Akira Ransomware
ActiveThreat actor group tracked in the global ransomware database · Last disclosure: Sep 4, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Akira and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Akira, a ransomware actor active since March 2023, has infected at least fourteen-hundred-and-fifteen victims across sixty-seven countries.
Who Akira is
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group. It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others. According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware. The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast. Subsequently, a version was released that fixed the decryption fla
Recorded activity
Disclosures attributed to Akira in this database run from January 2024 to September 2026, totalling 1,438 victims — 6.7% of everything tracked here. Akira has listed victims in 67 countries in this database, most often United States, followed by Canada and Germany. The sectors appearing most in its listings are Manufacturing, Business Services, Construction.
How Akira is documented to operate
Valid Accounts T1078 Stealth Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →External Remote Services T1133 Persistence Initial Access
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.
Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program
MITRE ATT&CK reference →Exploit Public-Facing Application T1190 Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →Windows Management Instrumentation T1047 Execution
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
Mitigations: Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management
MITRE ATT&CK reference →Command and Scripting Interpreter T1059 Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Akira across its recorded activity. They describe the group overall, not any single incident.
Vulnerabilities Akira is recorded exploiting
- CVE-2022-40684 — Fortinet FortiOS (CRITICAL 9.8) · CISA KEV (patch due 1 Nov 2022)
- CVE-2023-48788 — Fortinet FortiClient (CRITICAL 9.8) · CISA KEV (patch due 15 Apr 2024)
- CVE-2024-40766 — SonicWall SonicOS SSL-VPN (CRITICAL 9.8) · CISA KEV (patch due 30 Sep 2024)
- CVE-2024-40711 — Veeam Backup & Replication (CRITICAL 9.8) · CISA KEV (patch due 7 Nov 2024)
- CVE-2021-21972 — VMware vSphere Client (CRITICAL 9.8) · CISA KEV (patch due 17 Nov 2021)
- CVE-2020-3259 — Cisco ASA & FTD (HIGH 7.5) · CISA KEV (patch due 7 Mar 2024)
- CVE-2023-27532 — Veeam Backup & Replication (HIGH 7.5) · CISA KEV (patch due 12 Sep 2023)
- CVE-2019-6693 — Fortinet FortiOS (MEDIUM 6.5) · CISA KEV (patch due 16 Jul 2025)
8 of these 8 are in the CISA Known Exploited Vulnerabilities catalog, 8 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Akira in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.
Tooling observed in Akira operations
- DonPAPI
- LaZagne
- Mimikatz
- PowerTool
- ThrottleStop driver
- Zemana Anti-Rootkit driver
- Advanced IP Scanner
- Advanced Port Scanner
- Bloodhound
- Masscan
- ReconFTW
- ShareFinder
Software reported in use by Akira. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Threat Actor Analysis
Akira is a ransomware threat group that has disclosed 1,438 victims in publicly accessible leak site data, representing 6.7% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Akira in our dataset dates to January 2024.
Geographically, Akira has targeted organisations in 67 countries. The most frequently targeted nation is United States with 867 victim organisations. Other heavily targeted nations include Canada, Germany, United Kingdom.
Industry-wise, Akira shows a concentration in the Manufacturing, Business Services, Construction sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Akira likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 1,438 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 1,438)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Stransky Heiz-Mess-Regeltechnik GmbH | 🇩🇪 Germany | Manufacturing | Sep 4, 2026 |
| 2 | Worrell | — | — | Sep 4, 2026 |
| 3 | Algra Group | 🇳🇱 Netherlands | Other | Sep 2, 2026 |
| 4 | PennFab | — | Manufacturing | Sep 2, 2026 |
| 5 | ScrubaDub Auto Wash Centers | 🇺🇸 United States | Retail & E-Commerce | Sep 2, 2026 |
