One Missing MFA Control Lets Credential Spray Become Full Akira Ransomware Intrusion
Brief
A single missing multi-factor authentication (MFA) control turned a basic credential-spraying attempt into a near-complete Akira ransomware intrusion in early August 2026.
The incident shows how quickly an exposed VPN can become the starting point for domain-wide reconnaissance, data theft, defence evasion, and ransomware deployment.
Akira remains one of the most active ransomware operations, with affiliates repeatedly abusing VPN services that lack MFA.
Their common playbook is direct: obtain valid remote-access credentials, move through the Windows domain, steal data, and encrypt systems.
Akira operators have also been widely observed using valid VPN accounts, Active Directory discovery, RDP, remote-management tools, and archive utilities during intrusions.sophos+1
Missing MFA Enables Akira
The intrusion began at approximately 03:45 UTC on August 4.
