AK

Akira Ransomware

Active

Threat actor group tracked in the global ransomware database · Last disclosure: Sep 4, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Manufacturing
1,438
Total Victims
6.7% of all tracked
67
Countries Targeted
20
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Akira and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Akira, a ransomware actor active since March 2023, has infected at least fourteen-hundred-and-fifteen victims across sixty-seven countries.

Who Akira is

The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group. It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others. According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware. The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast. Subsequently, a version was released that fixed the decryption fla

Recorded activity

Disclosures attributed to Akira in this database run from January 2024 to September 2026, totalling 1,438 victims — 6.7% of everything tracked here. Akira has listed victims in 67 countries in this database, most often United States, followed by Canada and Germany. The sectors appearing most in its listings are Manufacturing, Business Services, Construction.

How Akira is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference →
Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Windows Management Instrumentation T1047 Execution

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management

MITRE ATT&CK reference →
Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Akira across its recorded activity. They describe the group overall, not any single incident.

Vulnerabilities Akira is recorded exploiting

8 of these 8 are in the CISA Known Exploited Vulnerabilities catalog, 8 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Akira in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.

Tooling observed in Akira operations

  • DonPAPI
  • LaZagne
  • Mimikatz
  • PowerTool
  • ThrottleStop driver
  • Zemana Anti-Rootkit driver
  • Advanced IP Scanner
  • Advanced Port Scanner
  • Bloodhound
  • Masscan
  • ReconFTW
  • ShareFinder

Software reported in use by Akira. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Threat Actor Analysis

Akira is a ransomware threat group that has disclosed 1,438 victims in publicly accessible leak site data, representing 6.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Akira in our dataset dates to January 2024.

Geographically, Akira has targeted organisations in 67 countries. The most frequently targeted nation is United States with 867 victim organisations. Other heavily targeted nations include Canada, Germany, United Kingdom.

Industry-wise, Akira shows a concentration in the Manufacturing, Business Services, Construction sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Akira likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 1,438 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 1,438)