| 6 | BYK Construction bykconstruction.com | 🇺🇸 United States | Manufacturing | Sep 1, 2026 |
| 7 | Congressional Iron Works | — | Manufacturing | Sep 1, 2026 |
| 8 | Flex1 | — | — | Sep 1, 2026 |
| 9 | Gale Credit Union galecu.net | 🇺🇸 United States | Financial Services | Aug 31, 2026 |
| 10 | KFZ-MEISTERBETRIEB JOST GmbH kfzjost.de | 🇩🇪 Germany | Transportation | Aug 31, 2026 |
| 11 | WEMS | — | Other | Aug 31, 2026 |
| 12 | Alumax | 🇺🇸 United States | Manufacturing | Aug 28, 2026 |
| 13 | BEPeterson | — | — | Aug 28, 2026 |
| 14 | JRT Mechanical | — | Manufacturing | Aug 28, 2026 |
| 15 | Cetylite cetylite.com | 🇺🇸 United States | Manufacturing | Aug 27, 2026 |
| 16 | CGP MEP cgpmep.com | — | Other | Aug 27, 2026 |
| 17 | Seabrook Island seabrookisland.com | 🇺🇸 United States | Hospitality | Aug 27, 2026 |
| 18 | Gill Rock Drill gillrockdrill.com | — | Manufacturing | Aug 26, 2026 |
| 19 | Oral and Maxillofacial Surgery | — | Healthcare | Aug 26, 2026 |
| 20 | PA-ID | — | — | Aug 26, 2026 |
| 21 | Davis & Ferber davisferber.com | — | Professional Services | Aug 25, 2026 |
| 22 | WINTER Ingenieure winter-ingenieure.de | 🇩🇪 Germany | Manufacturing | Aug 25, 2026 |
| 23 | Bihl | 🇩🇪 Germany | Other | Aug 24, 2026 |
| 24 | JC Sales jcsalesweb.com | 🇺🇸 United States | Retail & E-Commerce | Aug 21, 2026 |
| 25 | Cascade Coffee cascadecoffee.com | 🇺🇸 United States | Retail & E-Commerce | Aug 20, 2026 |
| 26 | Deas Millwork | — | Manufacturing | Aug 20, 2026 |
| 27 | Ericksen Krentel ericksenkrentel.com | — | Professional Services | Aug 19, 2026 |
| 28 | Borchert & LaSpina | — | — | Aug 18, 2026 |
| 29 | Cozad Asset Management cozadasset.com | 🇺🇸 United States | Financial Services | Aug 14, 2026 |
| 30 | Keystops keystops.com | 🇺🇸 United States | Technology | Aug 14, 2026 |
| 31 | CF Supply | — | Retail & E-Commerce | Aug 13, 2026 |
| 32 | Alcast | — | Manufacturing | Aug 10, 2026 |
| 33 | i4 Solutions | — | Technology | Aug 10, 2026 |
| 34 | One Vision Imaging onevisionimaging.com | — | Healthcare | Aug 10, 2026 |
| 35 | Basic Grain Products | — | Agriculture and Food Production | Aug 6, 2026 |
| 36 | Pharma Test Apparatebau AG | 🇨🇭 Switzerland | Manufacturing | Aug 6, 2026 |
| 37 | University SprinklerSystems | — | Manufacturing | Aug 4, 2026 |
| 38 | Albers Mechanical Contractors albersmechanicalcontractors.com | 🇺🇸 United States | Manufacturing | Aug 3, 2026 |
| 39 | Belasco Electric belascoelectric.com | 🇺🇸 United States | Energy & Utilities | Aug 3, 2026 |
| 40 | Northwood Country Club northwoodcountryclub.org | 🇺🇸 United States | Hospitality | Jul 29, 2026 |
| 41 | Franz Krause artworksgroup | 🇺🇸 United States | Other | Jul 28, 2026 |
| 42 | Emerge2 Digital emerge2.com | 🇨🇦 Canada | Technology | Jul 24, 2026 |
| 43 | Kruse Construction | — | Construction | Jul 22, 2026 |
| 44 | University Sprinkler Systems | 🇨🇦 Canada | Business Services | Jul 22, 2026 |
| 45 | Finer & Finer | — | Consumer Services | Jul 21, 2026 |
| 46 | Finer & Finer | 🇺🇸 United States | Consumer Services | Jul 21, 2026 |
| 47 | Novasport s.r.o. | 🇨🇿 Czech Republic | Consumer Services | Jul 21, 2026 |
| 48 | Novasport s.r.o. | 🇨🇿 Czech Republic | Consumer Services | Jul 21, 2026 |
| 49 | L&A Transport landatransport.com | 🇺🇸 United States | Transportation/Logistics | Jul 20, 2026 |
| 50 | L&A Transport landatransport.com | 🇺🇸 United States | Transportation/Logistics | Jul 20, 2026 |
| 51 | McKeever , Varga & Senko mvs-cpa.com | 🇺🇸 United States | Business Services | Jul 20, 2026 |
| 52 | McKeever , Varga & Senko mvs-cpa.com | 🇺🇸 United States | Business Services | Jul 20, 2026 |
| 53 | Nesco Bus Maintenance nescobus.com | 🇺🇸 United States | Transportation/Logistics | Jul 17, 2026 |
| 54 | Nesco Bus Maintenance nescobus.com | 🇺🇸 United States | Transportation/Logistics | Jul 17, 2026 |
| 55 | Westcoast Communication Services westcoastcomm.com | 🇺🇸 United States | Telecommunication | Jul 17, 2026 |
| 56 | Westcoast Communication Services westcoastcomm.com | 🇺🇸 United States | Telecommunication | Jul 17, 2026 |
| 57 | Plumley Engineering PlumleyEng.com | 🇺🇸 United States | Manufacturing | Jul 16, 2026 |
