Ransomware Group intelligence
Akira
ActiveTrack Akira with 1676 published victims and 2 known leak locations in a single intelligence view.
Overview
Akira is tracked by Breach House as a ransomware group with 1676 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 4h ago | akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion |
| Leak location 1 | Onion service | Down checked 4h ago | akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion |
Top Activity Sectors (18)
- Finance / Legal / Insurance 426
- Communication / Marketing 320
- Manufacturing / Engineering 170
- Services 128
- Construction / Real Estate 105
- Not identified 75
- Healthcare / Pharma 66
- IT 64
- Energy 39
- Hospitality / Food & Beverage / Tourism 32
- Transportation / Travel / Logistics 32
- Agriculture / Food 31
- Retail / E-commerce 27
- Telecommunications 27
- Education 25
- Public Sector 16
- NGOs / Associations 5
- null 1
Typical Attacks (29)
▼How Akira typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Akira, Akira, Akira _v2.
-
What they do: Akira uses valid account information to remotely access victim networks, such as VPN credentials.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Akira uses compromised VPN accounts for initial access to victim networks.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Akira will leverage COM objects accessed through WMI during execution to evade detection.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Akira has used PowerShell scripts for credential harvesting and privilege escalation.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Akira executes from the Windows command line and can take various arguments for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Akira _v2 can create a child process for encryption.
What that means: Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
-
T1027.001 Binary Padding Stealth
What they do: Akira has used binary padding to obfuscate payloads.
What that means: Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Akira has used legitimate names and locations for files to evade defenses.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1480 Execution Guardrails Stealth
What they do: Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Akira has disabled or modified security tools for defense evasion.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1558 Steal or Forge Kerberos Tickets Credential Access
What they do: Akira have used scripts to dump Kerberos authentication credentials.
What that means: Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
-
T1018 Remote System Discovery Discovery
What they do: Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Akira can identify remote file shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1482 Domain Trust Discovery Discovery
What they do: Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.
What that means: Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
T1654 Log Enumeration Discovery
What they do: Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.
What that means: Adversaries may enumerate system and service logs to find useful data.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Akira has used RDP for lateral movement.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1213.002 Sharepoint Collection
What they do: Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.
What that means: Adversaries may leverage the SharePoint repository as a source to mine valuable information.
-
T1560.001 Archive via Utility Collection
What they do: Akira uses utilities such as WinRAR to archive data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1219 Remote Access Tools Command and Control
What they do: Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Akira will exfiltrate victim data using applications such as Rclone.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Akira encrypts files in victim environments as part of ransomware operations.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Akira _v2 can stop running virtual machines.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Akira will delete system volume shadow copies via PowerShell commands.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1531 Account Access Removal Impact
What they do: Akira deletes administrator accounts in victim networks prior to encryption.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
-
T1657 Financial Theft Impact
What they do: Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (41)
▼Software Akira has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (15)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh |
bitcoin | $997,461 | 2 |
bc1qfdzu6uv2nek524pe7lz4w0mxtt9898vfaegdaj |
bitcoin | $482,181 | 1 |
bc1q0dx45y82r5rt36sm38jv0k4dexwc4nj9z4ryw7 |
bitcoin | $446,073 | 2 |
bc1q9wnp6k7xxdqkdv4fa5ceyhv08espuskhu8ghq2 |
bitcoin | $351,883 | 1 |
bc1qknumj4326runqxfr58kg0s7v7gu9y5v5t9uv6h |
bitcoin | $298,537 | 2 |
bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24 |
bitcoin | $252,389 | 1 |
bc1q0lwpz2yufw3x9as6f679lwk8jx43g44683x5mc |
bitcoin | $229,395 | 4 |
bc1qhzd63mz9mfucak7yzfn65p6rcsgztnsqr3dak8 |
bitcoin | $150,205 | 1 |
bc1qqrsd02sqthm8gej8lfesgpx82saw7q2g5pjtah |
bitcoin | $149,891 | 1 |
bc1q4my6vqq8cg689drf9jccqudjclv67sz4cudkyd |
bitcoin | $139,534 | 1 |
bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh |
bitcoin | $109,655 | 2 |
bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0 |
bitcoin | $106,115 | 2 |
+3 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
akira_readme_3.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. 6. Negotiations with Akira can only be conducted in a chat room, which you can access using the login details provided below or in the notes (a readme.txt file) in your systems. You should ignore any attempts (such as emails/social media messages, phone calls, etc.) to redirect you to another chat or email address (proton.me is often used by unauthorized individuals) on our behalf. 7. Be careful while working with recovery agencies as they often try to use your cyber incident to stuff their pockets. There are many risks for you to lose money and get nothing in return. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme_2.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme.txt
Hi friends, Whatever who you are and what your title is if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining your financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of a deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidently corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of a great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and used in order to get into, identify backup solutions and upload your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion. 5. We're more than negotiable and will definitely find the way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - https://www.torproject.org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion. 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1676)
Search, filter and paginate the victim timeline for Akira. Showing 1–100 of 1676.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Stransky Heiz-Mess-Regeltechnik GmbH id32573 View details | Germany | Manufacturing / Engineering | — | |
|
Stransky Heiz-Mess-Regeltechnik GmbH operates within Germany's manufacturing and engineering sector, providing temperature measurement, control, and regulation technology solutions for industrial applications. The entity is formally listed within the threat-intelligence index under the designation of ransomware victim, associated with the threat actor akira. This classification reflects cybersecurity event documentation concerning this organization without disclosing unverified incident details. The entry serves to inform stakeholders about potential security exposures within the manufacturing ecosystem. It underscores the importance of vigilance for industrial enterprises facing ransomware threats from identified actors. |
|||||
| Ransomware | Stransky Heiz-Mess-Regeltechnik GmbH id32573 View details | Germany | Manufacturing / Engineering | — | |
|
