🇷🇺 Akira
Threat-actor battle card · maintained from public sources · last updated 2026-09-01 · also known as RedBike
CategoryRansomware-as-a-Service
AttributionPossible Conti lineage (links to Storm-1567 / Howling Scorpius)
First seenMarch 2023
StatusActive
Rank#3
Victims L3M184
Victims YTD228
Primary targetsSMBs, Manufacturing, Healthcare, Education, Transportation
Overview
Akira is a Ransomware-as-a-Service operation that emerged in March 2023 and is the subject of a #StopRansomware CISA/FBI advisory (AA24-109A, updated Nov 2025) warning of an imminent threat to critical infrastructure. It has matured into one of the most active groups, claiming ~$244M in proceeds by late September 2025 and 749 victims across the April 2025 – March 2026 annual period (Emsisoft, July 2026 — second only to Qilin at 1,358). Currently #3 with 184 claimed victims over the trailing three months and 228 YTD 2026, having expanded after the RansomHub / LockBit disruptions. Possible Conti lineage tracked as Storm-1567 (Microsoft) and Howling Scorpius (CrowdStrike). Note: L3M/YTD figures are current as of July 2026 (Emsisoft Q2); update pending Q3 report.
Tradecraft
- Initial access via SonicWall CVE-2024-40766, spear-phishing, password spraying, brute force, and purchased credentials from initial-access brokers.
- Tooling: Mimikatz, LaZagne, Advanced IP Scanner, AnyDesk for credential dumping, lateral movement and remote access.
- Disables security software, deletes backups, and specifically targets Veeam and VMware/ESXi infrastructure to maximise impact.
- Aug 2026 — Safe Mode EDR bypass: Reboots victim machines into Windows Safe Mode before executing ransomware to disable endpoint detection tools that do not load in Safe Mode. Documented by Huntress in August 2026 intrusion response. Signals that defenders' EDR tooling is constraining normal-mode execution.
- Aug 2026 — encryptor defect: The Register reported at least one intrusion where Akira's encryptor corrupted rather than encrypted files, inadvertently increasing attack visibility. Suggests rushed tooling updates under operational pressure.
Notable recent victims
- Golfview Developmental Center (US healthcare / disability services)
- InSite Architects (US)
- Leo International (supply chain/PVF/HVAC/US — DLS June 23)
- IH Engineers P.C. (engineering consulting/US — DLS June 23)
- Miami Machine Inc. (manufacturing/US — DLS June 24)
- JIT-EX LLC (trucking-logistics/US — ~40GB, employee SSNs/W-9s/passports/credit card data — DLS June 24)
- JMS Southeast (business services/US — ~25GB, employee PII + government entity NDAs — DLS June 25)
- Padget Technologies (robotics-automation/US — DLS June 25)
- Precise Forms, Inc. (aluminum forms manufacturing/US — ~10GB — DLS June 26 🟥 unverified)
- Refinery Hotel (hospitality/US — New York City boutique hotel; ~15GB exfiltrated claimed; DLS July 1, 2026 🟥 unverified)
- Advanced Business Systems (office solutions/IT/US — ~31GB exfiltrated claimed; DLS July 1, 2026 🟥 unverified)
- Excalibur Rentals (equipment rental/US — 45GB claimed incl. employee PII, SSNs, passports, contracts; DLS July 7, 2026 🟥 unverified)
- Dignity Health St. Mary's Medical Center (healthcare/US — 41GB claimed incl. employee passports, SSNs, contracts; April 2026 attack, notifications mailed July 2026 🟥 unverified)
- L&A Transport (transportation/US — DLS July 20, 2026 🟥 unverified)
Assessment
A relentless SMB-and-mid-market threat with a mature virtualization-targeting playbook. The active CISA advisory and Veeam/ESXi focus make backup integrity and edge-VPN patching the priority defenses.
Sources
🗂️ Attacks & victims
All disclosed victims attributed to this actor, newest first.
