Cybersecurity August 14, 2026 · 5 min read

Ransomware Rebooted the Server Into Safe Mode — and the Security Software Never Saw It

William “BJ” Pote

CEO, eTop Technology

Here’s an uncomfortable question: what happens to your security software when the computer it runs on boots into Safe Mode?

For most third-party endpoint protection, the answer is: it doesn’t load. Safe Mode is Windows’ minimal-boot troubleshooting state — it deliberately skips most drivers and services, and that includes a lot of security tooling. Ransomware crews know this, and in an incident documented in detail this week, an Akira ransomware affiliate used it as the centerpiece of an attack.

The play-by-play is worth walking through, because almost every step has a direct lesson for a small or mid-sized business — including the step where the attack partially failed.

How the attack unfolded

According to the incident report, on August 4 the attacker logged into the victim’s SonicWall VPN using an account that had no multi-factor authentication. Not an exploit. Not malware. A username and password on an internet-facing VPN, and no second factor to stop it.

Within about two hours they had mapped the network’s Active Directory — the who’s-who and what’s-where of the environment. They installed AnyDesk, a legitimate remote-access tool, to keep a reliable way back in.

Then the notable part: they rebooted a machine into Safe Mode with Networking. The third-party security tooling didn’t load. Real-time antivirus protection was blinded. The report describes a roughly ten-minute window where the host had no working EDR at all. The attacker had pre-registered AnyDesk to run in Safe Mode via the registry, so their access survived the reboot while the defenses didn’t.

From there they harvested credentials and exfiltrated data — compressing files with WinRAR and shipping them to an attacker-controlled cloud storage bucket with a copy tool.

Where it went wrong for the attacker

The final act failed. The ransomware executable wouldn’t run in Safe Mode — it crashed with memory errors. And when the machine rebooted back to normal mode, a scheduled Microsoft Defender scan caught and quarantined the payload.

So the encryption never happened. But be honest about why: the payload failed for technical reasons the attacker didn’t anticipate. That’s luck. The data theft had already succeeded — and with crews like Akira, stolen data is its own extortion lever. “The files never got encrypted” and “the incident was harmless” are very different sentences.

What this incident actually teaches

The VPN account without MFA was the whole ballgame. Everything downstream — the reconnaissance, the Safe Mode trick, the data theft — was enabled by one credential with no second factor on an internet-facing system. This is the single most common serious finding in the assessments we run. Not exotic. Not expensive to fix. If you have any remote access into your network — VPN, remote desktop, remote-access software — every account on it needs MFA, with zero exceptions, including (especially) the old service and vendor accounts everyone forgot about.

EDR is a layer, not a force field. We’re strong advocates for endpoint detection and response, and this incident doesn’t change that — it clarifies it. EDR raises the cost and noise of an attack dramatically. It also runs on the same machine the attacker is trying to control, and attackers invest heavily in switching it off: Safe Mode reboots, vulnerable-driver tricks, straight uninstalls with stolen admin credentials. A security posture that amounts to “we bought good antivirus” fails exactly here. The tooling needs to be part of a stack: MFA at the entrances, EDR on the endpoints, and monitoring that notices the things a blinded agent can’t report.

Absence of signal is a signal. When a machine reboots into Safe Mode, or an EDR agent goes quiet mid-day, or a new remote-access tool appears in the environment, those events are the alarm. Detecting them requires someone — a monitored security operation, internal or outsourced — watching for machines that stop reporting, not just machines that report something bad. The incident responders’ own recommendations here were concrete: enforce MFA on all VPN accounts, watch for Safe Mode boot configuration changes, and track remote-access tools being added to the environment.

Exfiltration is the attack now. Ten minutes of blindness was enough to start moving data out. Even a fully successful backup and recovery posture — which you still need, and we’ve written about what that actually requires — doesn’t un-steal the client files, financials, and credentials that left the building. Prevention and early detection are the only controls that address the theft half of modern ransomware.

The Tuesday-morning checklist

Translate this incident into five questions for your business:

  1. Does every account on every remote-access path (VPN, RDP, remote-access tools) have MFA enforced? Who verified that, and when?
  2. Do we know every remote-access tool installed in our environment? Would we notice a new one appearing?
  3. Would anyone notice if a workstation or server rebooted into Safe Mode at 2 a.m.?
  4. If our endpoint protection went silent on one machine, does an alert fire, or does it just… go silent?
  5. If data were exfiltrated tonight, would we be able to tell what left?

If any answer is “I don’t know,” that’s not a criticism — it’s the to-do list. Most businesses we assess can’t answer all five on day one.

The bottom line

This attack was stopped by a crashed executable and a scheduled scan — not by the defenses that were supposed to stop it. The defense that would have actually prevented it costs almost nothing: MFA on a VPN account. The defenses that would have caught it in progress — monitoring for dead agents, Safe Mode reboots, and new remote-access tools — are exactly what separates a security stack from a security program.

If you want to know how your environment would have handled this specific playbook, book an intro call — qualifying businesses receive our $2,500 IT Risk Assessment complimentary. We’ll check the remote-access paths, the MFA coverage, the endpoint tooling, and the monitoring behind it, and give you the prioritized list of what to fix first.

William “BJ” Pote

CEO, eTop Technology

eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.

How Secure Is Your Business?

Most breaches start with gaps businesses don’t know they have. Book an intro call and we’ll identify vulnerabilities before attackers do.

Book an Intro Call →

Or call us directly: (951) 398-0021