Akira
Fast-growing since 2023. Gains access through VPNs without MFA and stolen credentials; encrypts Windows and VMware ESXi. Shares lineage and tooling with Conti alumni.
Claimed victims
552
Top region
US
Top sector
Manufacturing
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2026-10-03 | The Official Collegeof Architects of León (COAL) | Professional Services | MX |
| 2026-10-02 | The Official College of Architects of León (COAL) | Professional Services | MX |
| 2026-10-02 | Jampac Alimentos | Agriculture and Food Production | BR |
| 2026-10-02 | Pacific Tank Lines | Transportation | US |
| 2026-10-01 | Wesmar | Manufacturing | US |
| 2026-10-01 | DPL Group | Other | — |
| 2026-10-01 | Krycler, Ervin, Taubman & Kaminsky | Professional Services | — |
| 2026-09-28 | Geebee Garments | Retail & E-Commerce | — |
| 2026-09-28 | Knit | Technology | — |
| 2026-09-24 | Wallatec | Other | — |
Regions targeted
Sectors targeted
Suspected origin
Russia — Conti ties; Russian-speaking (OSINT). Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.