AK

akira

Known ransomware group ACTIVE
Currently active

Akira is a prolific ransomware operation active since March 2023, known for its retro green-on-black leak site and for encrypting both Windows and Linux/ESXi environments. It frequently gains initial access through compromised VPN credentials and unpatched edge devices, and shares code lineage with the defunct Conti group.

7

Total Claims

7

Critical

Records Claimed

4

Industries Hit

Active span: Apr 22, 2026 – Jun 3, 2026 · 7 organizations targeted

Currently active
Activity 5.6 Severity 10.0 Sectors 5.4 Tooling 10.0

Actor Threat Profile

Activity Timeline

Peak: May 2026 (5)
Apr 2026
LessMore
Jun 2026

Share this profile

Shareable intel card for akira

Top Targeted Industries

Healthcare 4
Financial Services 1
Energy 1
Business Services 1

Tradecraft & Infrastructure

42

Documented tools

12 / 27

MITRE tactics / techniques

2

Known leak sites

CredentialTheftDefenseEvasionDiscoveryEnumExfiltrationLOLBASNetworkingOffsecRMM-Tools
Full intelligence profile on ransomware.live →

Claims by akira

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.