Discover Stransky—a leader in sustainable energy solutions. Trust in over 30 years of experienc e in heating technology and quality. We will upload 50gb of corporate data soon. Employee personal information, contacts and agreeme nts, financials, projects, NDAs and so on. |
|||||
| Ransomware | Worrell id32572 View details | United Kingdom | Services | — | |
|
Worrell operates within the Services sector and is situated in the United Kingdom. The entity provides professional services to clients and stakeholders within its operational domain. Worrell has been formally listed within this threat-intelligence index under the designation of ransomware victim, with its associated threat actor identified as akira. This classification reflects the cybersecurity event documented for the organization without disclosing unverified technical or operational details. The entry serves to inform threat analysts and defenders of the entity's exposure within the indexed threat landscape. |
|||||
| Ransomware | Worrell id32572 View details | United Kingdom | Services | — | |
|
Worrell Corporation is a family-owned business based in Indianapolis that specializes in promot ional products, marketing, and print services. They assist clients in finding impactful promoti onal items while offering tailored marketing strategies and webstore solutions. We will upload 45gb of corporate data soon. Employee and client information, contacts and agree ments, financials, projects and so on. |
|||||
| Ransomware | PennFab id32429 View details | United States | Manufacturing / Engineering | — | |
|
PennFab operates within the United States manufacturing and engineering sectors, providing specialized industrial and engineering solutions tailored to production, design, and operational requirements. As a prominent entity in this field, its inclusion in the threat-intelligence index reflects cybersecurity risk exposure relevant to industrial and engineering organizations. The listing identifies PennFab specifically as a ransomware victim associated with the threat actor akira. This designation contributes contextual intelligence for analysts monitoring industrial-sector threats, ransomware campaigns, and entity-level attack patterns. The description remains factual and neutral, focusing on the entity's sector, geographic presence, and the verified association without disclosing unconfirmed incident details. |
|||||
| Ransomware | PennFab id32429 View details | United States | Manufacturing / Engineering | — | |
|
PennFab is a Pennsylvania-based steel manufacturing company specializing in structural steel fa brication for various industries, including railroad and transportation. They offer a wide rang e of services such as engineering, welding, and custom metal fabrication, ensuring high-quality products made in the USA. We will upload 40gb of corporate data soon. Employee personal information (scanned passports, D Ls, SSNs and so on of 53 employees), clients information, contacts and agreements, financials, NDAs. |
|||||
| Ransomware | ScrubaDub Auto Wash Centers id32417 View details | United States | Services | — | |
|
ScrubaDub Auto Wash Centers operates within the Services sector, providing automotive vehicle cleaning and wash center services to customers in the United States. The entity functions as a commercial auto wash business, offering services such as exterior washing, detailing, and convenience-based vehicle care. This listing type identifies ScrubaDub Auto Wash Centers as a ransomware victim within the threat-intelligence index. The association links the entity to threat actor akira, reflecting cybersecurity incident classification rather than confirmed breach details. The description remains factual and neutral, avoiding invented specifics regarding data theft, ransom demands, or incident timelines. |
|||||
| Ransomware | ScrubaDub Auto Wash Centers id32417 View details | United States | Services | — | |
|
ScrubaDub Car Wash is New England's leading auto wash, offering customizable tunnel and touchle ss washes, interior cleaning, and detailing services across over 20 locations in Massachusetts, New Hampshire, Maine, and Rhode Island. We will upload corporate data soon. Employee personal information (passport numbers, DLs of 22 employees, contact information), clients information (addresses, contacts and so on), company f inancials, payment details. |
|||||
| Ransomware | Algra Group id32418 View details | Netherlands | Services | — | |
|
Algra Group is a company operating within the Services sector, based in the Netherlands (NL). The entity provides professional services aligned with its sector classification, contributing to the broader service economy. It has been formally cataloged within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor akira. This designation reflects its inclusion in records documenting cybersecurity incidents and adversary activity. The description remains factual and neutral, focusing on the entity's profile and its recognized association without elaborating on unconfirmed incident details. |
|||||
| Ransomware | Algra Group id32418 View details | Netherlands | Services | — | |
|
Algra Group specializes in customized input systems, front panels, and industrial labels, provi ding tailored solutions for various industries. Their product range includes agnostic touch sys tems, piezo keyboards, and weightpads, catering to sectors such as food processing, automation, wellness, medical technology, and transportation. We will upload corporate data soon. Employee personal information (passport numbers, DLs), clie nts and partners information, contacts and agreements, financials, NDAs. |
|||||
| Ransomware | Congressional Iron Works id32404 View details | Manufacturing / Engineering | — | ||
|
Congressional Iron Works operates within the Manufacturing and Engineering sector, providing specialized industrial and technical solutions tailored to industrial production and design requirements. As a listed ransomware victim associated with threat actor akira, this entity represents a case documented within the threat-intelligence index for cybersecurity analysis and awareness. The listing type identifies the relationship between the organization and the identified threat actor without disclosing unverified technical details or incident specifics. This catalog entry serves to inform stakeholders about potential security exposures in critical manufacturing and engineering infrastructure. Congressional Iron Works remains cataloged neutrally to support ongoing threat monitoring and defensive intelligence. |
|||||
| Ransomware | Congressional Iron Works id32404 View details | Manufacturing / Engineering | — | ||
|
Congressional Iron Works is a full-service miscellaneous metals contractor serving the commerci al construction industry in the greater Baltimore-Washington area. Established in 2004, the com pany offers a range of services including estimating, drafting, fabrication, and project manage ment, focusing on steel and architectural metals components such as structures, stairs, and can opies. We will upload 35gb of corporate data soon. Employee personal information (passport numbers, SS Ns, DLs, financial information, health information), clients information, company financials, p rojects, NDAs. |
|||||
| Ransomware | Flex1 id32400 View details | United States | IT | — | |
|
Flex1 operates within the IT sector and is identified as a ransomware victim within the threat-intelligence index. The entity is situated in the United States and represents a target profile relevant to cybersecurity monitoring and defense efforts. Its classification as a ransomware victim linked to the threat actor akira provides structured context for analysts tracking adversary activity and impacted organizations. This description maintains factual neutrality regarding the incident without disclosing unverified specifics. Flex1 was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Flex1 id32400 View details | United States | IT | — | |
|
