Akira
Attribution profile
- Type
- Criminal
- Location
- Russia
- Known incidents
- 25 incidents
- Sources
- 17 sources
- First seen
- 2023-05-02
- Last seen
- 2026-06-10
- Updated
- 2026-09-04 10:43
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Akira ransomware group emerged in March 2023 and has since established itself as a prolific financially motivated cybercrime operation. The group operates a dark web leak site where it publicly names victims and threatens to release stolen data as leverage in ransom negotiations, a hallmark of the double-extortion model. Public reporting and statements from affected organizations have attributed hundreds of compromises to Akira across a diverse range of industries and geographies, with the United States and Canada featuring prominently among victim locations. The group has drawn public scrutiny for high-profile attacks on corporate, governmental, educational, and critical infrastructure targets, and it has been the subject of advisories from agencies such as the FBI.
Akira's targeting is notably broad, spanning sectors that include manufacturing, technology, transportation, healthcare, financial services, education, public sector entities, business services, and energy. Victim disclosures and investigative reporting reference attacks on logistics firms, architecture practices, ambulatory medical facilities, industrial service providers, regional airports, media companies, municipalities, and managed service providers whose environments host downstream customers. This wide sectoral reach, combined with the group's willingness to disrupt operational systems, suggests a strategy aimed at maximizing ransom leverage rather than adhering to any specific ideological or espionage-driven agenda. The group is also reported to have shifted toward targeting ESXi virtualization environments, as seen in the Shook Lin & Bok incident, where the firm allegedly paid roughly US$1.4 million in bitcoin to recover access.
In terms of tradecraft, public reporting and technical analyses describe Akira as obtaining initial access through tactics such as phishing emails and the exploitation of unpatched or weakly secured remote access products, with particular emphasis on Cisco VPN accounts lacking multi-factor authentication. Once inside a network, the actors are reported to escalate privileges, move laterally, and exfiltrate data before encrypting systems, after which ransom notes are left on compromised hosts. The Finnish National Cyber Security Center warned that Akira frequently leverages unpatched Cisco VPN vulnerabilities, and Cisco itself has advised customers to enforce MFA and forward logs to remote syslog servers to preserve evidence of intrusion. Researchers at Avast and Arctic Wolf have noted code-level similarities between Akira's malware and the now-defunct Conti ransomware family, suggesting the operators were at least inspired by leaked Conti sources, though no direct lineage has been publicly proven.
Attribution to a specific state or criminal consortium has not been definitively established in the available reporting. Some sources, particularly European media outlets covering attacks on Icelandic and Swedish entities, have described Akira as a Russian-linked or Russian-speaking group, but no official law enforcement attribution to a named state actor is reflected in the supplied material. The group is consistently characterized as a financially motivated criminal enterprise rather than an espionage or sabotage operation, and its ransom demands have been publicly reported to range from roughly US$200,000 to several million dollars depending on the victim's size and perceived ability to pay.
Representative operations attributed to Akira include the 2024 compromise of Tietoevry's Swedish data center, which cascaded into outages for numerous Swedish government agencies, universities, and retailers; the 2024 ransomware attack on Split's Saint Jerome Airport in Croatia, which forced manual passenger processing during peak tourist season; the 2024 cyberattack on Icelandic media company Árvakur, publisher of Morgunblaðið; the 2025 Akira ransomware incident at Hitachi Vantara that disrupted internal systems and manufacturing; and the 2023 attack on Singapore law firm Shook Lin & Bok, which reportedly resulted in a multi-million-dollar ransom payment. Earlier victims cited in public reporting include Yamaha Canada Music, Stanford University's Department of Public Safety, Middlesex County Public Schools, and Mercer University, illustrating the group's sustained activity across both private and public sector targets since its emergence.
Incidents
Attributed incidents are available to members.
25 incidentsSources
Sources available to members: 17 sources.