Ransomware group profile · #3 by claimed victims
Akira ransomwarealso Megazord
High-volume operation that grew primarily by exploiting VPN appliances where multi-factor authentication was not enforced. Technically unremarkable and commercially very effective.
Victimology
Who Akira claims to have breached, from 1,618 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Manders | — | — | 16 Sep 2026 |
| Blossomland Accounting | — | — | 16 Sep 2026 |
| Bee Maid Honey | — | — | 16 Sep 2026 |
| Southern California Telephone Company | — | — | 15 Sep 2026 |
| Lazyboyz | — | — | 15 Sep 2026 |
| Pilot Precision | — | — | 15 Sep 2026 |
| Pilot Precision | Manufacturing | — | 15 Sep 2026 |
| Lazyboyz lazyboyz.no | Other | — | 15 Sep 2026 |
| Southern California Telephone Company | Energy & Utilities | US | 15 Sep 2026 |
| AK Stamping | — | — | 10 Sep 2026 |
| Eagle Construction | — | — | 10 Sep 2026 |
| George Cameron Nash | — | — | 10 Sep 2026 |
All 1,618 Akira victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
6 MITRE ATT&CK techniques mapped to Akira from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1078 Valid Accounts | Valid accounts obtained from brokers and infostealer logs. | Confirmed |
| Initial Access | T1133 External Remote Services | Cisco VPN appliances reached with valid credentials where MFA was absent, including exploitation of CVE-2023-20269. | Confirmed |
| Credential Access | T1003.001 LSASS Memory | Credential dumping to broaden access. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | Rclone, FileZilla and WinSCP to move stolen data out. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | ChaCha20 encryption, with a Rust build named Megazord aimed at ESXi datastores. | Confirmed |
| Defense Evasion | T1562.001 Disable or Modify Tools | PowerTool and similar utilities to terminate endpoint protection. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Akira intrusion unfolds, section by section.
Initial access
One missing control, at scale — The overwhelming majority of Akira intrusions begin at a VPN account without a second factor. There is no clever tradecraft to emulate here, which is precisely the point: the control that stops them is unglamorous and fr…
Frequently asked
Is Akira ransomware still active?
How many victims has Akira claimed?
Which industries does Akira target?
Which countries are most affected by Akira?
Where does VULONE get Akira victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| #StopRansomware: Akira Ransomware (AA24-109A) | CISA / FBI / Europol / NCSC-NL | 18 Apr 2024 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].