August 2026
Aug 21
JC Sales
Akira
Ransomware · Wholesale Distribution · USA
Akira ransomware DLS claim August 21 2026; JC Sales is a full-service wholesaler based in Los Angeles; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 13
CF Supply
Akira
Ransomware · Distribution · US
Akira DLS claim August 13, 2026; industrial supply distributor; scope unconfirmed. · Sources: https://www.ransomware.live/group/akira
July 2026
Jul 20
L&A Transport
Akira
Ransomware · transportation · US
US trucking company; Akira DLS claim July 20, 2026; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 08
Dignity Health St. Mary's Medical Center
Akira
Ransomware · healthcare · hospital/US
acute-care hospital (232 beds); Akira DLS claim April 2026; 41 GB claimed including employee passports, SSNs, government IDs, contracts, NDAs; victim notification letters sent July 2026; attack date estimated April 2026; 🟥 unverified — hospital has not issued public statement confirming breach · Sources: [ClassAction.org] · [BleepingComputer]
Jul 08
Wade's Dairy
Akira
Ransomware · food · dairy manufacturing/US
Akira DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/akira · Sources: [SharkStriker] · [ransomware.live]
Jul 07
Excalibur Rentals
Akira
Ransomware · equipment rental · US
Akira DLS claim July 7, 2026; 45 GB claimed including employee PII (SSNs, passports), contracts, and customer data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-excalibur-rentals/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jul 07
RISE Architecture
Akira
Ransomware · architecture · US
Akira DLS claim July 7, 2026; 57 GB claimed including employee PII, client files, financial records, and project documents; data scope unconfirmed; 🟥 unverified · https://www.galaxywarden.com/blog/breach/rise-architecture-akira-2026-07 · https://www.ransomware.live/group/akira · Sources: [GalaxyWarden] · [ransomware.live]
Jul 07
Chisholm, Persson & Ball, PC
Akira
Ransomware · legal · law firm/US
Akira DLS claim July 7, 2026; 45 GB claimed including client passports, visas, SSNs, court files, and police reports; data scope unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-akira-hits-chisholm-persson-and-ball/ · https://www.ransomware.live/group/akira · Sources: [HookPhish] · [ransomware.live]
Jul 01
Refinery Hotel
Akira
Ransomware · hospitality · hotel/US
luxury boutique hotel near Bryant Park (197 rooms, Parker & Quinn restaurant, Refinery Rooftop bar); Akira DLS claim July 1, 2026; 15 GB claimed including employee PII (passports, driver's licenses, SSNs, W-9 forms), guest information, financials, contracts and agreements, and NDAs; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.redpacketsecurity.com/akira-ransomware-victim-refinery-hotel/ · https://www.hookphish.com/blog/ransomware-group-akira-hits-refinery-hotel/ · https://ransomware.live/id/UmVmaW5lcnkgSG90ZWxAYWtpcmE= · Sources: [RedPacket Security] · [HookPhish] · [ransomware.live]
June 2026
Jun 30
Advanced Business Systems
Akira
Ransomware · office solutions · technology/US
regional office technology solutions and managed services provider; Akira DLS claim June 30, 2026; 31 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jun 26
Precise Forms, Inc.
Akira
Ransomware · manufacturing · aluminum forms/US
aluminum forming products manufacturer; Akira DLS claim June 26, 2026; ~10 GB claimed; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-precise-forms-inc/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jun 25
JMS Southeast
Akira
Ransomware · business services · industrial distribution/US
temperature measurement and control products distributor (thermocouples, RTDs, thermowells, transmitters); Akira DLS claim June 25, 2026; ~25 GB claimed including employee PII (names/addresses), payment data, NDAs, project contracts, agreements with government entities, and customer information · https://www.redpacketsecurity.com/akira-ransomware-victim-jms-southeast/ · https://malware.news/t/akira-ransomware-attack-targets-jms-southeast/108233 · Sources: [RedPacket Security] · [malware.news]
Jun 25
Padget Technologies
Akira
Ransomware · manufacturing · robotics-automation/US
robotics and automation company specialising in engineered machinery, assembly solutions, and robotic palletizing cells; Akira DLS claim June 25, 2026; data upload pending, includes employee records (government IDs, tax forms), payment details, and NDAs · https://www.redpacketsecurity.com/akira-ransomware-victim-padget-technologies/ · https://malware.news/t/akira-ransomware-targets-padget-technologies/108234 · Sources: [RedPacket Security] · [malware.news]
Jun 24
Miami Machine Inc.
Akira
Ransomware · manufacturing · US
DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 24
JIT-EX LLC
Akira
Ransomware · transportation · trucking-logistics/US
regional and local truckload carrier (dedicated fleets, crossdock, transloading, storage trailer services); ~40GB claimed; includes employee SSNs, W-9 forms, driver's license documents, passport copies, and credit card details · https://www.redpacketsecurity.com/akira-ransomware-victim-jit-ex/ · https://www.ransomware.live/group/akira · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
Leo International
Akira
Ransomware · supply chain · PVF/HVAC/plumbing products/US
https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 23
IH Engineers, P.C.
Akira
Ransomware · engineering consulting · US
https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 16
Golfview Developmental Center
Akira
Ransomware · healthcare · disability services/US
Sources: ransomware.live DLS
Jun 09
Spray Equipment & Service Center
Akira
Ransomware · industrial equipment · US
Sources: ransomware.live DLS
← All threat actors · Full victim database →