Redpacketsecurity AKIRA Ransomware Targets Lazyboyz and Southern California Telephone Company
Article Content
- •AKIRA ransomware group claims Lazyboyz and Southern California Telephone Company as victims.
- •No confirmed data breaches; claims of data leaks remain unverified.
- •Sensitive information, including employee records, is reportedly at risk.
On September 15, 2026, the AKIRA ransomware group listed both Lazyboyz, a motorcycle dealership, and Southern California Telephone Company, a telecommunications provider, as victims on its leak site. Lazyboyz specializes in Harley-Davidson and Royal Enfield motorcycles, while Southern California Telephone Company offers internet and VoIP services. The AKIRA group claims that sensitive corporate data from both organizations will be uploaded later, including employee personal information and financial records. No ransom demands or specific compromise details were provided in either case. The listings indicate a potential data leak threat rather than confirmed data breaches, as no evidence of stolen data has been presented. Both articles caution that the claims made by the threat actors remain unverified. The lack of specific details regarding the attack method or encryption status further complicates the assessment of the situation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Akira and Lazyboyz in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft Cybercriminals are increasingly abusing Microsoft’s Volume Shadow Copy Service (VSS) to facilitate ransomware attacks and steal credentials. They achieve this by deleting recovery options before deploying ransomware and extracting sensitive data from protected files, including the Active Directory database. Tools such…