Threats · 166 days ago
The Akira ransomware group now completes entire attacks in less than an hour by chaining exploitation of internet-facing VPN and backup appliances (SonicWall, Veeam, Cisco) with credential theft and initial access brokers. They use living-off-the-land tools like FileZilla and RClone for stealthy data exfiltration and encryption, often encrypting only 1% of files to speed impact. This rapid, disciplined tempo leaves almost no time for detection or manual response, invalidating standard incident playbooks.
Organizations with exposed VPN or backup appliances lacking MFA are at highest risk. Detection should focus on unusual use of legitimate tools and rapid exfiltration. Backup strategies must assume exfiltration can precede encryption and prioritize immutable, air-gapped copies. This is not a zero-day emergency but a critical operational shift demanding faster, automated defenses and hardened credential hygiene.
2 sources covering this story
Akira ransomware group can achieve initial access to data encryption in less than an hour
A new report from Halcyon finds that the group also puts more effort than usual into developing working decryptors, likely to incentivize businesses to pay up.
Researchers Observe Sub-One-Hour Ransomware Attacks
Halcyon says Akira is now capable of carrying out an entire ransomware attack in less than an hour
Part of the PlainSec briefing for 2026-04-03