Akira Ransomware Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 14, 2025
Last Seen
May 29, 2026

Akira Ransomware is a ransomware_group tracked across 8 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity May 29, 2026.

Related Threat Clusters

  • Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million

    The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…

    9 articles · Updated November 14, 2025
  • Akira Ransomware Attack Exploits Disabled VPN Account

    A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…

    2 articles · Updated May 29, 2026
  • Apache OpenOffice Denies Ransomware Breach Claims by Akira

    Akira ransomware claims to have breached Apache OpenOffice and stolen 23GB of sensitive corporate data. However, Apache has denied the breach, asserting that OpenOffice's open-source nature prevents such an incident.…

    1 article · Updated January 6, 2026
  • SonicWall SonicOS Vulnerability Allows Remote DoS Attacks

    SonicWall has issued a security advisory regarding a critical vulnerability in its SonicOS operating system, identified as CVE-2025-40601. This high-severity flaw affects Gen7 and Gen8 hardware and virtual appliances,…

    9 articles · Updated November 20, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…

    8 articles · Updated November 21, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…

    11 articles · Updated November 26, 2025
  • WhatsApp Vulnerability Exposes Data of 3.5 Billion Users

    A significant security flaw in WhatsApp's discovery system allowed researchers to access the phone numbers and personal information of approximately 3.5 billion users globally. The vulnerability, which exploited a…

    37 articles · Updated November 28, 2025
  • SonicWall SonicOS Flaw Allows Remote Firewall Crashes

    SonicWall has disclosed a critical vulnerability in its SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. The flaw, caused by a…

    11 articles · Updated November 24, 2025

Recent Intelligence Reports

  • Akira Ransomware Kill Chain Reconstructed from Logs — Socprime · May 29, 2026
  • Apache OpenOffice says it wasn't hit by cyberattack — Msn · January 6, 2026
  • SonicWall acts after backup breach as state actors target cloud files — Securitybrief · November 20, 2025
  • Critical SonicOS Flaw Enables Hackers To Crash SonicWall Firewall Systems — Linkedin · November 20, 2025
  • WhatsApp Flaw Enables Massive Scraping of 3.5 Billion User Accounts — Esecurityplanet · November 20, 2025
  • CISA Warns: Akira Ransomware Has Extracted $42M After Targeting Hundreds — Gbhackers · November 14, 2025

CVSS v3.1 Breakdown