
Akira, a ransomware-as-a-service gang, has set a new record by publishing data from 35 victims in a single day, with more expected to be added. The notorious cybercriminal group, which emerged in March 2023, has been steadily increasing its presence in the cybercrime landscape. According to the FBI, Akira made $42 million in its first year from around 250 attacks.
The group operates by offering a platform to other hackers, enabling them to extort victims by stealing and encrypting data. Akira’s leak site, designed to resemble a monochrome 1980s command-line interface, is divided into sections for extortion and leaked data. The recent surge in data dumps is unprecedented, with 32 of the 35 victims being fresh targets.
Cybersecurity expert Adi Bleih from Cyberint noted that this marks an unusually aggressive move by Akira, suggesting the group is expanding rapidly within the cybercrime ecosystem. While ransomware groups typically give victims a grace period before publishing stolen data, Akira’s sudden bulk release has raised questions. The new victim listings are predominantly from the business services sector, with many based in the United States, alongside firms from Canada, Germany, and the UK.
While there has been speculation on social media about Akira’s motives, Bleih dismissed the idea that the gang was nearing its end. Instead, he believes the group may be showing off its capabilities and growing operations.
The Akira group’s rapid expansion and aggressive tactics serve as a reminder of the evolving threat posed by ransomware gangs. As investigators work to track down these criminals, the risk to businesses and critical infrastructure continues to rise.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543