# Organization Country Sector Date
1 Stransky Heiz-Mess-Regeltechnik GmbH 🇩🇪 Germany Manufacturing Sep 4, 2026
2 Worrell Sep 4, 2026
3 Algra Group 🇳🇱 Netherlands Other Sep 2, 2026
4 PennFab Manufacturing Sep 2, 2026
5 ScrubaDub Auto Wash Centers 🇺🇸 United States Retail & E-Commerce Sep 2, 2026
6 BYK Construction bykconstruction.com 🇺🇸 United States Manufacturing Sep 1, 2026
7 Congressional Iron Works Manufacturing Sep 1, 2026
8 Flex1 Sep 1, 2026
9 Gale Credit Union galecu.net 🇺🇸 United States Financial Services Aug 31, 2026
10 KFZ-MEISTERBETRIEB JOST GmbH kfzjost.de 🇩🇪 Germany Transportation Aug 31, 2026
11 WEMS Other Aug 31, 2026
12 Alumax 🇺🇸 United States Manufacturing Aug 28, 2026
13 BEPeterson Aug 28, 2026
14 JRT Mechanical Manufacturing Aug 28, 2026
15 Cetylite cetylite.com 🇺🇸 United States Manufacturing Aug 27, 2026
16 CGP MEP cgpmep.com Other Aug 27, 2026
17 Seabrook Island seabrookisland.com 🇺🇸 United States Hospitality Aug 27, 2026
18 Gill Rock Drill gillrockdrill.com Manufacturing Aug 26, 2026
19 Oral and Maxillofacial Surgery Healthcare Aug 26, 2026
20 PA-ID Aug 26, 2026
21 Davis & Ferber davisferber.com Professional Services Aug 25, 2026
22 WINTER Ingenieure winter-ingenieure.de 🇩🇪 Germany Manufacturing Aug 25, 2026
23 Bihl 🇩🇪 Germany Other Aug 24, 2026
24 JC Sales jcsalesweb.com 🇺🇸 United States Retail & E-Commerce Aug 21, 2026
25 Cascade Coffee cascadecoffee.com 🇺🇸 United States Retail & E-Commerce Aug 20, 2026
26 Deas Millwork Manufacturing Aug 20, 2026
27 Ericksen Krentel ericksenkrentel.com Professional Services Aug 19, 2026
28 Borchert & LaSpina Aug 18, 2026
29 Cozad Asset Management cozadasset.com 🇺🇸 United States Financial Services Aug 14, 2026
30 Keystops keystops.com 🇺🇸 United States Technology Aug 14, 2026
31 CF Supply Retail & E-Commerce Aug 13, 2026
32 Alcast Manufacturing Aug 10, 2026
33 i4 Solutions Technology Aug 10, 2026
34 One Vision Imaging onevisionimaging.com Healthcare Aug 10, 2026
35 Basic Grain Products Agriculture and Food Production Aug 6, 2026
36 Pharma Test Apparatebau AG 🇨🇭 Switzerland Manufacturing Aug 6, 2026
37 University SprinklerSystems Manufacturing Aug 4, 2026
38 Albers Mechanical Contractors albersmechanicalcontractors.com 🇺🇸 United States Manufacturing Aug 3, 2026
39 Belasco Electric belascoelectric.com 🇺🇸 United States Energy & Utilities Aug 3, 2026
40 Northwood Country Club northwoodcountryclub.org 🇺🇸 United States Hospitality Jul 29, 2026
41 Franz Krause artworksgroup 🇺🇸 United States Other Jul 28, 2026
42 Emerge2 Digital emerge2.com 🇨🇦 Canada Technology Jul 24, 2026
43 Kruse Construction Construction Jul 22, 2026
44 University Sprinkler Systems 🇨🇦 Canada Business Services Jul 22, 2026
45 Finer & Finer Consumer Services Jul 21, 2026
46 Finer & Finer 🇺🇸 United States Consumer Services Jul 21, 2026
47 Novasport s.r.o. 🇨🇿 Czech Republic Consumer Services Jul 21, 2026
48 Novasport s.r.o. 🇨🇿 Czech Republic Consumer Services Jul 21, 2026
49 L&A Transport landatransport.com 🇺🇸 United States Transportation/Logistics Jul 20, 2026
50 L&A Transport landatransport.com 🇺🇸 United States Transportation/Logistics Jul 20, 2026
51 McKeever , Varga & Senko mvs-cpa.com 🇺🇸 United States Business Services Jul 20, 2026
52 McKeever , Varga & Senko mvs-cpa.com 🇺🇸 United States Business Services Jul 20, 2026
53 Nesco Bus Maintenance nescobus.com 🇺🇸 United States Transportation/Logistics Jul 17, 2026
54 Nesco Bus Maintenance nescobus.com 🇺🇸 United States Transportation/Logistics Jul 17, 2026
55 Westcoast Communication Services westcoastcomm.com 🇺🇸 United States Telecommunication Jul 17, 2026
56 Westcoast Communication Services westcoastcomm.com 🇺🇸 United States Telecommunication Jul 17, 2026
57 Plumley Engineering PlumleyEng.com 🇺🇸 United States Manufacturing Jul 16, 2026
58 Pioneer Construction Construction Jul 15, 2026
59 Ironmark ironmarkusa.com 🇺🇸 United States Business Services Jul 13, 2026
60 Transworld Signs transworldsigns.com 🇨🇦 Canada Business Services Jul 13, 2026
61 Vandalia Rental vandaliarental.com 🇺🇸 United States Consumer Services Jul 10, 2026
62 Wade's Dairy wadesdairy.com 🇬🇧 United Kingdom Agriculture and Food Production Jul 8, 2026
63 Chisholm Persson & Ball Business Services Jul 7, 2026
64 Excalibur Rentals Consumer Services Jul 7, 2026
65 RISE Architecture Business Services Jul 7, 2026
66 Stone Ridge Payments stoneridgepayments.com 🇺🇸 United States Financial Services Jul 7, 2026
67 Refinery Hotel Hospitality and Tourism Jul 1, 2026
68 About Todd Hamaker & Johnson Business Services Jun 30, 2026
69 Advanced Business Systems Business Services Jun 30, 2026
70 Precise Forms preciseforms.com 🇺🇸 United States Business Services Jun 26, 2026
71 JMS Southeast jms-se.com 🇺🇸 United States Business Services Jun 25, 2026
72 Padget Technologies padgettechnologies.com 🇺🇸 United States Technology Jun 25, 2026
73 Jit Ex Jun 24, 2026
74 Miami Machine 🇺🇸 United States Manufacturing Jun 24, 2026
75 IH Engineers ihengineers.com 🇺🇸 United States Manufacturing Jun 23, 2026
76 Leo International leointernational.com 🇺🇸 United States Jun 23, 2026
77 Ntd Apparel Consumer Services Jun 22, 2026
78 Apptricity 🇺🇸 United States Business Services Jun 18, 2026
79 Berg Lilly Jun 18, 2026
80 Smith Filter Manufacturing Jun 17, 2026
81 Insite Architects Business Services Jun 16, 2026
82 DDC Domus Design Collection Consumer Services Jun 12, 2026
83 Associated Investor Services Financial Services Jun 10, 2026
84 Port Air Express portairexpress.com Transportation/Logistics Jun 10, 2026
85 The Midland Theatre 🇬🇧 United Kingdom Hospitality and Tourism Jun 10, 2026
86 Centre Ellipse Jun 9, 2026
87 Rockaway River Country Club Hospitality and Tourism Jun 9, 2026
88 SMPC Architects Construction Jun 9, 2026
89 Spray Equipment & Service Center Business Services Jun 9, 2026
90 HRC Sicherheitsdienste 🇩🇪 Germany Business Services Jun 8, 2026
91 Kennon Worldwide kennon.com Business Services Jun 5, 2026
92 Oaks Park oakspark.com 🇺🇸 United States Consumer Services Jun 5, 2026
93 T/CCI Manufacturing Manufacturing Jun 5, 2026
94 National Standard Parts Associates Manufacturing Jun 4, 2026
95 Northern Ohio Regional Multiple Listing Service 🇺🇸 United States Business Services Jun 4, 2026
96 Cherokee Distributing Co 🇺🇸 United States Transportation/Logistics Jun 3, 2026
97 Factors Western Business Services Jun 3, 2026
98 Hal Otey Financial Financial Services Jun 3, 2026
99 Sunrise, Toscana Country Club, AndalusiaCountry Club. 🇪🇸 Spain Hospitality and Tourism Jun 3, 2026
100 Healthtrax Fitness &Wellness healthtrax.com 🇺🇸 United States Consumer Services May 29, 2026

Frequently Asked Questions

What is Akira ransomware?

Akira is a ransomware threat group that has claimed 1,438 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Akira attacked?

Akira has claimed 1,438 victims in our database, representing 6.7% of all tracked ransomware attacks. The most targeted countries are United States, Canada, Germany, United Kingdom.

Which countries does Akira target?

Akira has attacked organizations in 67 countries. The top targeted countries are: United States, Canada, Germany, United Kingdom.

Which industries does Akira target?

Akira most frequently targets the Manufacturing, Business Services, Construction sectors based on victim disclosures in our database.

Is Akira still active?

Akira's most recent victim disclosure in our database was on September 4, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.