Flex1 is an innovative provider of desktop-as-a-service solutions that enables businesses to cr eate secure and cost-effective digital workspaces. Their platform combines cloud architecture w ith productivity tools and managed support services to ensure employees can work efficiently fr om any device, at any time. We will upload 402gb of corporate data and their client soon. Employee personal information, cl ients information (lawyers clients (passports, DLs, SSNs and so on), pet's clinic, etc), financ ials and so on. |
|||||
| Ransomware | BYK Construction id32401 View details | Germany | Construction / Real Estate | — | |
|
BYK Construction operates within the Construction and Real Estate sector, with operations associated with Germany. The entity provides construction-related services and project development offerings typical to its industry classification. This listing classifies BYK Construction as a ransomware victim within the threat-intelligence index. The association connects the entity to the threat actor akira, reflecting observed cybersecurity incident correlations. The description remains factual and neutral regarding the nature of any potential compromise without asserting unverified breach details. |
|||||
| Ransomware | BYK Construction id32401 View details | United States | Construction / Real Estate | — | |
|
BYK Construction is a trusted home builder based in Mount Vernon, Washington, specializing in r esidential and commercial construction, land development, property management, and home mainten ance. We will upload 27gb of corporate data and their client soon. Employee personal information (pas sport numbers, SSNs, DLs, financial information), clients information, company financials, proj ects (specifications) and so on. |
|||||
| Ransomware | KFZ-MEISTERBETRIEB JOST GmbH id32335 View details | Germany | Manufacturing / Engineering | — | |
|
KFZ-MEISTERBETRIEB JOST GmbH operates within Germany's manufacturing and engineering sector, conducting industrial machinery and equipment-related activities under its corporate name. The entity is formally listed within the threat-intelligence index under the designation ransomware victim, associated with the threat actor akira. This classification reflects the cybersecurity context in which the organization was documented, without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The record serves catalog and intelligence purposes for monitoring threat actor activity across industrial sectors. It neutrally states that KFZ-MEISTERBETRIEB JOST GmbH was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | KFZ-MEISTERBETRIEB JOST GmbH id32335 View details | Germany | Manufacturing / Engineering | — | |
|
KFZ-MEISTERBETRIEB JOST GmbH specializes in the repair and maintenance of all types of motor ve hicles. The company offers comprehensive services in the maintenance, repair, and sale of motor vehicles. We will upload 6gb of corporate data soon. Employee personal information, clients information, financials and so on. |
|||||
| Ransomware | Gale Credit Union id32336 View details | United States | Finance / Legal / Insurance | — | |
|
Gale Credit Union is a financial institution operating within the United States, providing credit union services including deposit accounts, loans, financial products, and member-focused banking solutions across Finance, Legal, and Insurance-adjacent service areas. As a listed ransomware victim associated with threat actor akira, this entry documents the entity's inclusion in the threat-intelligence index without disclosing specific incident details. The catalog description maintains neutrality regarding the nature, scope, or resolution of any potential security event. Gale Credit Union's sector classification underscores the criticality of cybersecurity awareness for financial organizations targeted by ransomware campaigns. |
|||||
| Ransomware | Gale Credit Union id32336 View details | United States | Finance / Legal / Insurance | — | |
|
Gale Credit Union offers a variety of financial products and services including loans, savings and checking accounts, and credit cards. Their intended clients are individuals and businesses residing or working in ten counties in Illinois. We will upload 50gb of corporate data soon. Employee personal information (passport, SSNs, DLs, credit cards and so on), clients and partners information, projects, financials, contracts and agreements and so on. |
|||||
| Ransomware | WEMS id32328 View details | United States | IT | — | |
|
WEMS is cataloged as a ransomware victim within the US IT sector. The entity represents an organization or infrastructure profile relevant to threat-intelligence indexing, where ransomware activity and associated adversary attribution are documented for analytical use. Its classification under the ransomware victim listing type indicates it was identified in relation to threat actor akira, with sector and geographic context provided as IT and United States. This entry supports neutral assessment of exposure patterns, attribution links, and sector-specific threat context without confirming specific breach details. WEMS was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | WEMS id32328 View details | United States | IT | — | |
|
WEMS Electronics is a full-service turn-key small business specializing in state-of-the-art EMI custom filters, engineering, and manufacturing services. The company offers a completely integ rated approach to the design and fabrication of precision electronic components, assemblies, an d subsystems. We will upload 51gb of corporate data soon. Employee personal information, client information, lots of confidential HR files, projects, financials, projects, contrast and agreements, NDAs an d so on. |
|||||
| Ransomware | Alumax id32232 View details | United States | Manufacturing / Engineering | — | |
|
Alumax is a company operating within the United States manufacturing and engineering sector, providing specialized industrial solutions and technical services relevant to production, design, and operational workflows. As a ransomware victim, Alumax has been cataloged within this threat-intelligence index due to its association with threat actor akira. The listing type identifies Alumax specifically as a ransomware victim linked to akira, reflecting the entity’s exposure within the observed threat landscape. This entry provides neutral, factual context regarding the company’s sector, geographic location, and the nature of its relationship with the identified threat actor without speculating on confirmed breach details, data impacts, or operational outcomes. Alumax serves as a reference point for monitoring security implications across manufacturing and engineering environments. |
|||||
| Ransomware | Alumax id32232 View details | United States | Manufacturing / Engineering | — | |
|
Alumax Alumínios specializes in the distribution of aluminum and accessories for the constructi on industry, focusing on providing tailored solutions for builders and metalworkers. The compan y prides itself on its partnership with Hydro, a global leader in sustainable aluminum, allowin g them to offer high-quality products that meet the market's demanding needs. We will upload 58gb of corporate data soon. Detailed employee personal information (passports, IDs, and another personal docs scans), client information, projects, financials, confidential f iles, contrast and agreements, NDAs and so on. |
|||||
| Ransomware | BEPeterson id32234 View details | United States | Services | — | |
|
BEPeterson is a company operating within the Services sector located in the United States. Its catalog entry identifies it specifically as a ransomware victim within the threat-intelligence index. The entity is associated with the threat actor akira, which contextualizes its inclusion in cybersecurity monitoring and incident analysis frameworks. This description focuses on the entity's classification and its verified linkage to the specified actor without disclosing unconfirmed incident details. BEPeterson was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | BEPeterson id32234 View details | United States | Services | — | |
|
