Akira Ransomware Uses Safe Mode to Bypass EDR Tools

Akira ransomware operators have found a way to neutralise one of the most common defences businesses rely on — and they are doing it without any sophisticated malware. Recent incidents show that Akira hackers are deliberately rebooting compromised systems into Windows Safe Mode to disable endpoint detection and response tools, then exfiltrating data before attempting encryption. For small and medium businesses that have invested in security software believing it keeps them protected, this is a wake-up call worth taking seriously.

How Akira Uses Safe Mode to Disable Your Security Tools

Endpoint detection and response software, commonly called EDR, is a layer of security that monitors activity on computers and servers in real time. Most EDR products are designed to flag or block suspicious behaviour the moment it happens. The problem is that many EDR agents do not load when Windows starts in Safe Mode — a diagnostic state originally built for IT troubleshooting, not production environments.

Akira operatives, once they have a foothold inside a network, are exploiting this quirk deliberately. They push remote commands to reboot target machines into Safe Mode, which silences the EDR software. With the watchdog effectively asleep, they move through the network, locate valuable data, and copy it out to external infrastructure they control. In the recent wave of incidents, encryption — the step that usually triggers ransom demands — failed to execute properly. That does not mean the victims got off lightly. Their confidential data was already gone.

Why Stolen Data Without Encryption Is Still a Crisis

There is a misconception that ransomware is only dangerous when it locks your files. Increasingly, criminal groups like Akira operate what the industry calls double extortion or, in cases like these, pure data theft. They threaten to publish sensitive business data, client records, financial documents, or employee information on dark web leak sites unless a ransom is paid. In some cases, stolen data is sold directly to other criminals without any public announcement.

For SMBs, the consequences are severe regardless of whether a single file gets encrypted. A data breach triggers regulatory notification obligations, erodes client trust, and can expose businesses to legal liability. If the stolen data includes employee credentials, those credentials often end up in infostealer logs and breach databases that circulate across dark web markets for months or years after the original incident.

What SMBs Should Do After Learning About This Technique

The Safe Mode EDR bypass highlights something that security professionals have said for years: layered defences matter more than any single tool. If your entire security posture depends on one software agent staying active, an attacker only needs to find one way to switch it off.

There are practical steps businesses can take now. First, speak with your IT team or managed service provider about whether your EDR solution has Safe Mode protections or a separate tamper-protection feature — some vendors have already released mitigations for this exact scenario. Second, review who has the ability to issue remote reboot commands on your network. Attackers need administrative credentials to force Safe Mode restarts, which means either your credentials were stolen or your access controls are too permissive. Third, treat credential hygiene as an ongoing operational concern, not a one-time setup task.

The Credential Connection You Cannot Ignore

Akira and groups like them rarely gain initial access through technical wizardry alone. In most documented cases, attackers get in using stolen or leaked credentials purchased from dark web markets, harvested through phishing, or extracted from infostealer malware logs. By the time they are rebooting your machines into Safe Mode, they have already been inside your environment long enough to map it.

This is precisely where monitoring for credential exposure makes a meaningful difference. Knowing that an employee's username and password have appeared in a breach database or infostealer dump — before an attacker acts on that information — gives businesses a narrow but real window to respond. Changing the exposed credentials, enforcing multi-factor authentication, and investigating how the exposure occurred can prevent an intrusion from ever starting.

Akira ransomware's Safe Mode technique is a reminder that modern attackers are patient, methodical, and creative. They find the gaps between your tools. Closing those gaps starts with knowing what is already exposed. You can find out in minutes by running a free audit at breachrr.com/audit.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →
Akira Ransomware Uses Safe Mode to Bypass EDR Tools · Breachrr · Breachrr