What Is Akira Ransomware? Attack Chain, Victims, and Current Status of the RaaS Platform

Key takeaways
- Akira ransomware is a Ransomware-as-a-Service operation that has been active since March 2023 and remains active, with government advisories describing it as an imminent threat to critical infrastructure;
- Most Akira ransomware intrusions begin at a virtual private network account without multifactor authentication, either through a known vulnerability in an edge device or through credentials that survived a hardware migration;
- The Akira ransomware group operates double extortion, exfiltrating data before encrypting it and threatening publication on a Tor leak site in preference to relying on encryption alone;
- Figures attributed to Akira ransomware require care, because the widely quoted proceeds total is undefined by the agencies that published it and the largest victim counts come from the group's own leak-site postings;
- Free decryption for Akira ransomware exists only for superseded variants, and the Linux method published in March 2025 no longer works against the current version;
- No indictment, sanction, arrest, or law enforcement disruption has named the Akira ransomware group, which distinguishes it from most operations of comparable scale;
- The clearest Akira ransomware lessons come from what failed at named victims: absent multifactor authentication, unpatched edge devices, credentials carried through migrations, and destroyed backups.
Akira ransomware is a Ransomware-as-a-Service operation first observed in March 2023 that steals data before encrypting it, then threatens publication unless paid. It has impacted over 250 organizations across manufacturing, education, healthcare, and financial services in North America, Europe, and Australia, and remained active through 2026 with no law enforcement disruption.

According to the FBI's 2023 Internet Crime Report, Akira was among the top five ransomware variants affecting critical infrastructure with 95 incidents, third behind LockBit with 175 and ALPHV/BlackCat with 100.
The distance between what is confirmed about Akira ransomware and what circulates as fact has widened since. This comprehensive article covers:
- How the Akira ransomware attack chain moves from a virtual private network account to encryption;
- What the Akira ransomware SonicWall campaign actually exploited, and why early zero-day reporting was corrected;
- Which organizations Akira ransomware has hit, and what each confirmed against what the group claimed;
- Whether an Akira ransomware decryptor exists, and which variants it covers;
- Where the Akira ransomware group stands in 2026 and what remains unknown.
One guessed password ended a 158-year-old logistics firm and cost 730 jobs. Adaptive Security closes the credential and lure gaps that let ransomware operators reach production systems.
Quick Facts About Akira Ransomware
The reference table below summarizes what the public record establishes about Akira ransomware, with a confidence label attached to every entry. CONFIRMED indicates verified information, REPORTED indicates credible sources without independent verification, and UNKNOWN indicates missing evidence.
| Field | Detail | Confidence |
|---|---|---|
| Entity name | Akira ransomware | CONFIRMED |
| Aliases | Storm-1567, Howling Scorpius, Punk Spider, Gold Sahara; variants Megazord and Akira_v2 | CONFIRMED |
| First observed | March 2023 | CONFIRMED |
| Operating model | Ransomware-as-a-Service, operator plus affiliates | CONFIRMED |
| Initial access | Virtual private network without multifactor authentication; CVE-2020-3259, CVE-2023-20269, CVE-2020-3580, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711, CVE-2024-40766; stolen credentials; Remote Desktop Protocol; spearphishing | CONFIRMED |
| File extensions | .akira, .powerranges, .akiranew, .aki | CONFIRMED |
| Ransom note filename | akira_readme.txt or fn.txt; akiranew.txt on the Linux ESXi variant | CONFIRMED |
| Ransom demanded | $200,000 to over $4 million | REPORTED |
| Ransom paid, per victim | No confirmed payment established in the public record | UNKNOWN |
| Organizations affected | Over 250 as of January 1, 2024 | CONFIRMED |
| Current status | Active; described as an imminent threat to critical infrastructure | CONFIRMED |
| Law enforcement action | None naming Akira as of August 26, 2026 | CONFIRMED |
| Free decryptor | Partial, covering superseded variants only | CONFIRMED |
What Akira Ransomware Is and How the Operation Works
Akira ransomware is a Ransomware-as-a-Service operation in preference to an isolated incident, first observed in March 2023 and still running through 2026. That distinction matters for every figure attached to it, because the operation's confirmed behavior and the totals assigned to it come from different counting methods, both of which need to be discussed.
How the Akira Ransomware-as-a-Service Model Operates
The Akira ransomware operation runs on a Ransomware-as-a-Service model, meaning a core operator maintains the encryption tooling while affiliates carry out intrusions for a share of proceeds. The FBI and CISA joint advisory confirms that operator-plus-affiliate structure, though no public source distinguishes individual affiliates.
Double extortion is the standing method: the Akira ransomware group exfiltrates data first and encrypts it second, so publication of stolen files remains a live consequence even where a victim restores from backups. According to IBM's Cost of a Data Breach Report 2026, 39% of breached organizations reported at least one ransomware incident, up from 34% the previous year.
Targeting concentrates on small and mid-sized businesses, and the advisory names manufacturing, education, information technology, healthcare and public health, financial services, and food and agriculture as stated preferences. Documented ransomware attacks by the group span North America, Europe, and Australia.
How Much Akira Ransomware Has Actually Collected
According to the FBI and CISA's #StopRansomware: Akira Ransomware (AA24-109A) 2024, as of January 1, 2024 Akira had impacted over 250 organizations and claimed approximately $42 million (USD) in ransomware proceeds. The advisory update of November 13, 2025 raises that cumulative total for a measurement date in late September 2025. Both totals are running cumulative figures measured 21 months apart, so neither contradicts the other.
The word "proceeds" carries more weight in coverage than the source supports. The 31-page document publishes no methodology, attributes the figure to no authoring agency, and gives no split between amounts demanded and received. Reporting that renders the total as ransom collected states something the joint advisory on Akira ransomware does not.
Ransom demands for Akira ransomware have been reported in a range from $200,000 to over $4 million, a REPORTED figure in preference to a confirmed one. No per-victim payment is established anywhere in the public record.
Why the Akira Ransomware Name Appears for Two Different Incidents
An unrelated ransomware family also carrying the Akira name was reported in 2017, and the two share no code. Both append the .akira extension to encrypted files, which is why the collision persists in search results. The Avast decryption tool built for the 2023 Akira ransomware family does not work on the 2017 one.
Treat every headline ransomware figure as a claim until its source defines it. Adaptive Security grounds workforce readiness in measured behavior rather than in numbers borrowed from press coverage.
How the Akira Ransomware Attack Chain Unfolds
The Akira ransomware attack chain is documented through FBI investigations rather than reconstructed from theory, and the joint advisory maps it across five stages. This section walks initial access, spread, encryption, and extortion in the order they occur. Initial access is the most misreported stage, and the Akira ransomware SonicWall activity of 2025 is where that misreporting concentrated.
How Akira Ransomware Gains Initial Access
Virtual private network services without multifactor authentication are the primary confirmed entry point for Akira ransomware, and the FBI and CISA joint advisory lists that vector ahead of every other technique.
The advisory names eight vulnerabilities exploited for initial access across Cisco, SonicWall, VMware, and Veeam products: CVE-2020-3259, CVE-2023-20269, CVE-2020-3580, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711, and CVE-2024-40766. According to Verizon's Data Breach Investigations Report 2026, exploitation of vulnerabilities reached 31% of breaches and overtook stolen credentials as the leading initial access vector.
Credential-based routes sit alongside those vulnerabilities in the authoring organizations' technical detail:
- Stolen and brute-forced virtual private network credentials, potentially supplied by initial access brokers;
- Password spraying against exposed authentication endpoints;
- Remote Desktop Protocol sessions and spearphishing messages;
- Secure Shell access via a router's internet-facing address.
One documented intrusion began differently, when an employee acted on a fake verification prompt, known as a ClickFix lure, on a compromised third-party website. That prompt delivered the SectopRAT remote access tool and established persistent access, an account REPORTED by an incident response firm.
What the Akira Ransomware SonicWall Campaign Actually Exploited
The Akira ransomware SonicWall activity that began in July 2025 exploited CVE-2024-40766, disclosed in August 2024, instead of any previously unknown flaw. Early assessments treated a zero-day as plausible because compromises kept appearing on patched appliances.
