Ransomware dossier

Akira

Fast-growing since 2023. Gains access through VPNs without MFA and stolen credentials; encrypts Windows and VMware ESXi. Shares lineage and tooling with Conti alumni.

Claimed victims

552

Top region

US

Top sector

Manufacturing

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-10-03The Official Collegeof Architects of León (COAL)Professional ServicesMX
2026-10-02The Official College of Architects of León (COAL)Professional ServicesMX
2026-10-02Jampac AlimentosAgriculture and Food ProductionBR
2026-10-02Pacific Tank LinesTransportationUS
2026-10-01WesmarManufacturingUS
2026-10-01DPL GroupOther—
2026-10-01Krycler, Ervin, Taubman & KaminskyProfessional Services—
2026-09-28Geebee GarmentsRetail & E-Commerce—
2026-09-28KnitTechnology—
2026-09-24WallatecOther—

Regions targeted

US 89DE 9GB 7CA 6BR 3IT 3CH 3MX 2

Sectors targeted

Manufacturing 57Professional Services 30Retail & E-Commerce 14Business Services 12Healthcare 11Hospitality 10

Suspected origin

Russia — Conti ties; Russian-speaking (OSINT). Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups