{
  "id": 1513870,
  "title": "Ransomware gang crashes own attack — with no-one to blame but themselves",
  "url": "https://urgent.news/2026/08/17/ransomware-gang-crashes-own-attack-with-no-one-to-blame-but-themselves",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-17T16:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/ransomware-gang-crashes-own-attack-with-no-one-to-blame-but-themselves"
  },
  "original_language": "en",
  "account": "In a recent ransomware attack, the Akira group inadvertently sabotaged their own operation. The cybercriminals attempted to disable security defenses by booting the infected device into Safe Mode with Networking. This typically disables antivirus and endpoint detection and response (EDR) programs, creating an opening for the ransomware to execute. However, Akira's encryptor failed to launch, as the Safe Mode environment lacked sufficient virtual memory. Consequently, the attackers were forced to reboot the system normally, allowing Defender to detect and quarantine the malicious code. Huntress, a cybersecurity firm, has warned organizations about this particular vulnerability, recommending a series of proactive measures to prevent such incidents. These include setting up alerts for failed VPN login attempts, enforcing multi-factor authentication (MFA), disabling or IP-allowlisting SSL VPNs during active attacks, rotating AD and VPN credentials, and deploying EDR on every host. Additionally, SIEM logging and monitoring VPN and Windows event logs are suggested to detect any suspicious activities early on.",
  "summary": "In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}