SonicWall's product notice of August 2025 reattributed the activity, stating high confidence that it was "not connected to a zero-day vulnerability" and tying it to Gen6 to Gen7 migrations that carried over local passwords without a reset. The Akira ransomware CISA advisory update of November 13, 2025 confirms CVE-2024-40766 as an initial access vector.
Credential reuse explains the detail that made a zero-day look likely. Where a migration preserved local passwords and one-time password secrets, patching left valid credentials in place, so an updated appliance still admitted the Akira ransomware group.
How Akira Ransomware Spreads Once Inside
The Akira ransomware group creates domain and local accounts and adds them to administrator groups, including one observed as itadm. Credential access follows, drawing on Kerberoasting, memory dumping of the Local Security Authority Subsystem Service, extraction of the SAM and NTDS.dit credential stores, Mimikatz, LaZagne, and NetExec. In one reported incident the group powered down a domain controller virtual machine and attached copies of its disk files to a new machine.
Discovery and lateral movement rely on administrative utilities instead of custom tooling, with Advanced IP Scanner, NetScan, AdFind, and nltest mapping the environment and Remote Desktop Protocol, Secure Shell, AnyDesk, and LogMeIn carrying movement between hosts. Defense evasion covers uninstalling endpoint detection and response software, loading a vulnerable signed driver, and modifying firewall rules, while command and control runs through Ngrok and Cobalt Strike.
How Akira Ransomware Encrypts and Extorts
Akira ransomware uses hybrid encryption, combining a stream cipher with RSA and selecting full or partial encryption by file type and size. The joint advisory describes ChaCha20 with RSA for the Windows lineage, while reverse engineering of the Linux V3 variant found KCipher2 across the first 65,535 bytes of each block and ChaCha8 for the remainder, with per-file keys wrapped in RSA-4096.
Encrypted files carry one of four extensions: .akira, .powerranges, .akiranew, or .aki. Ransom notes appear as akira_readme.txt or fn.txt, with akiranew.txt used by the Linux ESXi variant, and PowerShell commands delete Volume Shadow Copies so local rollback is unavailable.
The Akira ransomware group leaves no demand or payment instructions on the network, supplying a per-victim code and a Tor contact address instead, with payment requested in Bitcoin.
Cyberattackers reach domain administrator rights within hours of a first login on an unprotected account. Adaptive Security builds the reporting reflex that turns an early anomaly into an early response.
Akira Ransomware-as-a-Service Timeline: From March 2023 to 2026

First access, detection, public disclosure, and the group's own leak-site claim are four separate dates, and most coverage of Akira ransomware collapses them into one. The timeline below keeps them apart wherever public sources allow it. For two named victims the interval between compromise and discovery cannot be reconstructed from anything published.
Akira Ransomware Timeline: Key Dates
Three dates anchor the Akira ransomware timeline:
- March 2023 marks the first observation.
- April 18, 2024 marks the first joint advisory that established a government victim count and financial total.
- November 13, 2025 marks the update that added new vulnerabilities, Nutanix AHV targeting, and a revised proceeds figure.
According to the FBI and CISA's #StopRansomware: Akira Ransomware (AA24-109A) 2025, indicators of compromise for Akira were observed between June 2023 and August 2025. That window describes the period the authoring organizations could evidence, which is narrower than the operational lifespan of the Akira ransomware group.
