Acronis stops it at step 1.Every layer below is a new chance to stop the attack.
Monday morning · 08:47
Are you ready for this call?
This is what it sounds like when Akira has just hit your largest customer.
It's 08:50 AM. Akira has already been in the network for 11 days.
The question is not if the call will come - but if you are prepared when it does.
Who is the attacker
Meet Akira
Active global threat
$0M
Extorting companies since 2023
+ $0 just i denna session
Average ransom~ $1.5M
SourceFBI · CISA
One of the world's most profitable ransomware groups right now.
#0
World #2 by 2026
TrendFrom #4 (2024)
TargetMid-market & enterprise
Rapidly growing. Targets mid-sized and large enterprises.
< 0h
Time to data theft
Median53 minutes
Fastest confirmed19 minutes
Akira often manages to steal data before your security team has even reacted.
Akira is not just a hacking group - it's an entire organization. Technicians, salespeople, and negotiators work in parallel. To stop them, you need coverage at all levels.
01Break-in
How the attacker gets their first key.
1
A fake Microsoft login tricks the user into giving up their password.
2
With the account, the attacker accesses Microsoft 365 and your shared spaces.
3
Malicious files are placed in SharePoint - they appear internal.
4
Colleagues click and give up their passwords. The attacker gains broader access.
Inbox
Microsoft Security09:14
Verify your password - account locked
We detected suspicious activity. Click here to unlock your Microsoft 365 account within 24 hours...
sender: security-microsoft@mail-verify-365.cn
Blocked
Email & Collaboration Security stops the email before it reaches the inbox.
MITRE ATT&CKT1562.001Disable or Modify ToolsT1068Privilege EscalationT1070.001Indicator RemovalT1078Valid Accounts
Protection falls
Alarms are off. The attacker works undisturbed for hours.
Alarms last night
Lör 02:14:07
- No security analyst on site.
An alarm without anyone listening is worthless. What makes a difference is that the alarm cannot be turned off - and that someone actually responds.
"Akira affiliates have been observed disabling endpoint detection tooling within minutes of initial access, often during weekends and overnight hours."
- FBI · CISA Joint Advisory, 2024
04Stealing the data
The real weapon.
rclone exfil → mega.io
PID 4127
0.00 TB/ 2.30 TB
Speed
310 MB/s
Files
0
ETA
00:09
Live file feed
Potential GDPR fine (4% of revenue)
€ 2 847 000
The clock starts ticking the moment data leaves the network.
Goal
Everything of value
Personal data
Contracts
Source code
Financial data
Everything that can be used to pressure you into paying.
Business model
Double extortion
~ 70%
Pays
$1,5M
Average ransom
Two invoices per attack: one to unlock files, one not to leak them.
Channels
Common cloud services
Mega.ioRcloneFileZillaWinSCPMASSCAN
Data is smuggled out via services you already trust. The firewall sees nothing unusual.
Stolen data is the real threat today. Backup saves operations - but not leaks. Once data is out, the GDPR clock starts ticking.
How to stop the attacker in the middle of the attack.
One console. One agent
A single console and one agent per computer. You see everything in one place.
Stopping processes
Immediately stop suspicious programs and unauthorized connections.
Isolating machines
Cut the attacker's connections and remove affected machines from the network - with one click.
Without a unified platform you're chasing the attacker blindly, across hundreds of computers, with different tools. When every second counts, scattered systems are the attacker's best friend.
Acronis XDR + RMM combined
Auto-plays
Detection
0:02s
Assessment
0:30s
Isolation
1:10s
Restored
08:00
07Back in operation
From backup to operation in minutes.
Loss right now - without recovery environment
€ 12 847
Operations are at a standstill. Every second of downtime costs wages, missed orders, SLA fines, and lost trust.
With Acronis Disaster Recovery
€ 1 240
The recovery environment starts within minutes. The bleeding is stopped before customers even notice.