TL;DR: Akira ransomware continues to evolve across VPN compromise, valid credential abuse, lateral movement, data exfiltration, and rapid double-extortion impact, according to SafeBreach’s coverage of CISA Alert AA24-109A, with some incidents exfiltrating data in just over two hours and proceeds estimated at $244.17 million by late September 2025. The lesson is clear: control validation now has to track attack paths, not just isolated indicators.
At a glance
What this is: This is SafeBreach’s analysis of the updated CISA Akira ransomware alert, highlighting newer TTPs, broader platform targeting, and the attack methods defenders need to validate.
Why it matters: It matters because Akira combines initial access, credential abuse, lateral movement, and exfiltration in ways that expose gaps across IAM, PAM, endpoint, and recovery controls.
By the numbers:
- As of late September 2025, it’s believed that Akira ransomware has claimed approximately $244.17 million in ransomware proceeds.
- In a June 2025 incident, Akira threat actors encrypted Nutanix AHV VM disk files for the first time, expanding their capabilities beyond VMware ESXi and Hyper-V by abusing CVE-2024-40766 and CWE-284: Improper Access Control.
👉 Read SafeBreach’s coverage of the updated CISA Akira ransomware alert
Context
Akira ransomware is a multi-stage intrusion pattern, not a single encryptor. The central governance problem is that organisations often validate one control at a time, while attackers combine weak VPN authentication, stolen credentials, remote tooling, discovery, exfiltration, and destructive encryption in one chain. That makes coverage breadth and control interdependence the real issue for identity and resilience teams.
For identity practitioners, the article is especially relevant where VPN access, credential hygiene, privileged accounts, and remote administration tools intersect. Akira repeatedly shows that standing access, exposed credentials, and weak segmentation can turn an initial foothold into domain-level compromise before defenders have time to respond.
Key questions
Q: What breaks when VPN access is exposed without MFA in ransomware scenarios?
A: Attackers can turn a single compromised or brute-forced VPN login into a trusted foothold, then escalate through credential theft, discovery, and lateral movement. Without MFA, the organisation loses one of the few controls that can stop legitimate-looking access before it becomes domain compromise. That is why VPN hardening, identity telemetry, and exposure monitoring must work together.
Q: Why do valid accounts make ransomware attacks harder to detect?
A: Valid accounts blend into normal access patterns, especially when they are purchased or stolen through initial access brokers. Once inside, attackers can use native tools and legitimate protocols, which reduces obvious malware signals and delays investigation. This is why IAM, PAM, and SOC teams need shared visibility into who accessed what, when, and from where.
Q: What do organisations get wrong about ransomware recovery?
A: Many organisations treat recovery as a storage or backup problem and underweight identity control. In practice, an attacker who still has active access can relock systems, delete backups, or trigger more encryption before restoration finishes. Recovery is only reliable when identity pathways are narrowed first.
Q: Who is accountable when ransomware operators move from access to extortion?
A: Accountability spans identity owners, infrastructure teams, endpoint defenders, and incident response leadership because the failure is usually cross-control. Frameworks such as NIST CSF and NIST SP 800-53 expect governance over access, monitoring, and recovery. If no team owns the full attack path, the attacker effectively does.
Technical breakdown
Initial access through VPNs, phishing, and valid credentials
Akira’s entry pattern is broad because initial access is often the easiest part of the chain. The group has used VPN services without MFA, exploited public vulnerabilities, abused RDP, and leveraged compromised credentials obtained through spraying or brokered access. That matters because once attackers authenticate legitimately, many perimeter controls treat them as trusted users. In practice, the difference between blocked and successful access is often whether authentication, exposure management, and login monitoring are tied together tightly enough to spot anomalous use before a session becomes persistent.
Practical implication: validate MFA coverage, exposed VPN endpoints, and credential-use telemetry together, not as separate hygiene checks.
Privilege escalation and discovery after the first foothold
After entry, Akira operators look for admin paths, stored credentials, and domain trust relationships. Techniques such as LSASS memory harvesting, Kerberoasting, Mimikatz, LaZagne, and creation of new admin accounts show a classic escalation model built around credential access and account manipulation. They also use discovery commands to map domain controllers, trusts, and connected systems, which helps them find high-value routes to broader impact. The technical lesson is that privilege escalation is often a governance failure as much as a tooling gap, because over-permissioned accounts shorten the attacker’s path from access to control.
Practical implication: harden privileged accounts, restrict account creation rights, and monitor discovery commands that map domain trust and admin reach.
Exfiltration, ransomware deployment, and recovery suppression
Akira’s impact phase combines data theft with encryption. The group uses common transfer tools and tunneling services to move data out quickly, then deploys ransomware across Windows and Linux or virtualised environments. The alert also notes deletion of volume shadow copies and abuse of legitimate remote tools, both of which reduce recovery options and make malicious activity blend into normal administration. That combination is important because defenders cannot assume ransomware is only about encryption anymore; the operational objective is to maximise leverage by stealing data first and disabling recovery second.
Practical implication: separate exfiltration detection from recovery-control monitoring so data theft and backup sabotage are visible before encryption completes.
Threat narrative
Attacker objective: The objective is to steal data, disable recovery, and extort payment while maximising damage across Windows, Linux, and virtualised systems.
- Entry occurs through vulnerable or non-MFA VPN access, exposed services, phishing, or compromised credentials that give the attacker a legitimate foothold.
- Escalation follows credential harvesting, account creation, discovery of trusts, and abuse of remote administration tools that expand access across the domain.
- Impact comes from rapid exfiltration, double-extortion ransomware deployment, and suppression of recovery mechanisms such as shadow copy deletion.
