A single lapse in multi-factor authentication allowed a basic credential spray to escalate into a nearly complete Akira ransomware breach in early August 2026. This incident highlights how an exposed VPN can quickly become the starting point for domain-wide reconnaissance, data theft, evasion of defenses, and ransomware deployment. Akira remains one of the most active ransomware operations, with affiliates repeatedly exploiting weakly protected VPN services that lack MFA.

Their typical approach involves obtaining valid remote-access credentials, moving through the Windows domain, stealing data, and encrypting systems. This was a credential spray attack: attackers tried a limited set of passwords across numerous usernames to avoid lockouts and detection. Two files were created in C:\ProgramData\—AdUsers.txt for user exports and AdComp.txt for computer exports.

The detailed account information included group memberships, password-change times, logon history, job titles, email addresses, phone numbers, and mailbox-related fields. They subsequently sent staged data to an attacker-controlled S3 bucket via s5cmd, employing a double extortion tactic: the group can threaten to leak stolen data even if the victim restores encrypted systems from backups. Indicators of Compromise - **IOC / Artifact Type Description** - **72.23.77[.

]35** IP address - External source IP linked to a successful SonicWall SSL VPN login - **WIN-DNCVG09TAT8** Hostn - Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.