Akira
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Akira Ransomware Group is a threat actor tracked under that alias, with open‑source reporting indicating the group is based in Russia. Public sources refer to the actor primarily as a ransomware operator, and no alternative names have been widely reported in the material provided. The group’s location is noted as Russia, though no further detail about its infrastructure or headquarters is available.
On 21 June 2023, the Akira Ransomware Group launched a cyber attack against Yokohama Off‑Highway Tires, a Japanese tire manufacturer. According to reports, at least some of the company’s computer systems were compromised during the incident. The attack was publicly described as a ransomware event, although the specific operational or data consequences were not disclosed in the initial announcements. No additional technical details about the malware used or the infection vector were included in the source material.
Beyond the Yokohama OHT incident, the provided sources do not contain information about the group’s typical targeting patterns, preferred tools, or any known affiliations with state actors or criminal consortia. Consequently, the June 2023 attack remains the sole publicly documented operation that can be cited as a representative example of the group’s activity. The profile is therefore limited to the confirmed facts of the alias, the reported Russian location, and the single ransomware incident against a tire manufacturer in Japan.
Incidents
Attributed incidents are available to members.
25 incidents