| Date | Event | Source | Confidence |
|---|---|---|---|
| March 2023 | Akira ransomware first observed | AA24-109A | CONFIRMED |
| April 2023 | Linux and VMware ESXi variant deployed | AA24-109A | CONFIRMED |
| May 12, 2023 | Stanford University Department of Public Safety network first accessed | Stanford breach notice via Maine Attorney General | CONFIRMED |
| June 2023 | KNP Logistics Group attacked | BBC Panorama, July 21, 2025 | CONFIRMED |
| June and July 2023 | Avast releases free Windows decryptor | Avast; The Record | CONFIRMED |
| August 2023 | Megazord variant appears, appending .powerranges | AA24-109A | CONFIRMED |
| September 25, 2023 | KNP Logistics Group enters administration | FRP Advisory; trade press | CONFIRMED |
| September 27, 2023 | Stanford University detects intrusion | Stanford; The Record | CONFIRMED |
| December 5, 2023 | Nissan Oceania detects intrusion | SecurityWeek | CONFIRMED |
| January 17, 2024 | Toronto Zoo discloses breach | IPC Ontario; BleepingComputer | CONFIRMED |
| January 19 to 20, 2024 | Tietoevry Sweden datacenter attacked | Tietoevry press release | CONFIRMED |
| April 18, 2024 | Joint advisory AA24-109A published | CISA | CONFIRMED |
| April 26, 2025 | Hitachi Vantara detects ransomware | Hitachi Vantara statement | CONFIRMED |
| July 2025 | Surge exploiting SonicWall SSL VPN begins | Arctic Wolf | REPORTED |
| November 13, 2025 | Advisory updated with new CVEs and Nutanix AHV targeting | CISA and IC3 | CONFIRMED |
| November 19, 2025 | OFAC sanctions bulletproof hosting network, naming LockBit, BlackSuit, and Play but not Akira | US Department of State | CONFIRMED |
| March 2026 | 84 leak-site victims posted, second most active month recorded | Breachsense via secondary reporting | REPORTED |
What the Akira Ransomware Timeline Is Missing
Stanford University is the only named victim whose first-access and detection dates are separately published, giving an interval of approximately 4.5 months between May 12 and September 27, 2023. Every other entry collapses into a single point.
According to the FBI and CISA's #StopRansomware: Akira Ransomware (AA24-109A) 2025, Akira threat actors in some incidents exfiltrated data in just over 2 hours from initial access. One documented intrusion instead ran 42 days before encryption, so the pace of an Akira ransomware compromise varies by more than two orders of magnitude between incidents.
Hitachi Vantara and KNP Logistics Group have published no first-access date distinct from detection. Dwell time is UNKNOWN for both, and estimating an interval for either would be unsupported by any source.
Adaptive Security shortens the gap between a first unauthorized login and the moment someone notices. Months of undetected access turn one credential into an enterprise-wide encryption event.
Who Operates Akira Ransomware and Its Relation to Conti
Less is established about the operators of Akira ransomware than most coverage implies. Government sources name a group and hedge everything beyond that, while vendor reporting states the same lineage with more confidence than any agency has adopted. This section addresses three questions: what the Akira ransomware group is called, whether it descends from Conti, and why no one has been charged.
What the Akira Ransomware Group Is Called Across Threat Intelligence
Four aliases identify the Akira ransomware group across threat intelligence reporting, each assigned by a different organization: Microsoft tracks the operation as Storm-1567, Palo Alto Networks Unit 42 as Howling Scorpius, and CrowdStrike as Punk Spider and Gold Sahara.
The alias sprawl matters for anyone searching threat intelligence, because one operation surfaces under six labels depending on who published the report. Megazord and Akira_v2 add a further layer, since both describe developer tooling instead of separate groups.
Origin is assessed as likely Russia-linked on the basis of Russian-language forum use and non-VPN address observations, an assessment from blockchain analytics reporting that carries a REPORTED label rather than a government finding.
Does the Akira Ransomware Group Descend From Conti?
Every government statement on the question stays hedged. Both the April 18, 2024 and November 13, 2025 versions of the joint advisory state that Akira threat actors may have connections to the defunct Conti ransomware group, and that wording did not strengthen between the two.
The supporting evidence is reported but not confirmed. Analysis published in July 2023 recorded at least three transactions in which Akira actors sent full ransom payments to Conti-affiliated cryptocurrency addresses totaling over $600,000, two of those wallets associated with Conti leadership, alongside resemblance to Conti version 2 code.
A competing explanation fits the same evidence. Akira, Royal, Black Basta, and DragonForce all built on the leaked Conti source code, so shared code indicates a shared starting point instead of continuity of personnel. No source establishes the stronger claim of organizational descent.
Why No One Has Been Charged Over Akira Ransomware
No indictment, sanction, arrest, or disruption operation has named the Akira ransomware group, verified against US Department of Justice releases, OFAC designations, Europol releases, and Rewards for Justice through August 26, 2026. That absence separates the operation from most of the ones in comparable scale.
The nearest adjacent actions do not close the gap. According to the US Department of Justice press release of July 14, 2026 and the OFAC designations of November 19, 2025 against a bulletproof hosting network, the operations served were LockBit, BlackSuit, and Play, with Akira ransomware absent from both.
Sealed indictments are by definition not public, and no unsealing naming the Akira ransomware group has occurred as of August 26, 2026.
Attribution rarely arrives in time to help a victim organization decide what to do next. Adaptive Security focuses on the controls and behaviors that hold regardless of which group appears.
Named Victims of Akira Ransomware-as-a-Service and Documented Impact
Two separate records exist for Akira ransomware victims, and merging them produces figures that no source can support. What the group posts on its leak site is an assertion, while what a victim discloses through a regulator or a press release is a confirmation. At least one leak-site tracking service now warns that listings attributed to Akira have included unverified or fabricated victim claims.
Confirmed Akira Ransomware-as-a-Service Victims and What Each Disclosed
Stanford University confirmed that its Department of Public Safety network was first accessed on May 12, 2023 and that the intrusion was detected on September 27, 2023. Approximately 27,000 individuals were notified through the Maine Attorney General portal, with exposure covering dates of birth, Social Security numbers, government identification, passport, and license data.
Nissan Oceania detected an intrusion on December 5, 2023 and notified approximately 100,000 individuals across Australia and New Zealand, approximately 10,000 of whom had government identification exposed. The stolen data was subsequently published.

Toronto Zoo disclosed a breach on January 17, 2024 covering visitor transaction data from 2000 to April 2023 and staff records dating to 1989. The Akira ransomware group claimed responsibility on January 25, 2024, and the zoo has never attributed the incident to any group. A reported demand of $1.2 million was declined.
Tietoevry Oyj confirmed a cyberattack on the night of January 19 to 20, 2024 against one Swedish datacenter. The disruption reached the Primula payroll and human resources system used by Swedish government agencies and universities, the Filmstaden cinema chain, and Uppsala Region healthcare records. Restoration took weeks, and the intrusion is linked to CVE-2023-20269.
Hitachi Vantara LLC confirmed ransomware in a company statement dated April 26, 2025 and took servers offline, with manufacturing, remote support, and government project work disrupted while cloud services were unaffected. Attribution to Akira ransomware is REPORTED rather than confirmed, and the first-access date is UNKNOWN.
What Akira Ransomware-as-a-Service Claimed Versus What Victims Confirmed
The table below sets the group's leak-site assertions against what each organization confirmed publicly. Every figure in the claimed column is an assertion made by the Akira ransomware group.
| Claimed by the Akira ransomware group | Confirmed by the organization | Confidence |
|---|---|---|
| Stanford University: 430 GB | 27,000 individuals; dates of birth, Social Security numbers, government identification, passports, licenses | Left column CLAIMED; right column CONFIRMED |
| Nissan Oceania: 100 GB including non-disclosure agreements, project and client data | Approximately 100,000 individuals; approximately 10,000 government identification documents; employee and customer data | Left column CLAIMED; right column CONFIRMED |
| Toronto Zoo: 133 GB including non-disclosure agreements and driver licenses | Visitor transaction data 2000 to April 2023; staff records from 1989; last four digits and expiry of payment cards used January 2022 to April 2023 | Left column CLAIMED; right column CONFIRMED |
| Tietoevry: no prominent leak-site claim | Service disruption confirmed; extent of data theft not fully established | Right column CONFIRMED; extent UNKNOWN |
| Hitachi Vantara: files stolen, ransom notes dropped | Ransomware and disruption confirmed; data specifics not detailed | Left column CLAIMED; right column CONFIRMED |
The two columns diverge because they measure different things. A claimed volume in gigabytes describes what the Akira ransomware group says it took, while a confirmed disclosure describes what a victim's own investigation established and what a regulator required it to report. According to IBM's Cost of a Data Breach Report 2026, 41% of ransomware incidents applied reputational pressure through data leaks and public shaming alongside encryption, which is the pressure that makes such claims worth publishing.
Claimed volumes cannot be aggregated into a victim count or a data-loss total. Listings attributed to Akira have included unverified claims, so summing the left column would produce a number resting entirely on the group's self-reporting.
How Widely Akira Ransomware Has Spread
The FBI Internet Crime Report ranks variants by complaint volume from United States victims, which is a narrower measure than global victim totals. According to the FBI's 2024 IC3 Annual Report, Akira was the most-reported ransomware variant affecting critical infrastructure in 2024.
Larger totals circulating in coverage of Akira ransomware come from aggregating trackers that count leak-site postings, and those carry a REPORTED label because they rest on what the group published about itself. The government-confirmed count established through FBI investigations is substantially smaller.
The two measures are not interchangeable. One reflects what federal investigators verified against victim reports, and the other reflects what the Akira ransomware group chose to announce.
Universities, manufacturers, and municipal bodies have all disclosed breaches that began at one account. Adaptive Security measures which roles hold credentials reaching externally exposed services, then trains them first.
Akira Ransomware Decryption and Recovery Options
Free decryption for Akira ransomware exists only for superseded variants, and no published tool recovers files encrypted by the version in use through 2026. That answer holds in both directions, because one method that worked has since been defeated and the other never covered the current lineage. This section sets out which Akira ransomware decryptor covers which variant, and where each one stops.
Does an Akira Ransomware Decryptor Exist?
An Akira ransomware decryptor exists for superseded variants alone. Avast released a free tool in late June and July 2023 for the earliest Windows .akira variant, exploiting a weakness in the way that build handled partial encryption and key generation, and the tool requires a matched pair of plaintext and encrypted files of identical size.
Two exclusions travel with any mention of that tool. It does not work on the unrelated 2017 Akira family, and it does not work on the variant that appeared in July 2023 after the operators corrected the flaw.
The tool is listed on the No More Ransom project index of decryption tools with an accompanying how-to guide, which is the appropriate destination for any organization checking whether recovery without payment is available. The date that listing was added is not displayed, so its age is UNKNOWN.
Why the Linux Akira Ransomware Decryption Method No Longer Works
A GPU brute-force method published on March 13, 2025 targeted one Linux and VMware ESXi variant, identified by its author as Linux V3 and matched to a single sample hash. The method recovers per-file keys by exploiting the encryptor's use of nanosecond timestamps as seeds.
One documented recovery was achieved without payment using that method. Rented GPU capacity for a comparable job cost approximately $1,200 and completed in just over 10 hours across 16 rented RTX 4090 units.
That method no longer works against current Akira ransomware builds. The author added a standing notice, present as of the post's last modification on November 7, 2025, stating that a newer version cannot be decrypted with it, an outcome he anticipated in the original publication. The date the operators changed the routine is UNKNOWN.
No independent replication, refutation, or second confirmed recovery by any national computer emergency response team or incident response firm has been published.
What Akira Ransomware Recovery Looks Like Without Backups
Recovery without backups is not realistically achievable against current Akira ransomware variants. According to Verizon's Data Breach Investigations Report 2026, 69% of ransomware victims declined to pay a ransom, which places the entire weight of restoration on backup integrity. Destroyed backups, rather than the strength of the encryption itself, decide whether an organization recovers.
Recovery without backups is not realistically available for current ransomware variants. Adaptive Security reduces the odds of reaching that point by hardening the human path into the network.
Where Akira Ransomware Stands in 2026
Akira ransomware remained active as of August 26, 2026, with Akira_v2 as the current variant and the group's Tor leak site still operating. The authoring organizations describe the operation as an imminent threat to critical infrastructure. Government-confirmed status and tracker-reported volume are separate categories of evidence, and this section keeps them apart so the weight behind each figure stays visible.
Which Akira Ransomware Variants Are Current
Akira_v2 is the current Akira ransomware variant. Megazord, the Rust build that appended .powerranges and appeared in August 2023, has likely fallen out of use since 2024 according to the authoring organizations.
Target coverage expanded beyond VMware ESXi and Hyper-V to Nutanix AHV virtual machine disk files, first observed in June 2025. That expansion appears in the November 13, 2025 advisory update as a confirmed capability of the Akira ransomware group.
The victim of that first Nutanix AHV encryption is not identified in any public source, which leaves the capability documented while the incident behind it stays anonymous.
How Active Akira Ransomware Remains
According to Comparitech's Akira Ransomware: Stats on Attacks, Ransoms and Data Breaches 2025, Akira claimed responsibility for 683 ransomware attacks from January to November 2025, more than double its 2024 total of 272 and second only to Qilin with 864.
Those counts derive from leak-site postings, so they measure claims rather than confirmed compromises. Volume figures for 2026 circulating through aggregating trackers carry the same REPORTED label and the same limitation.
According to the FBI's 2025 Internet Crime Report, the Internet Crime Complaint Center received 3,611 ransomware complaints during 2025 with more than $32 million in reported losses, and identified 63 new ransomware variants over the year. Those reported losses exclude downtime, remediation, and third-party costs.
No takedown has occurred. The original Tor infrastructure of the Akira ransomware group remains operational, and no law enforcement disruption has been directed at it.
Match defensive habits to a ransomware operation that doubled its victim count in one year. Adaptive Security keeps workforce readiness moving at the pace of the groups targeting it.
Defensible Lessons From Akira Ransomware Incidents
Each lesson below traces to a documented failure at a named Akira ransomware victim rather than to generic ransomware guidance. Controls that would apply to any intrusion have been left out deliberately, because the value of the Akira record is its specificity. The same failures repeat across four years and five named organizations.
What Failed at Named Akira Ransomware Victims
Four failures recur across the Akira ransomware victim record, and each one is documented at a named organization:
- Virtual private network accounts without multifactor authentication, absent across the 2023 victim cohort and at KNP Logistics Group, where a guessed employee password on an externally exposed service granted entry;
- Patching lag on internet-facing edge devices, which admitted the cyberattackers at Tietoevry Oyj through CVE-2023-20269 despite prior national warnings about that vector;
- Credentials carried through hardware migrations without reset, which admitted the Akira ransomware group to SonicWall appliances already patched against CVE-2024-40766;
- Backups, servers, and disaster recovery were destroyed together at KNP Logistics Group, leaving no restoration path once encryption completed.
According to Verizon's Data Breach Investigations Report 2026, only 26% of critical vulnerabilities listed in the CISA Known Exploited Vulnerabilities catalog were fully remediated during 2025, down from 38% the previous year, while median remediation time worsened from 32 days to 43 days.
The controls that address these failures are unglamorous, and each one pairs with security awareness training that reinforces it:
- Phishing-resistant multifactor authentication protects virtual private network, webmail, and privileged accounts;
- Prioritized remediation of known exploited vulnerabilities closes the internet-facing gap first;
- Credential and one-time password rotation after any firmware upgrade or migration removes the reuse path;
- Offline, immutable, tested backups with credentials separated from the production domain preserve a restoration option.
Why Deployed Detection Did Not Stop Akira Ransomware
Two enterprise endpoint detection and response platforms logged every stage of one 42-day Akira ransomware intrusion and generated very few alerts. Deployment and tuning are separate states, and only tuning produces a response.
According to IBM's Cost of a Data Breach Report 2026, the mean time to identify and contain a breach rose to 247 days, comprising 183 days to identify and 64 to contain. Logging that no one reads extends that interval.
The detection signals the Akira ransomware record supports are specific: anomalous virtual private network logins, creation of unexpected administrative accounts, uninstallation of endpoint detection and response software, deletion of Volume Shadow Copies, and tunneling utilities in outbound traffic. Validating that each produces an actionable alert is different work from confirming the tooling is installed.
The Human Decisions Behind Akira Ransomware Intrusions
KNP Logistics Group had traded for 158 years when a guessed employee password on an externally exposed service gave Akira ransomware operators access to its network in June 2023. The cyberattackers destroyed servers, backups, and disaster recovery together, and the firm entered administration on September 25, 2023, ending 730 jobs. The company's former director stated that the employee was never told of their unwitting role.
According to Verizon's Data Breach Investigations Report 2026, 62% of breaches involved the human element, which places credential handling and lure recognition in the same risk category as unpatched infrastructure.
A fake verification prompt on a compromised third-party website opened the 42-day intrusion, a REPORTED finding rather than a government-confirmed one. Help desk impersonation is documented for a different actor and is not attributed to Akira ransomware.
Two enterprise detection platforms logged a 42-day intrusion and generated almost no alerts. Adaptive Security builds the human reporting layer that fires when automated tooling stays silent.
Reducing Ransomware Exposure Through Human Risk and Access Controls

Approaching Akira ransomware exposure as a human and access problem changes what an organization measures, moving the question from whether tooling is deployed to whether the people holding privileged access behave differently when a convincing prompt appears.
