, though they accidentally leave before locking the owners inside.

Understanding the Technical Approach

Security professionals rely on special monitoring tools called Endpoint Detection and Response systems—think of them as security guards watching every computer in an organization. These tools catch suspicious behavior in real time. The Akira group found that by moving computers into Safe Mode (a basic startup condition that only runs essential programs), they could disable these watchful guardians temporarily.

Once the protective systems were offline, the criminals had free access to steal company files, customer information, and confidential documents. However, something went wrong during their final step: they were unable to deploy the encryption attack that would have locked all the stolen data and made systems unusable until payment arrived.

What This Means for Your Organization

This incident highlights that no single security tool provides complete protection. Companies that relied too heavily on one defensive system found themselves exposed. The attack shows that:

The incomplete attack also suggests these criminals are still learning and improving their methods, making future attempts potentially more dangerous.

Why You Should Care

If you work at any business that stores customer information, financial records, or proprietary details, this affects you directly. A successful data theft can lead to stolen identities, financial fraud, leaked trade secrets, and damaged reputation—even without the dramatic encryption that makes news headlines. Organizations across industries from healthcare to finance to manufacturing rely on the same types of protective systems the Akira group bypassed.

The real threat isn't just the obvious ransomware demand—it's the quiet theft of your private information.

What You Can Do

The lesson here is clear: as attackers find new methods to bypass our defenses, we must continuously strengthen our security approach from multiple angles.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →