Case Study
International nonprofit restores encrypted VMs
In a 2024 ransomware attack by the Akira group, an IT manager discovered encrypted VMs and a ransom note during a summer weekend. The organization quickly engaged Cohesity’s Cyber Event Response Team (CERT) on day two. The firewall had already auto-disabled ports to limit damage, and the IT team unplugged the network to prevent further spread. While rebuilding servers, CERT worked to contain the attack, identify initial access techniques, and evict the threat. Greg Tucker of Cohesity emphasizes that once the threat is removed, data recovery becomes a straightforward process.