How We Stopped an Akira Ransomware Attack and Got a Central Illinois Law Firm Back to Work the Next Day
A small Central Illinois law firm called Facet on a Monday morning. The symptoms they described were unremarkable: two computers wouldn't get online, a few programs wouldn't open, the rest of the office seemed fine. They thought it was a routine technical issue.
Within an hour of arriving on site, our technician identified files with the .akira extension and a ransom note in a user's local directory. The firm was in the middle of an active ransomware attack by the Akira ransomware group, exploiting a known vulnerability in their Cisco AnyConnect VPN.
Twenty-four hours later, the firm was operating again on a clean network. The malicious access was terminated. A temporary firewall was in place. The recovery was underway. The total cost of the response was covered by the firm's cyber liability insurance.
This is what ransomware response looks like when it's done right, including the parts most case studies skip.
The Threat: Akira Ransomware Targeting Cisco VPN Appliances
Understanding the threat actor matters because it explains how the attack succeeded and how response had to be structured.
Akira is a ransomware-as-a-service group first identified in March 2023. According to a 2024 U.S. Department of Health and Human Services analysis, the group has connections to the defunct Conti syndicate based on shared exploitation techniques and cryptocurrency infrastructure. Blockchain analysts have attributed approximately $244 million in ransom proceeds to Akira affiliates as of mid-2025.
Akira actively targets VPN infrastructure as the initial entry point, with a particular focus on Cisco ASA and AnyConnect SSL VPN appliances. CISA, Cisco's own security team, and independent researchers at Truesec have all confirmed that Akira affiliates exploit known Cisco vulnerabilities, particularly CVE-2020-3259, which allows attackers to extract usernames and passwords from device memory.
This particular law firm fit the target profile precisely. They had an aging Cisco ASA 5506 firewall providing AnyConnect SSL VPN access. They did not have multi-factor authentication on their VPN, which Cisco itself has identified in their official Akira analysis as the specific gap that enables these attacks.
What We Found On Site
Our technician arrived around 8:45 AM and began routine troubleshooting. None of the standard fixes worked. While examining the user's Chrome profile in the local AppData directory, the technician found files with the .akira extension and a readme file that turned out to be the ransom note.
At that moment, the routine IT call became an active incident response. The picture that emerged over the next several hours:
- The threat actors were inside the network and had accessed the file server
- Files were being encrypted across multiple systems with the .akira extension
- The Cisco ASA VPN appliance was the confirmed entry point (later validated by the insurance carrier's forensics consultant)
- The attackers had attempted to destroy the recovery path by formatting the partition on the firm's backup NAS and deleting the Veeam backups stored locally on the domain controller through the Veeam console (a known Akira tactic)
- Logs had been deleted before the date of compromise, making it difficult to piece together the full timeline of the intrusion
For a small law firm, this is the worst possible scenario: client files encrypted, internal backups destroyed, and the threat actor still potentially active in the network. Every minute of delay increases the spread of the attack and the difficulty of recovery.
How We Stopped It
The immediate priority was containment. The on-site technician escalated to the rest of our team, and within hours we had additional engineers working remotely alongside the technician on site.
1Terminate the Attack Vector
The Cisco ASA was the entry point, and as long as it stayed on the network, the threat actors could re-establish access. We provisioned a temporary FortiGate firewall from our inventory, deployed it on site, and removed the compromised ASA from the network. This single change cut off the attackers' ability to reach the environment.
2Deploy Detection and Response Tooling
Simultaneously, we deployed SentinelOne endpoint protection and Huntress managed detection and response across the firm's workstations and servers. These tools allowed us to identify any remaining malicious processes, scan for indicators of compromise, and begin continuous monitoring for any further activity.
3Lock Down Access
Active Directory user passwords were rotated. Accounts that the attackers had created or compromised were disabled. The file server was analyzed for any remaining persistence mechanisms.
4Coordinate with Forensics
Over the following days, we worked alongside a ransomware forensics consultant assigned by the firm's cyber liability insurance carrier. The forensics team confirmed the Cisco ASA as the attack vector and helped piece together the timeline. SentinelOne and Huntress monitoring continued throughout to confirm no malicious activity persisted.
By the end of the first day, the technician had been on site from 8:45 AM to 5 PM and the firm was no longer actively under attack.
The Recovery: What We Saved, and What We Couldn't
This is the part of the story most case studies skip, and the part that matters most.
The Akira attackers had specifically targeted the firm's backup infrastructure. The local NAS partition had been formatted. The Veeam backups on the domain controller had been deleted through the management console. Standard recovery tools could not extract data from the formatted NAS volume, suggesting the attackers had damaged the file system before formatting it.
What partial recovery was achieved came from creative work using sources the attackers hadn't reached. Our engineers copied VMDK files from servers to external hard drives and confirmed the copies completed cleanly over the weekend. The firm's primary practice share was successfully backed up to a separate external drive by Monday at noon. This off-network copy gave us a baseline to rebuild from.
Working in parallel with the forensics team, we documented affected directories and files, identified what had been encrypted versus what remained intact, and attempted recovery from every available source.
The firm's core operational data was successfully restored. Some files, however, were permanently lost.
This is the honest part of the story. The firm's pre-existing backup strategy had gaps that no incident response can fully close after the fact. Their post-incident backup design, deployed as part of the managed services relationship that followed, closed those gaps. But the data lost during the attack was lost.
What the Cyber Liability Insurance Covered
The total cost of the incident response was paid by the firm's cyber liability insurance policy. This included:
- The forensics consultant assigned by the carrier
- Facet's technical incident response and recovery work
- The temporary firewall hardware
- The replacement workstations for the most heavily affected machines
The firm had purchased a cyber liability policy years before the attack, almost as a precautionary box-check. When the attack happened, that policy covered the entire response. Without it, the firm would have faced a multi-tens-of-thousands-of-dollars bill for the same recovery work, on top of the operational impact of the incident itself.
"$5 million average ransomware cost."
The 2025 IBM Cost of a Data Breach Report puts the average ransomware incident at over $5 million in total cost. For a small business without cyber liability insurance, an attack like this becomes an existential threat. With proper coverage, it was a stressful week followed by a return to normal operations.
The Results
| Before the Incident | After Recovery |
|---|---|
| Cisco ASA 5506 firewall (aging, vulnerable to Akira exploitation) | FortiGate firewall with current security posture |
| VPN with no multi-factor authentication | Duo MFA deployed across all systems that support it |
| Local Veeam backups deletable from inside the network | Backup strategy designed to survive an active attack |
| Backup NAS reachable and destroyable by attackers | Off-network backup architecture as part of managed services |
| No managed endpoint detection | SentinelOne and Huntress on all systems |
| On-premises mail and authentication infrastructure | Microsoft 365 with Duo enforcement |
| Occasional break/fix IT support relationship | Full Facet managed services contract |
| Aging server infrastructure | Azure-based environment after migration project |
What Happened After the Recovery
This is the part of the story that matters most for businesses thinking about their own IT support.
The firm had previously engaged Facet only for occasional break/fix work. They were not under a managed services contract. They did not have proactive monitoring. They did not have managed endpoint protection. They did not have multi-factor authentication on their VPN.
After the recovery, the firm signed a managed services contract with Facet covering helpdesk, cybersecurity, backups, and ongoing monitoring. The decision was straightforward from their perspective: they had seen what happens without proper coverage, and they wanted the team that recovered them to handle their environment going forward.
Multi-factor authentication was deployed across all user accounts. Microsoft 365 was rolled out for email. Duo MFA was added to every system that supported it. The relationship deepened further when the firm engaged Facet for an Azure migration project, modernizing their server infrastructure as part of the post-incident cleanup.
What started as an emergency response call became a multi-year strategic partnership.