Adaptive Security addresses that exposure through Security Awareness Training and phishing simulations built around the lure patterns the Akira ransomware record documents, including fake verification prompts served from legitimate-looking third-party sites. Phishing simulations extend past email into the channels where credential lures now arrive, and the results feed back into role-specific cybersecurity awareness training rather than into a single completion score.
The 42-day intrusion in the Akira ransomware record, where deployed detection logged every stage while generating almost no alerts, defines the second window that matters. Adaptive Security's risk monitoring tracks human risk signals across that post-intrusion period, surfacing which roles carry elevated exposure and where reporting behavior has degraded. The outcome is a measurable reduction in the share of the workforce likely to surrender a credential or act on a lure, in place of a record of who finished a course.
Credential hygiene and lure recognition decide whether a ransomware operation gets its first foothold. Adaptive Security delivers both through measured cybersecurity awareness training rather than annual compliance modules.
Frequently Asked Questions About Akira Ransomware
Is Akira Ransomware Still Active?
Yes. Akira ransomware remained active as of August 26, 2026. The joint advisory updated on November 13, 2025 describes the operation as an imminent threat to critical infrastructure, Akira_v2 is the current variant, and leak-site postings attributed to the group continued into 2026.
Is There an Akira Ransomware Decryptor?
Only for superseded variants. The Avast tool released in mid-2023 decrypts the earliest Windows .akira variant and is listed on the No More Ransom project. A GPU brute-force method published on March 13, 2025 covered one Linux and VMware ESXi variant, and its author has since stated that a newer version defeats it.
How Much Has the Akira Ransomware Group Collected?
According to the FBI and CISA's #StopRansomware: Akira Ransomware (AA24-109A) 2025, as of late September 2025 Akira ransomware has claimed approximately $244.17 million (USD) in ransomware proceeds. The authoring organizations never define proceeds, publish no methodology, and give no split between amounts demanded and amounts received, so that total is not a confirmed collection figure.
Who Is Behind the Akira Ransomware Group?
A Ransomware-as-a-Service group tracked as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara operates Akira ransomware, with an operator maintaining the tooling and affiliates carrying out intrusions. Blockchain analytics reporting assesses the operation as likely Russia-linked, a REPORTED judgment. No individual has been indicted or arrested as of August 26, 2026.
Is Akira Ransomware Linked to Conti?
Possibly, though no government source states the link as established. Both versions of the joint advisory say Akira threat actors may have connections to the defunct Conti ransomware group. Reported evidence includes ransom payments to Conti-affiliated cryptocurrency addresses and code resemblance to Conti version 2, while the leaked Conti source code explains the overlap equally well.
What Is the Akira Ransomware SonicWall Vulnerability?
CVE-2024-40766, disclosed in August 2024. The Akira ransomware SonicWall activity from July 2025 was initially treated as a possible zero-day, but SonicWall's product notice of August 2025 attributed it to that known vulnerability combined with Gen6 to Gen7 migrations carrying unresetted local passwords. The November 13, 2025 advisory confirms it as an initial access vector.
What Does the Akira Ransomware Note and File Extension Look Like?
Ransom notes appear as akira_readme.txt or fn.txt in the root directory and each user home directory, with akiranew.txt used by the Linux ESXi variant. Encrypted files carry one of four extensions: .akira, .powerranges, .akiranew, or .aki. The note supplies a per-victim code and a Tor contact address rather than a stated demand.
What Was the Knights of Old Akira Ransomware Attack?
KNP Logistics Group, trading as Knights of Old, was a 158-year-old UK logistics firm attacked in June 2023 that entered administration on September 25, 2023. Entry came through a guessed employee password on an externally exposed service without multifactor authentication. The outcome was 730 redundancies, with approximately 170 jobs preserved through the sale of Nelson Distribution.
Questions about ransomware recovery usually arrive after encryption, when the affordable options have already closed. Adaptive Security moves the decision earlier, to the point where prevention still works.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Related articles

Qilin Ransomware: How It Attacks, Who It Has Hit, and How to Defend Against It

Ransomware Attack Lifecycle: A Complete Guide to Detection, Disruption, Response, and Resilient Recovery