BEPeterson is a full-service metal fabricator specializing in custom solutions for vessels, tan ks, and heavy-gauge metal parts since 1935. The company serves a diverse range of industries in cluding defense, medical, energy, and industrial sectors, providing high-quality products throu gh advanced manufacturing techniques. We will upload 20gb of corporate data soon. Employee personal information, client information, projects, financials, NDAs and so on. |
|||||
| Ransomware | JRT Mechanical id32235 View details | India | Manufacturing / Engineering | — | |
|
JRT Mechanical operates within the manufacturing and engineering sector, based in India, providing specialized mechanical solutions and industrial services tailored to production and technical requirements. The entity is documented in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor akira. This classification reflects the cybersecurity context in which the organization was identified, without disclosing unverified incident details such as data accessed, financial impact, or confirmed breach specifics. The entry serves to contextualize JRT Mechanical's operational profile alongside its threat-related designation for analytical and defensive reference. |
|||||
| Ransomware | JRT Mechanical id32235 View details | India | Manufacturing / Engineering | — | |
|
JRT Mechanical is a full-service mechanical contractor specializing in plumbing, HVAC, hydronic s, and mechanical insulation, serving the Pacific Northwest for over 30 years. Founded in 1992, the company has expanded from a small plumbing business to a robust team of over 160 employees , focusing primarily on commercial and industrial projects. We will upload 46gb of corporate data soon. Detailed employee personal information (SSNs, passp orts, DLs, resumes, and another personal docs scans), medical information, client information, projects, financials, confidential files, contrast and agreements, NDAs and so on. |
|||||
| Ransomware | Cetylite id32199 View details | United States | null | — | |
|
Cetylite is cataloged as a ransomware victim within the United States context. Its operational sector is not specified in the provided data, so the entity is described neutrally based on its listing type and associated threat actor rather than inferred activity. The designation identifies Cetylite within a threat-intelligence index as an affected organization or entity connected to the akira threat actor profile. This entry supports security teams in mapping ransomware incidents, tracking actor-associated victims, and maintaining structured intelligence records for risk assessment and situational awareness. |
|||||
| Ransomware | Cetylite id32199 View details | United States | null | — | |
|
Cetylite, Inc. specializes in dental and medical products aimed at enhancing patient comfort, s afety, and satisfaction. Their offerings include exclusive specialty products like Cetacaine fo r dental practices and proprietary Rx and disinfection products for the medical field. We will upload 6gb of corporate data soon. Employee personal information (passports, DLs, SSNs, credit cards), client information, detailed financials, confidential files, NDAs and so on. |
|||||
| Ransomware | CGP MEP id32200 View details | United Kingdom | Manufacturing / Engineering | — | |
|
CGP MEP operates within the Manufacturing and Engineering sector, with headquarters or primary activity associated with the United Kingdom. The entity provides engineering, manufacturing, and related technical services, serving industrial clients and operational workflows. In this threat-intelligence index, CGP MEP is listed as a ransomware victim associated with the threat actor akira. This listing reflects the entity's inclusion in the ransomware victim category tied to akira's activity, without confirming specific incident details such as data exfiltration, ransom demands, or breach scope. The record supports threat-context analysis for sector-relevant organizations in manufacturing and engineering. |
|||||
| Ransomware | CGP MEP id32200 View details | United Kingdom | Manufacturing / Engineering | — | |
|
CGP MEP is a Building Services Consultancy based in London and Leeds, specializing in mechanica l and electrical engineering. They offer a wide range of services across various sectors includ ing leisure, education, residential, and industrial projects. We will upload 260gb of corporate data soon. Detailed employee personal information (passports, DLs, SSNs, personal financials), client information, projects, financials, NDAs and so on. |
|||||
| Ransomware | Seabrook Island id32201 View details | United States | — | — | |
|
Seabrook Island is a location-based entity operating within the United States, associated with threat-intelligence indexing under the ransomware victim classification. Its sector and specific operational profile are contextualized within cybersecurity monitoring frameworks, where such entities are cataloged to understand exposure patterns and attacker targeting behavior. This listing type identifies Seabrook Island as a victim of ransomware activity attributed to the threat actor akira, reflecting the intelligence index's role in mapping real-world incidents to associated actors and geographic contexts. The description remains neutral and factual, focusing on the entity's classification without extrapolating unconfirmed breach details or operational specifics. |
|||||
| Ransomware | Seabrook Island id32201 View details | United States | — | — | |
|
Seabrook Island and its stunning natural beauty create the perfect setting for luxury homes enj oying oceanfront, riverfront, tidal marsh, golf course, and maritime forest views. We will upload 55gb of corporate data soon. Employee personal information (passports, DLs, SSNs , personal financials), client information, projects, financials, NDAs and so on. |
|||||
| Ransomware | Gill Rock Drill id32145 View details | United States | Manufacturing / Engineering | — | |
|
Gill Rock Drill is a company operating within the United States manufacturing and engineering sectors, specializing in industrial tooling, drilling solutions, and related engineering services. The entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor akira. This listing type indicates the organization was identified within cybersecurity intelligence records as a target of malicious activity linked to akira. The description focuses on the entity’s operational profile and its verified association with the specified threat actor without disclosing unconfirmed incident details. Neutral documentation supports threat-aware cataloging and sector-specific risk analysis. |
|||||
| Ransomware | Gill Rock Drill id32145 View details | United States | Manufacturing / Engineering | — | |
|
Gill Rock Drill Company, Inc., located in Lebanon, PA, is a family-owned manufacturer and distr ibutor specializing in drilling equipment and tools for the drilling industry. The company offe rs a range of services including contract drilling, rentals, and technical support, focusing on building strong customer relationships based on integrity and trust. We will upload 5gb of corporate data soon. Employee personal information (passports, DLs, w-9 c omplete forms), client information, financials, payment details, CCs, NDAs and so on. |
|||||
| Ransomware | Oral and Maxillofacial Surgery id32146 View details | Healthcare / Pharma | — | ||
|
Oral and Maxillofacial Surgery is a specialized healthcare discipline within Medicine focused on diagnosing, preventing, and treating conditions affecting the mouth, jaw, face, salivary glands, and associated structures. Practitioners provide surgical interventions such as tooth extractions, jaw reconstruction, facial trauma repair, implant placement, and management of cysts or tumors in these regions. The entity operates within the Healthcare sector, delivering clinical services typically in outpatient or hospital settings. It was listed as a ransomware victim associated with threat actor akira. This entry reflects threat-intelligence indexing of an affected organization without confirming specific breach details. |
|||||
| Ransomware | Oral and Maxillofacial Surgery id32146 View details | Healthcare / Pharma | — | ||
|