What This Project Tells You About Cybersecurity for Small Businesses
The technical lessons are straightforward. Aging firewall hardware that was never patched is a real risk. VPNs without multi-factor authentication are sitting targets for groups like Akira. Local-only backups can be destroyed by attackers who reach the management console. Cyber liability insurance is one of the most effective business investments a small organization can make.
The strategic lesson is more important. The firm in this case study was not negligent. They had IT support. Their firewall worked. Their backups ran. Their software was reasonably current. Their vulnerability was the gap between "we have IT" and "we have IT that is actively managing modern threats." That gap is where most small businesses are exposed, and it is where attacks like this consistently succeed.
The other lesson is about who you call when something goes wrong. The firm called Facet because they had used us occasionally for routine work and trusted us to be honest about what was happening. They had not bought a service package. They had bought a relationship. When the worst happened, that relationship was what they needed. Most ransomware victims spend the first hours of an attack trying to figure out who can help. The firms with established relationships start their recovery hours ahead.
Frequently Asked Questions
How long does it take to recover from a ransomware attack?
It depends on the attack, the size of the environment, the state of backups, and how quickly response begins. In this case, the law firm was operating on a clean network the day after the attack was identified. Core operational data was restored, though some files were permanently lost due to gaps in their pre-existing backup setup. Recoveries that take weeks or months are usually environments where backups were destroyed and no off-network copies existed, or where response was delayed by days while the attackers continued moving through the network.
What is the Akira ransomware group, and how do they get in?
Akira is a ransomware-as-a-service group active since 2023, responsible for hundreds of attacks globally and approximately $244 million in ransom proceeds as of mid-2025. According to CISA and Cisco's own security advisories, Akira affiliates frequently exploit vulnerabilities in Cisco ASA and AnyConnect SSL VPN appliances, particularly devices that lack multi-factor authentication or are running outdated firmware. Once they have credentials, they typically move laterally through the network, destroy backups, exfiltrate data, and then deploy ransomware.
Does cyber liability insurance actually cover ransomware response?
For policies with proper coverage, yes. In this case, the firm's cyber liability insurance covered the forensics consultant, the technical response work, replacement hardware, and the recovery effort. Coverage details vary substantially between policies, which is why businesses should review their cyber liability coverage before they need it, not during an incident.
Can a small business really be a ransomware target?
Yes, and small businesses are increasingly the primary target. Groups like Akira don't specifically choose small targets, but they scan continuously for vulnerable devices like unpatched Cisco ASAs. Any business with an exposed vulnerability can become a target regardless of size. Small businesses with limited IT support and aging infrastructure are often easier to breach than larger organizations with dedicated security teams.
What should I do right now if I think we might be vulnerable?
Three steps that meaningfully reduce risk: verify multi-factor authentication is required on every system that accesses business data including VPN access, verify that your backups exist somewhere the attackers cannot reach from inside your network, and have a current cyber liability insurance policy you have actually read. None of these are expensive. All of them dramatically change the math during an incident.
What's the difference between a ransomware response team and an ongoing IT provider?
A ransomware response is an emergency engagement focused on containing the active threat and recovering data. An ongoing IT provider handles the day-to-day work that prevents attacks from succeeding: monitoring, MFA, patching, backup verification, employee training, and security tooling. The same provider can often do both, but they are different services with different priorities. Businesses with an existing IT partnership start their recovery hours ahead of those who have to find a provider during the crisis.
Ready to Find Out Where Your Cybersecurity Actually Stands?
If your current IT provider hasn't given you an honest assessment of your security posture, or if you suspect your environment has gaps no one's told you about, we can help.
Facet Technologies has been providing IT services to Central Illinois businesses for over 30 years. We'll give you an honest picture of your environment, explain what needs attention and why, and build a plan that fits your budget and timeline.
Fill out the form on this page to request a consultation.
Not ready to talk yet?
Download our free guide: Beyond the Quote: 11 Questions You Must Ask Before Hiring a Managed IT Service Provider. It will help you evaluate any IT company, including your current one.