Breaches seen in the wild
- Cisco Active Directory credentials breach — Kraken ransomware group leaked Cisco Active Directory credentials.
- MongoBleed breach — MongoBleed exposed secrets across 87K MongoDB servers.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Akira reinforces the exposure-validation gap: organisations still tend to test isolated detections instead of the full attacker path. The article shows why that is insufficient. A VPN compromise, a stolen credential, or a remote tool abuse event only becomes decisive when it can be chained into privilege escalation, exfiltration, and encryption. Practitioners should treat attack-path validation as a control requirement, not a nice-to-have.
Standing access is the governance assumption Akira exploits most consistently: once a session or credential is accepted, the group rapidly turns that access into admin reach. That is a direct challenge to models that assume identity checks at login are enough. In NHI terms, the same pattern applies to service accounts, tokens, and remote access automation when their privilege scope outlives their intended use.
Privilege discovery has become a ransomware multiplier: Akira does not need exotic malware when common administrative tools, trust relationships, and weak account governance can expose the route to domain control. That shifts the security conversation from single-control hardening to privilege containment, segmentation, and telemetry correlation. Teams that cannot see trust relationships and admin activity together are operating with blind spots attackers can weaponise.
Recovery suppression is now part of the ransomware business model: deleting shadow copies, using legitimate remote tools, and blending with administrative activity are all designed to reduce response options. That means ransomware preparedness must include detection of backup tampering, not just malware execution. The practical conclusion is that resilience depends on proving recovery paths, not merely preserving them on paper.
Attack-path simulation should become a board-level resilience input: the article’s focus on new and existing coverage is a reminder that organisations need evidence that controls work across the chain, not just at the point of alerting. Exposure validation is most useful when it answers whether a real attacker can progress from entry to extortion under current policy and privilege conditions. Teams should use that evidence to prioritise the controls that actually shorten dwell time.
From our research:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- Forward pivot: Read NHI Lifecycle Management Guide for the provisioning, rotation, and offboarding controls that reduce standing access risk.
What this signals
Akira is a reminder that ransomware resilience is increasingly an identity governance problem as much as a malware problem. If exposed credentials, standing remote access, and over-privileged accounts remain in place, attacker dwell time compresses and response windows shrink. Teams should treat identity telemetry, privilege containment, and recovery validation as a single programme, not separate workstreams.
Exfiltration-to-encryption latency: the operational gap between first access and destructive impact is now short enough that detection needs to be chained to containment automatically. For practitioners, that means validating whether alerting on credential abuse, remote tool use, and backup tampering can trigger a coordinated response before encryption starts.
Where identity intersects with recovery, the practical question is whether access paths can be constrained fast enough to stop a valid session from becoming an extortion event. That is where controls such as least privilege, admin separation, and verification of recovery dependencies become decisive.
For practitioners
- Validate VPN and remote access exposure paths Test every externally reachable VPN, RDP, SSH, and remote admin path for MFA gaps, weak authentication, and known exploitable versions. Prioritise systems that can become the first authenticated foothold for ransomware operators.
- Harden privileged account creation and trust discovery Restrict who can create admin accounts, monitor net, nltest, LDAP, and similar discovery activity, and alert on trust-mapping behaviour that reveals escalation routes. These signals often appear before domain compromise.
- Correlate credential theft with lateral movement telemetry Link LSASS access, Mimikatz-style behaviour, remote PowerShell, WMI, RDP, and SMB execution into a single detection model so credential abuse cannot hide as ordinary administration.
- Test data exfiltration and recovery suppression together Simulate file transfer tools, tunnelling services, and shadow copy deletion in the same exercise to confirm whether exfiltration alerts fire before backup tampering disables restoration.
Key takeaways
- Akira’s updated tradecraft shows that ransomware is a cross-control identity and resilience problem, not just a malware event.
- The evidence points to short exfiltration windows, fast escalation, and expanding impact across virtualised and hybrid systems.
- Exposure validation, privilege containment, and recovery sabotage testing are the controls that most directly reduce Akira-style risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral Movement; TA0010 , Exfiltration; TA0040 , Impact | Akira uses the full attack chain from access through exfiltration and encryption. |
| NIST CSF 2.0 | PR.AC-4 | The article centers on access control failures and privilege abuse. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to limiting the escalation path Akira exploits. |
| CIS Controls v8 | CIS-5 , Account Management | Account governance and privileged account review are directly implicated. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Compromised non-human and remote access identities are part of the risk pattern. |
Tighten account lifecycle controls, especially admin creation, review, and deprovisioning across critical systems.
Key terms
- Attack-path validation: Attack-path validation is the practice of proving whether an attacker can move from one weakness to another until they reach meaningful impact. It goes beyond scanning by testing how exposures connect across identity, network, cloud, and application layers under realistic adversarial conditions.
- Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
- Recovery suppression: Recovery suppression is any action that reduces an organisation’s ability to restore systems after compromise, such as deleting shadow copies, tampering with backups, or disabling recovery services. It is often paired with encryption so the attacker increases pressure and shortens the defender’s response choices.
What's in the full article
SafeBreach's full coverage covers the operational detail this post intentionally leaves for the source:
- The full updated CISA alert mapping for Akira TTPs across initial access, privilege escalation, lateral movement, exfiltration, and encryption.
- The complete SafeBreach attack coverage list, including IOC-based and behavioural simulations for Windows, Linux, and virtualised environments.
- Specific playbook identifiers for validating exposure against the newer Akira, Megazord, and Akira_v2 variants.
- Guidance on how SafeBreach customers can run the alert scenario from the homepage, scenario page, or Known Threats Series report.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It helps practitioners connect identity controls to the broader security programme they operate every day.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org