Oral and maxillofacial surgeons Dr. Catrambone and Dr. August , Brockton, MA practice a full sc ope of oral and maxillofacial surgery with expertise ranging from corrective jaw surgery to wis dom tooth removal. We will upload 14gb of corporate data soon. Employee personal information (passports, phone con tacts), client information, financials, patients and so on. |
|||||
| Ransomware | PA-ID id32147 View details | Other | — | ||
|
PA-ID is cataloged as a ransomware victim within the Other sector. As a threat-intelligence index entry, it documents the entity's classification alongside its association with threat actor akira. The listing type identifies PA-ID specifically as a ransomware victim, providing structured context for analysts tracking cyber incidents and actor-victim relationships. Sector classification under Other reflects the broad operational category assigned to this entity in the index. This description neutrally states that PA-ID was listed as a ransomware victim associated with akira, adhering to factual and neutral reporting standards without inventing incident details. |
|||||
| Ransomware | PA-ID id32147 View details | Other | — | ||
|
PA-ID GmbH specializes in mechanical construction and manufacturing, building series and custom systems, as well as electrical design and the development of tailored industrial software. We will upload 119gb of corporate data soon. Employee personal information (passports, ID's), c lient information, financials, NDAs and so on. |
|||||
| Ransomware | WINTER Ingenieure id32097 View details | Germany | Manufacturing / Engineering | — | |
|
WINTER Ingenieure is a company operating within the Manufacturing and Engineering sector, headquartered or associated with Germany. The entity provides engineering and technical solutions typical to industrial and manufacturing environments. It is formally listed in this threat-intelligence index under the designation ransomware victim, with the associated threat actor or source identified as akira. The listing reflects the entity's classification within cybersecurity intelligence records for monitoring and risk assessment purposes. No specific incident details, such as data stolen or ransom demands, are included per strict factual disclosure guidelines. |
|||||
| Ransomware | WINTER Ingenieure id32097 View details | Germany | Manufacturing / Engineering | — | |
|
WINTER Ingenieure specializes in planning and monitoring the construction of technical building equipment across Germany, focusing on functionality, sustainability, and cost-effectiveness. W ith a team of over 140 employees located in Düsseldorf, Berlin, and Hamburg, they integrate tec hnical components into buildings innovatively. We will upload 340gb of corporate data soon. Employee personal information (German passports, I Ds, addresses, phones contacts), confidential files, projects, lots of specifications and so on . |
|||||
| Ransomware | Davis & Ferber id32099 View details | United States | Retail / E-commerce | — | |
|
Davis & Ferber is a company operating within the United States retail and e-commerce sectors, providing commercial goods and related services. The entity is cataloged as a ransomware victim within the threat-intelligence index, indicating its inclusion due to a cybersecurity incident involving ransomware activity. Its classification reflects the sector-specific exposure common in retail and e-commerce environments to digital threats. The listing associates Davis & Ferber with threat actor akira, providing context for threat-researcher and security-professional analysis. This description avoids speculative claims regarding data handling, breach confirmation, or operational impact, maintaining a neutral and authoritative tone consistent with threat-intelligence documentation. |
|||||
| Ransomware | Davis & Ferber id32099 View details | United States | Retail / E-commerce | — | |
|
Davis & Ferber LLP is a personal injury and malpractice law firm based in New York, specializin g in various legal areas including medical malpractice, motor vehicle accidents, nursing home a buse, and family law. We will upload 60gb of corporate data soon. Detailed personal client information (passports, DL s, addresses, SSNs, death/birth certs, phones and so on for almost a thousand people), confiden tial files, court files, hearings, police reports, NDAs, etc. |
|||||
| Ransomware | Bihl id32072 View details | Germany | Manufacturing / Engineering | — | |
|
Bihl operates within the manufacturing and engineering sector, based in Germany, providing specialized industrial and technical solutions relevant to production and design workflows. The entity is formally listed within this threat-intelligence index under the designation ransomware victim, with its associated threat actor and source identified as akira. This classification reflects the cybersecurity context in which Bihl was documented, highlighting its exposure profile within industrial sectors targeted by ransomware campaigns. The entry serves to inform threat analysts and defenders about the relationship between this organization and the akira threat actor without disclosing unverified incident details. Bihl remains cataloged as a ransomware victim associated with akira. |
|||||
| Ransomware | Bihl id32072 View details | Germany | Manufacturing / Engineering | — | |
|
Boustead International Heaters (BIH) is a leading global designer and supplier of thermal proce ss equipment, including direct fired heaters, waste heat recovery units (WHRUs), and heat recov ery steam generators (HRSGs). We will upload 392gb of corporate data soon. Huge amount of detailed personal employee informat ion (passports, DLs, addresses, SSNs, death/birth certs, phones, contacts), confidential financ ials and agreements and contracts, client information, NDAs and so on. |
|||||
| Ransomware | JC Sales id31966 View details | United States | — | — | |
|
JC Sales is a leading full-service wholesaler based in Los Angeles, California, specializing in a vast array of wholesale products including health and beauty items, food and beverages, gene ral merchandise, and seasonal items. We will upload 206gb of corporate data soon. Detailed personal employee information (passports, DLs, addresses, phones, contacts), confidential financials, contracts and agreements, client i nformation, NDAs and so on. |
|||||
| Ransomware | Cascade Coffee id31848 View details | — | — | ||
|
Cascade Coffee is a premier gourmet coffee contract manufacturer based near Seattle, Washington , specializing in roasting, grinding, flavoring, and packaging coffee. The company caters to so me of the world's finest coffee brands, providing a wide range of products including whole bean , ground, flavored coffees, and specialty blends. We will upload corporate data soon. Detailed personal employee information (passports, DLs, add resses, phones, car information), details, financials, contracts and agreements, NDAs and so on . |
|||||
| Ransomware | Cascade Coffee id31848 View details | United States | — | — | |
|
Cascade Coffee is a premier gourmet coffee contract manufacturer based near Seattle, Washington , specializing in roasting, grinding, flavoring, and packaging coffee. The company caters to so me of the world's finest coffee brands, providing a wide range of products including whole bean , ground, flavored coffees, and specialty blends. We will upload corporate data soon. Detailed personal employee information (passports, DLs, add resses, phones, car information), details, financials, contracts and agreements, NDAs and so on . |
|||||
| Ransomware | Deas Millwork id31854 View details | — | — | ||
|
Deas Millwork specializes in architectural design elements, offering custom millwork solutions for various projects. They focus on creating high-quality craftsmanship that serves as the cent erpiece of any design. We will upload corporate data soon. Employee personal information (passports, DLs, addresses, p hones, emails and other information), financials, contracts and agreements and so on. |
|||||
| Ransomware | Ericksen Krentel id31886 View details | — | — | ||
|
Ericksen Krentel CPAs and Consultants is a New Orleans-based CPA firm offering a wide range of services including tax, accounting, audit, advisory, and consulting for both businesses and ind ividuals. Their expertise spans various industries such as construction, healthcare, hospitalit y, maritime, and nonprofit sectors. We will upload 30gb of corporate data soon. Detailed client and employee personal information ( passports, DLs, SSNs, addresses and other information), detailed financials, confidential docum ents, contracts and agreements, NDAs and so on. |
|||||
| Ransomware | Borchert & LaSpina id31829 View details | — | — | ||
|
Borchert & LaSpina, P.C. is a respected law firm located in Queens, New York, with a team of si x experienced attorneys specializing in various areas of law including real estate, mortgage fo reclosure, commercial litigation, personal injury, and elder law. We will upload corporate data soon. Client personal information (lots of passports, DLs, SSNs a nd other information), financials, confidential legal files, contracts and so on. |
|||||
| Ransomware | Keystops id31716 View details | — | — | ||
|
Key Oil Company is the largest distributor of branded motor fuels for Marathon Petroleum Compan y and also holds contracts with major brands like ExxonMobil and ConocoPhillips. They provide a wide range of products including lubricants, diesel exhaust fluid, antifreeze, and various fue l delivery solutions. We will upload 15gb corporate data soon. Employee and client personal information (NAME, PASSPO RT, DL, SSN and so on), financials, payment details, contracts and agreements and so on. |
|||||
| Ransomware | Keystops id31716 View details | United States | — | — | |
|
Key Oil Company is the largest distributor of branded motor fuels for Marathon Petroleum Compan y and also holds contracts with major brands like ExxonMobil and ConocoPhillips. They provide a wide range of products including lubricants, diesel exhaust fluid, antifreeze, and various fue l delivery solutions. We will upload 15gb corporate data soon. Employee and client personal information (NAME, PASSPO RT, DL, SSN and so on), financials, payment details, contracts and agreements and so on. |
|||||
| Ransomware | Cozad Asset Management id31717 View details | United States | — | — | |
|
Cozad Asset Management, Inc. provides the highest quality professional and personalized financi al services and advice to individuals, families and institutional investors throughout the coun try. We will upload 13gb corporate data soon. Employee personal information (passport, DLs, SSN), fi nancials, confidential files, contracts and agreements, legal files and so on. |
|||||
| Ransomware | CF Supply id31663 View details | Other | — | ||
|
CF Supply operates in the other sector, providing various offerings to its customers. The company is likely based in the United States, given its name and sector. CF Supply was listed as a ransomware victim associated with akira |
|||||
| Ransomware | CF Supply id31663 View details | Other | — | ||
|
CF Supply is a Texas-based company that offers a wide range of construction products including drywall, metal framing, insulation, and door hardware. They provide services such as free estim ates and 24-hour online account access, ensuring convenience for their clients. We will upload corporate data soon. Client information (projects, personal information and so o n), contracts and agreements and so on. |
|||||
| Ransomware | Alcast id31533 View details | — | — | ||
|
ALCAST is a leading aluminum casting company specializing in precision casting, sand casting, a nd die casting. They provide high-quality aluminum castings for various industries, including a griculture, defense, heavy equipment, and marine. We will upload 170gb corporate data soon. Employee personal files (passport, DLs, SSNs, address es and so on), projects, customers information, contracts and agreements and so on. |
|||||
| Ransomware | One Vision Imaging id31530 View details | — | — | ||
|
One Vision Imaging are a team that are passionate about the process of photographic printing an d framing. This is why we started over 40-years ago. Many of our staff are photo enthusiasts or working photographers in their spare time. We will upload 180gb corporate data soon. Employee personal information and other HR files, sou rces, contracts and agreements, clients information and so on. |
|||||
| Ransomware | i4 Solutions id31531 View details | — | — | ||
|
i4 Solutions has created thousands of Websites for companies all over the world! i4 Solutions c reates custom websites and prides itself that all work is done by i4 employees not outsources c ontractors. We will upload 170gb corporate data soon. Lots of working files, projects and so on. |
|||||
| Ransomware | Basic Grain Products id31375 View details | United States | Agriculture / Food | — | |
|
Basic Grain Products is a company operating in the agriculture and food sector in the US, likely involved in the production and distribution of grain-based products. As a part of this sector, the company plays a role in the food supply chain. Basic Grain Products was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Basic Grain Products id31375 View details | United States | Agriculture / Food | — | |
|
TasteMorr is a culinary platform that offers a variety of gourmet food products and cooking ser vices. The company aims to cater to food enthusiasts and home cooks looking for high-quality in gredients and unique recipes. We will upload 104gb corporate data soon. Employee personal information (passports and SSNs, w9 forms and so on), detailed financials, contracts and agreements, NDA, clients information and so on. |
|||||
| Ransomware | Pharma Test Apparatebau AG id31372 View details | Switzerland | Manufacturing / Engineering | — | |
|
Pharma Test Apparatebau AG is a company based in Switzerland, operating in the manufacturing and engineering sector. The company likely produces equipment and machinery for the pharmaceutical industry, given its name. Pharma Test Apparatebau AG was listed as a ransomware victim associated with akira |
|||||
| Ransomware | Pharma Test Apparatebau AG id31372 View details | Switzerland | Manufacturing / Engineering | — | |
|
Pharma Test is an internationally leading manufacturer and household name for the development a nd production of high-value test devices and systems. They offer a complete product range from manual, physical testing instruments to fully automated, analytical test systems to analyze the active chemical composition of a dosage form as well as its release rate. We will upload 46gb corporate data soon. Employee personal information (passports and so on), f inancials, contracts and agreements, NDA, clients information and so on. |
|||||
| Ransomware | University SprinklerSystems id31207 View details | Manufacturing / Engineering | — | ||
|
University SprinklerSystems is a company operating in the manufacturing and engineering sector, providing sprinkler systems for various applications. The company's offerings likely include design, installation, and maintenance services for its products. University SprinklerSystems was listed as a ransomware victim associated with akira |
|||||
| Ransomware | University SprinklerSystems id31207 View details | Manufacturing / Engineering | — | ||
|
University Sprinklers is BC's largest irrigation company, specializing in the installation of irrigation sprinkler systems and landscape lighting for both residential and commercial client s. With over 40 years of experience, they provide tailored irrigation solutions that ensure he althy lawns and gardens while conserving water. Here is the access to upload company data. Employee information (DLs and other files), client information and and other internal files. Click the download button. You will find several password-free archives. Click on any of them to start the download. |
|||||
| Ransomware | Albers Mechanical Contractors id31181 View details | United States | Construction / Real Estate | — | |
|
Albers Mechanical Contractors is a US-based company operating in the construction and real estate sector, providing mechanical contracting services. The company's offerings likely include HVAC, plumbing, and other mechanical systems installation and maintenance. Albers Mechanical Contractors was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Albers Mechanical Contractors id31181 View details | United States | Construction / Real Estate | — | |
|
Albers Mechanical Contractors specializes in custom fabrication, welding, stainless steel fabri cation, and dust collection HVAC solutions. With over 54 years of experience, they provide desi gn and on-site consultations, positioning themselves as leaders in facility solutions. We will upload 30gb corporate data soon. Employee information, financials, contracts and agreem ents, NDA, customers information, etc. |
|||||
| Ransomware | Belasco Electric id31182 View details | United States | Manufacturing / Engineering | — | |
|
Belasco Electric is a US-based company operating in the manufacturing and engineering sector, providing various electrical products and services. The company is involved in the design, development, and production of electrical systems and components. Belasco Electric was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Belasco Electric id31182 View details | United States | Manufacturing / Engineering | — | |
|
Belasco Electric is a reliable electrical service provider based in Muskegon, Michigan, caterin g to both residential and commercial clients. They offer a wide range of services including eme rgency generator systems, fire alarm security systems, HVAC wiring, and EV installation. We will upload 16gb corporate data soon. Employee information (name, home addresses, passport, SSN, DL numbers, photos, credit card scans and so on), financials, contracts and agreements, ND A, etc. |
|||||
| Ransomware | Northwood Country Club id31025 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Northwood Country Club is a hospitality and tourism establishment in the US, offering various services and amenities to its members and guests. As part of the food and beverage sector, it provides a range of dining and recreational options. Northwood Country Club was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Northwood Country Club id31025 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Northwood Country Club is a private club located in Meridian, Mississippi, known for its beauti ful facilities and convenient city location. The club offers a range of amenities including cha mpionship golf, clubhouse dining, swimming pool, tennis, and fitness services. We will upload corporate data soon. Employee information (name, home addresses, contacts (emerg ency ones) and so on), financials, contracts and agreements, etc. |
|||||
| Ransomware | Franz Krause artworksgroup id31014 View details | Germany | Other | — | |
|
Franz Krause artworksgroup is an entity based in Germany, operating in the other sector. The group likely offers various services or products, given its categorization. Franz Krause artworksgroup was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Franz Krause artworksgroup id31014 View details | Germany | Other | — | |
|
Franz Krause artworksgroup is a streamlined agency that leverages extensive experience in media and event management to deliver high-quality services while maintaining budget efficiency. The company emphasizes strong relationships and a commitment to client satisfaction. We will upload 81gb of corporate data soon. Employee information, detailed client information, financials, contracts and agreements, NDAs, confidential files, etc. |
|||||
| Ransomware | Franz Krause artworksgroup id31014 View details | United States | Other | — | |
|
Franz Krause artworksgroup is a streamlined agency that leverages extensive experience in media and event management to deliver high-quality services while maintaining budget efficiency. The company emphasizes strong relationships and a commitment to client satisfaction. We will upload 81gb of corporate data soon. Employee information, detailed client information, financials, contracts and agreements, NDAs, confidential files, etc. |
|||||
| Ransomware | Emerge2 Digital id30824 View details | United States | IT | — | |
|
Emerge2 Digital is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to its clients. Emerge2 Digital was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Emerge2 Digital id30824 View details | United States | IT | — | |
|
Emerge2 Digital specializes in providing digital marketing solutions tailored for dealer groups , retailers, distributors, and manufacturers. Since 1980, the company has been dedicated to hel ping clients enhance their digital presence and connect with more customers through turnkey sol utions and managed services. We will upload 30gb of corporate data soon. Employee information (passports and other docs), de tailed client information, financials, contracts and agreements and so on. |
|||||
| Ransomware | Emerge2 Digital id30824 View details | Canada | IT | — | |
|
Emerge2 Digital specializes in providing digital marketing solutions tailored for dealer groups , retailers, distributors, and manufacturers. Since 1980, the company has been dedicated to hel ping clients enhance their digital presence and connect with more customers through turnkey sol utions and managed services. We will upload 30gb of corporate data soon. Employee information (passports and other docs), de tailed client information, financials, contracts and agreements and so on. |
|||||
| Ransomware | Kruse Construction id30744 View details | United States | Construction / Real Estate | — | |
|
Kruse Construction is a US-based company operating in the construction and real estate sector, providing various services. The company is involved in building and development projects. Kruse Construction was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Kruse Construction id30744 View details | United States | Construction / Real Estate | — | |
|
Kruse Construction is a mechanical contractor with over 50 years of experience in the petroleum and petrochemical industry, specializing in the construction and maintenance of liquid petrole um truck, rail, and pipeline terminals. The company also provides services for bulk plants, pip eline pump stations, lube oil plants, and underground pipelines. We will upload 10gb corporate data soon. Employee information (passports, lots of DLs), project s, contracts, financials, customer files and so on. |
|||||
| Ransomware | University Sprinkler Systems id30745 View details | United States | Construction / Real Estate | — | |
|
University Sprinkler Systems is a company operating in the construction and real estate sector in the US, providing services related to sprinkler systems. The company's offerings likely include installation, maintenance, and repair of sprinkler systems for various properties. University Sprinkler Systems was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | University Sprinkler Systems id30745 View details | United States | Construction / Real Estate | — | |
|
University Sprinklers is BC's largest irrigation company, specializing in the installation of i rrigation sprinkler systems and landscape lighting for both residential and commercial clients. With over 40 years of experience, they provide tailored irrigation solutions that ensure healt hy lawns and gardens while conserving water. We will upload corporate data soon. Employee information (DLs and other files), client informat ion and and other internal files. |
|||||
| Ransomware | University Sprinkler Systems id30745 View details | Canada | Construction / Real Estate | — | |
|
University Sprinklers is BC's largest irrigation company, specializing in the installation of i rrigation sprinkler systems and landscape lighting for both residential and commercial clients. With over 40 years of experience, they provide tailored irrigation solutions that ensure healt hy lawns and gardens while conserving water. We will upload corporate data soon. Employee information (DLs and other files), client informat ion and and other internal files. |
|||||
| Ransomware | Novasport s.r.o. id30728 View details | Czechia | Retail / E-commerce | — | |
|
Novasport s.r.o. operates in the retail and e-commerce sector, providing various products and services to customers in the Czech Republic. As a company in the retail and e-commerce space, Novasport s.r.o. is involved in the sale and distribution of goods through online and offline channels. Novasport s.r.o. was listed as a ransomware victim associated with akira |
