Akira ransomware continues to use defense evasion tactics, such as rebooting victim hosts into Safe Mode with Networking to disable security tools. In one incident, this backfired and broke the ransomware, but the attacker still exfiltrated credentials and file shares.