Piece of news of the day
ADVANCED SECURITY EUROPA
EOODSafe Mode Surprise: Ransomware Attack Foiled by Unintended Consequences
13 August 2026Huntress recently reported on a ransomware attack by the Akira affiliate that backfired when the attacker attempted to disable security tools by rebooting the victim's system into Safe Mode.
This prevented the ransomware from encrypting the files successfully.
The attacker gained access through a credential spraying attack on a SonicWall SSL VPN with no MFA, then accessed the domain controller, collected files, and transferred them to cloud storage.
Before deploying the ransomware, the attacker rebooted the system into Safe Mode, which disabled EDR and antivirus, but also interfered with ransomware detonation due to memory errors.
Huntress warned that while this was a lucky break for the victim, future attacks may not be so unsuccessful.
Organizations should take steps to protect themselves, including blocking credential spraying, deploying MFA, rotating compromised credentials, using EDR, deploying SIEM, and monitoring for Safe Mode boot configurations.
The attacker's mistake in this case may not be repeated in future attacks.