|||||
| Ransomware | Novasport s.r.o. id30728 View details | Czechia | Retail / E-commerce | — | |
|
Novasport spol. s r.o. We are a global manufacturer of LEKI brand ski, hiking, and Nordic walki ng poles. Novasport was founded in 1992 by Klaus Lenhart, the owner of the LEKI brand. LEKI has a long history of collaborating with the world’s top athletes. We will upload 17gb corporate data soon. Detailed employee information (passports and other inf ormation), projects, contracts, financials, clients information and so on. |
|||||
| Ransomware | Finer & Finer id30727 View details | Other | — | ||
|
Finer & Finer operates in the other sector, providing various offerings. The company is involved in activities related to its sector, although specific details about its location and services are not readily available. Finer & Finer was listed as a ransomware victim associated with akira |
|||||
| Ransomware | Finer & Finer id30727 View details | Other | — | ||
|
Finer & Finer CPA is a leading accounting firm based in Randolph, MA, offering a wide range of services including tax preparation, personal financial planning, and business accounting. They cater to business owners, executives, and independent professionals, providing personalized and professional attention to each client. We will upload 50gb corporate data soon. Employee information (personal docs and health informa tion, tests and so on), contracts, client information and other internal information. |
|||||
| Ransomware | Finer & Finer id30727 View details | United States | Other | — | |
|
Finer & Finer CPA is a leading accounting firm based in Randolph, MA, offering a wide range of services including tax preparation, personal financial planning, and business accounting. They cater to business owners, executives, and independent professionals, providing personalized and professional attention to each client. We will upload 50gb corporate data soon. Employee information (personal docs and health informa tion, tests and so on), contracts, client information and other internal information. |
|||||
| Ransomware | McKeever , Varga & Senko id30698 View details | Finance / Legal / Insurance | — | ||
|
McKeever, Varga & Senko operates within the finance, legal, and insurance sector, providing services to clients. The entity's specific location and offerings are not publicly disclosed. McKeever, Varga & Senko was listed as a ransomware victim associated with akira |
|||||
| Ransomware | McKeever , Varga & Senko id30698 View details | Finance / Legal / Insurance | — | ||
|
McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio r client service and professional guidance. They offer a range of services including informativ e articles, interactive financial calculators, and links to external resources to assist their clients. We will upload 12gb of corporate data soon. Detailed client internal data, employee personal in formation, contracts and agreements, confidential files, NDAs, etc. |
|||||
| Ransomware | McKeever , Varga & Senko id30698 View details | United States | Finance / Legal / Insurance | — | |
|
McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio r client service and professional guidance. They offer a range of services including informativ e articles, interactive financial calculators, and links to external resources to assist their clients. We will upload 12gb of corporate data soon. Detailed client internal data, employee personal in formation, contracts and agreements, confidential files, NDAs, etc. |
|||||
| Ransomware | L&A Transport id30699 View details | Transportation / Travel / Logistics | — | ||
|
L&A Transport operates in the transportation sector, providing logistics services. The company is involved in the movement of goods and people, facilitating trade and commerce. L&A Transport was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | L&A Transport id30699 View details | Transportation / Travel / Logistics | — | ||
|
L & A Transport is a reputable trucking company with over 50 years of experience in providing a wide range of shipping services, including international shipping, white glove handling, and l ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads, less than container truckloads, and offer warehousing services in Union, NJ. We will upload corporate data soon. Detailed financials, employee information (DLs and so on), contracts, client information, NDAs, etc. |
|||||
| Ransomware | L&A Transport id30699 View details | United States | Transportation / Travel / Logistics | — | |
|
L & A Transport is a reputable trucking company with over 50 years of experience in providing a wide range of shipping services, including international shipping, white glove handling, and l ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads, less than container truckloads, and offer warehousing services in Union, NJ. We will upload corporate data soon. Detailed financials, employee information (DLs and so on), contracts, client information, NDAs, etc. |
|||||
| Ransomware | Westcoast Communication Services id30640 View details | United Kingdom | Telecommunications | — | |
|
Westcoast Communication Services is a telecommunications company based in the United Kingdom, providing various communication services. The company operates in the telecommunications sector, offering services to clients in GB. Westcoast Communication Services was listed as a ransomware victim associated with akira. |
|||||
| Ransomware | Westcoast Communication Services id30640 View details | United Kingdom | Telecommunications | — | |
|
Westcoast Communication Services is a leading expert in low voltage and structured cabling, spe cializing in voice and data cabling solutions across Florida. They offer a range of services in cluding network integration, telecommunication networks, and access control systems. We will upload 20gb of corporate data soon. Employee personal information (DL, passports, SS ca rd scans and so on), contracts and agreements, customer info, financials, confidential agreemen ts, etc. |
|||||
| Ransomware | Westcoast Communication Services id30640 View details | United States | Telecommunications | — | |
|
Westcoast Communication Services is a leading expert in low voltage and structured cabling, spe cializing in voice and data cabling solutions across Florida. They offer a range of services in cluding network integration, telecommunication networks, and access control systems. We will upload 20gb of corporate data soon. Employee personal information (DL, passports, SS ca rd scans and so on), contracts and agreements, customer info, financials, confidential agreemen ts, etc. |
|||||
| Ransomware | Nesco Bus Maintenance id30641 View details | United States | Transportation / Travel / Logistics | — | |
|
Nesco Bus Maintenance is a company operating in the transportation sector in the US, providing bus maintenance services. The company is involved in the upkeep and repair of buses, ensuring they are safe and operational for transportation purposes. Nesco Bus Maintenance was listed as a ransomware victim associated with akira |
|||||
| Ransomware | Nesco Bus Maintenance id30641 View details | United States | Transportation / Travel / Logistics | — | |
|
Nesco Bus specializes in manufacturing and maintaining a wide range of buses, including school, childcare, activity, commercial, and specialty buses. With over three decades of experience, t hey are committed to providing exceptional customer support and ensuring the safety and comfort of their passengers. We will upload 26gb of corporate data soon. Employee personal information (DL scans and so on), contracts and agreements, customer info, payment details and other financial docs, etc. |
|||||
| Ransomware | Plumley Engineering id30610 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Plumley Engineering is a company based in the United Kingdom, operating in the manufacturing and engineering sector. The company likely provides various engineering services and products to its clients. Plumley Engineering was listed as a ransomware victim associated with akira |
|||||