| 58 | Pioneer Construction | — | Construction | Jul 15, 2026 |
| 59 | Ironmark ironmarkusa.com | 🇺🇸 United States | Business Services | Jul 13, 2026 |
| 60 | Transworld Signs transworldsigns.com | 🇨🇦 Canada | Business Services | Jul 13, 2026 |
| 61 | Vandalia Rental vandaliarental.com | 🇺🇸 United States | Consumer Services | Jul 10, 2026 |
| 62 | Wade's Dairy wadesdairy.com | 🇬🇧 United Kingdom | Agriculture and Food Production | Jul 8, 2026 |
| 63 | Chisholm Persson & Ball | — | Business Services | Jul 7, 2026 |
| 64 | Excalibur Rentals | — | Consumer Services | Jul 7, 2026 |
| 65 | RISE Architecture | — | Business Services | Jul 7, 2026 |
| 66 | Stone Ridge Payments stoneridgepayments.com | 🇺🇸 United States | Financial Services | Jul 7, 2026 |
| 67 | Refinery Hotel | — | Hospitality and Tourism | Jul 1, 2026 |
| 68 | About Todd Hamaker & Johnson | — | Business Services | Jun 30, 2026 |
| 69 | Advanced Business Systems | — | Business Services | Jun 30, 2026 |
| 70 | Precise Forms preciseforms.com | 🇺🇸 United States | Business Services | Jun 26, 2026 |
| 71 | JMS Southeast jms-se.com | 🇺🇸 United States | Business Services | Jun 25, 2026 |
| 72 | Padget Technologies padgettechnologies.com | 🇺🇸 United States | Technology | Jun 25, 2026 |
| 73 | Jit Ex | — | — | Jun 24, 2026 |
| 74 | Miami Machine | 🇺🇸 United States | Manufacturing | Jun 24, 2026 |
| 75 | IH Engineers ihengineers.com | 🇺🇸 United States | Manufacturing | Jun 23, 2026 |
| 76 | Leo International leointernational.com | 🇺🇸 United States | — | Jun 23, 2026 |
| 77 | Ntd Apparel | — | Consumer Services | Jun 22, 2026 |
| 78 | Apptricity | 🇺🇸 United States | Business Services | Jun 18, 2026 |
| 79 | Berg Lilly | — | — | Jun 18, 2026 |
| 80 | Smith Filter | — | Manufacturing | Jun 17, 2026 |
| 81 | Insite Architects | — | Business Services | Jun 16, 2026 |
| 82 | DDC Domus Design Collection | — | Consumer Services | Jun 12, 2026 |
| 83 | Associated Investor Services | — | Financial Services | Jun 10, 2026 |
| 84 | Port Air Express portairexpress.com | — | Transportation/Logistics | Jun 10, 2026 |
| 85 | The Midland Theatre | 🇬🇧 United Kingdom | Hospitality and Tourism | Jun 10, 2026 |
| 86 | Centre Ellipse | — | — | Jun 9, 2026 |
| 87 | Rockaway River Country Club | — | Hospitality and Tourism | Jun 9, 2026 |
| 88 | SMPC Architects | — | Construction | Jun 9, 2026 |
| 89 | Spray Equipment & Service Center | — | Business Services | Jun 9, 2026 |
| 90 | HRC Sicherheitsdienste | 🇩🇪 Germany | Business Services | Jun 8, 2026 |
| 91 | Kennon Worldwide kennon.com | — | Business Services | Jun 5, 2026 |
| 92 | Oaks Park oakspark.com | 🇺🇸 United States | Consumer Services | Jun 5, 2026 |
| 93 | T/CCI Manufacturing | — | Manufacturing | Jun 5, 2026 |
| 94 | National Standard Parts Associates | — | Manufacturing | Jun 4, 2026 |
| 95 | Northern Ohio Regional Multiple Listing Service | 🇺🇸 United States | Business Services | Jun 4, 2026 |
| 96 | Cherokee Distributing Co | 🇺🇸 United States | Transportation/Logistics | Jun 3, 2026 |
| 97 | Factors Western | — | Business Services | Jun 3, 2026 |
| 98 | Hal Otey Financial | — | Financial Services | Jun 3, 2026 |
| 99 | Sunrise, Toscana Country Club, AndalusiaCountry Club. | 🇪🇸 Spain | Hospitality and Tourism | Jun 3, 2026 |
| 100 | Healthtrax Fitness &Wellness healthtrax.com | 🇺🇸 United States | Consumer Services | May 29, 2026 |
Frequently Asked Questions
What is Akira ransomware?
Akira is a ransomware threat group that has claimed 1,438 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Akira attacked?
Akira has claimed 1,438 victims in our database, representing 6.7% of all tracked ransomware attacks. The most targeted countries are United States, Canada, Germany, United Kingdom.
Which countries does Akira target?
Akira has attacked organizations in 67 countries. The top targeted countries are: United States, Canada, Germany, United Kingdom.
Which industries does Akira target?
Akira most frequently targets the Manufacturing, Business Services, Construction sectors based on victim disclosures in our database.
Is Akira still active?
Akira's most recent victim disclosure in our database was on September 4, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.