← All ransomware groups
Akira logo

Ransomware group profile · #3 by claimed victims

Akira ransomwarealso Megazord

High-volume operation that grew primarily by exploiting VPN appliances where multi-factor authentication was not enforced. Technically unremarkable and commercially very effective.

Active Russia First seen Mar 2023 ATT&CK G1024 ChaCha20 with RSA wrapped key; Rust variant (Megazord) targets ESXi Russian
1,618Victims claimed on leak sites
51Victims in the last 30 days
94Victims in the last 90 days
71Countries hit
2Leak-site URLs tracked, 0 online
16 Sep 2026Latest claim recorded

Victimology

Who Akira claims to have breached, from 1,618 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 71OctNov 2025: 87Dec 2025: 71Jan 2026: 58JanFeb 2026: 47Mar 2026: 75Apr 2026: 49AprMay 2026: 43Jun 2026: 32Jul 2026: 22JulAug 2026: 31Sep 2026: 31

Top sectors

Manufacturing444
Professional Services370
Technology156
Retail & E-Commerce116
Financial Services103
Agriculture and Food Production90
Transportation76
Healthcare58

Top countries

United States871
Canada81
Germany73
United Kingdom43
Italy34
Switzerland27
Spain22
Australia21

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Manders 16 Sep 2026
Blossomland Accounting 16 Sep 2026
Bee Maid Honey 16 Sep 2026
Southern California Telephone Company 15 Sep 2026
Lazyboyz 15 Sep 2026
Pilot Precision 15 Sep 2026
Pilot Precision Manufacturing 15 Sep 2026
Lazyboyz lazyboyz.no Other 15 Sep 2026
Southern California Telephone Company Energy & Utilities US 15 Sep 2026
AK Stamping 10 Sep 2026
Eagle Construction 10 Sep 2026
George Cameron Nash 10 Sep 2026

All 1,618 Akira victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

6 MITRE ATT&CK techniques mapped to Akira from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1078 Valid Accounts Valid accounts obtained from brokers and infostealer logs. Confirmed
Initial Access T1133 External Remote Services Cisco VPN appliances reached with valid credentials where MFA was absent, including exploitation of CVE-2023-20269. Confirmed
Credential Access T1003.001 LSASS Memory Credential dumping to broaden access. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage Rclone, FileZilla and WinSCP to move stolen data out. Confirmed
Impact T1486 Data Encrypted for Impact ChaCha20 encryption, with a Rust build named Megazord aimed at ESXi datastores. Confirmed
Defense Evasion T1562.001 Disable or Modify Tools PowerTool and similar utilities to terminate endpoint protection. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Akira intrusion unfolds, section by section.

Initial access

One missing control, at scale — The overwhelming majority of Akira intrusions begin at a VPN account without a second factor. There is no clever tradecraft to emulate here, which is precisely the point: the control that stops them is unglamorous and fr…

Frequently asked

Is Akira ransomware still active?
Akira is tracked as active. The most recent leak-site claim VULONE recorded is dated 16 September 2026. 51 victims were claimed in the last 30 days.
How many victims has Akira claimed?
VULONE has recorded 1,618 leak-site victim claims attributed to Akira since April 2023, across 71 countries and 14 sectors.
Which industries does Akira target?
The sectors most often named on the Akira leak site are Manufacturing, Professional Services, Technology.
Which countries are most affected by Akira?
Most Akira victims recorded by VULONE are located in United States, Canada, Germany.
Where does VULONE get Akira victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
#StopRansomware: Akira Ransomware (AA24-109A)CISA / FBI / Europol / NCSC-NL18 Apr 2024

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].