Emergency, call now

Case Study · Incident Response

The police call: "Your data is with Akira. In seven days everything gets encrypted."

A car dealership, around 1,000 systems, our quote on the table. One day later the call from the state criminal police. How we built a security operations center in five days, threw Akira out of the network and kept the business running.

1 day

until the critical systems were monitored

5 days

until 1,000 systems were onboarded

5 minutes

to check all Akira IOCs across the whole fleet

0

incidents since

Starting point

The company is a car dealership with around 1,000 systems: servers, customer databases, dealer management system, laptops across several sites. Its own IT, but no security team. We do not name the company at the customer's request, as is customary in cybersecurity. The facts have been agreed with the customer.

We were already in talks. The dealership was interested in Spectacles, a quote was on the table. One day later the customer's phone rang: the state criminal police. The message was unambiguous. The company's data had already ended up with Akira, a Russian-speaking ransomware group. Without immediate action, the entire company would be encrypted within the next seven days.

Akira is one of the most active ransomware groups of recent years. The approach is well known: access via weak remote access or stolen credentials, then days of movement through the network, exfiltration of data, finally encryption. The exfiltration had already happened. Encryption was imminent. The dealership called us.

Timeline

  1. Day 0

    The call and the decision

    The dealership asks whether we can help. Our answer: yes, we roll out our platform immediately and take emergency measures in parallel. No preliminary project, no scoping workshop, straight to work.

  2. Day 1

    Protect the vital organs

    Spectacles is connected to all important servers, starting with what keeps the business alive: customer databases and the dealer management system. In parallel, containment: every visible SSH connection reviewed, firewalls checked for compromise, all VPN access locked. By the end of day one the critical systems are monitored and protected.

  3. Day 2 – 3

    All remaining servers

    The rest of the server landscape is onboarded. With every system the picture gets sharper: where the attacker was, which accounts they used, which systems they touched.

  4. Day 4 – 5

    All laptops, a working SOC

    After five days around 1,000 systems are onboarded, including every laptop. Out of nothing there is a security operations center capable of full forensics and threat hunting across the entire infrastructure.

  5. Ongoing

    Akira IOCs checked in five minutes

    All known Akira indicators, the traces that reveal an infection with Akira's ransomware, are checked across the whole fleet. Time taken: five minutes. When the police later supply extended indicators, those too are matched across all 1,000 systems within minutes. Akira is thrown out of the network, the encryption never happens.

  6. Since then

    Regular operation

    Spectacles has been running on the entire infrastructure ever since, and Goldoak protects the dealership permanently. To this day there has not been a single further incident.

What was at stake

Had the encryption gone through, the dealership would realistically have been unable to work for four to twelve weeks. No sales, no orders, no workshop jobs. At today's lead times and prices, the entire hardware would have had to be replaced, every server, every laptop. Together with the downtime, the damage sits in the high six-figure to nearly seven-figure range. For a dealership that is not a dent, it is the business.

What made the difference

Speed

A classic SIEM project takes months. Here the critical systems were protected after one day and 1,000 systems onboarded after five, because the agent is lightweight and the platform runs without a preliminary project.

Order

First what keeps the business alive: customer data and the dealer management system. Then the rest. Whoever wants everything at once during a live attack ends up protecting nothing in time.

Seeing instead of guessing

With the police's indicators we could say within minutes which systems were affected and which were not. Decisions were made on data, not on fear.

One team for everything

Containment, rollout, forensics, threat hunting and hardening from a single source. No switching between vendors mid-incident, no coordination loops while the clock is ticking.

What you can take from this

  • The first indication often comes from outside, here from the police. Make sure you can verify it before it arrives.
  • Without central visibility into your systems, every incident response is guesswork. Visibility is the prerequisite for everything else.
  • Remote access and VPN are the entry points. They must be monitored and lockable within minutes in an emergency.
  • A rollout in days is possible. Do not wait for the perfect project when the clock is ticking.
  • Whoever keeps the platform after the incident sees the return attempt. Most groups come back.

The questions every managing director asks at this point

We hear them in almost every conversation. Here are the answers, as honestly as the case allows.

Am I even a target?

Yes. A car dealership is not a corporation and was not a prominent name to anyone. Groups like Akira do not look for known names, they look for reachable remote access and stolen credentials, automated and at scale. An SME with 50 or 1,000 systems is not too small a target, it is a convenient one: enough to lose to pay up, and rarely anyone watching.

What would an attack actually cost me?

In this case: four to twelve weeks of standstill, replacement of every server and laptop, no sales and no orders during that time. Together a loss in the high six-figure to nearly seven-figure range, plus exfiltrated customer data with notification duties and awkward conversations with customers and insurers. And as managing director you are personally liable if appropriate protective measures are missing. The cost of the defence was a fraction of that.

Do I need my own IT staff or security expertise?

No. The dealership had its own IT, but no security team. Goldoak ran the rollout, executed containment, did the forensics and took over operations. Spectacles is built so that an IT lead or your external IT partner can run it on the side. For the emergency, our incident response team is there.

How much effort is the rollout, and does it disrupt operations?

Here the rollout happened in the middle of an active attack, across 1,000 systems, in five days, while the dealership kept selling cars. The agent is deployed via software distribution, cloud sources are connected without an agent. In the normal case, without an attacker in the network, most customers are live within a day.

What happens in an emergency? Who calls me, who acts, what do I have to do?

Spectacles detects the anomaly and isolates affected systems automatically or at the push of a button. In a serious incident a Goldoak senior analyst contacts the person you named, takes over containment and tells you what to do next. Your job: be reachable and make decisions, for which we deliver the facts. If you are not a customer yet, reach us via the emergency hotline.

Does it work with what I already have?

Yes. Microsoft 365, home office laptops, cloud tools, firewalls, VPN and an existing antivirus or EDR are connected as data sources, not replaced. Remote access and logins are exactly where attacks like this one begin, and that is exactly where Spectacles looks.

What does it cost, and why is that cheaper than the risk?

Spectacles costs CHF 8.50 per system per month plus dedicated hardware from CHF 25 per month, configurable online without a sales call. For a company with 100 systems that is under CHF 1,000 a month. A single day of standstill costs most businesses more, and here weeks were at stake. All details on the Spectacles page.

Who else uses it?

SMEs like this dealership, supported from Emmenbrücke near Lucerne. Spectacles is certified with the Swiss Made Software and Swiss Digital Services labels and won the *zünder Award in 2025. We do not name names for the same reason this case is anonymised: security customers do not want to be known as such. In a demo we show you the platform the way it runs there.

Affected right now?

Call our emergency hotline, around the clock. Disconnect affected systems from the network, do not power them off.

Not affected, but unsure whether you would see it?

See how Spectacles makes an attack like this visible. No sales pitch, no obligation.