Akira is a prolific Ransomware-as-a-Service (RaaS) threat group that has risen to prominence since its emergence in March
2023. By early 2024 the group had already impacted over 250 organisations worldwide and amassed an estimated
$42 million in ransom payments. In 2025, Akira’s operations have only intensified – the group is now consistently among
the most active ransomware actors, regularly posting dozens of new victims to its data leak site each month.
Akira specialises in double-extortion attacks, stealing sensitive data and encrypting systems, then threatening to publish the data
if victims refuse to pay. Their campaigns target a wide range of industries and geographic regions, with a concentration in
North America and other Western countries. Akira’s aggressive tactics and rapidly evolving techniques have enabled it to
inflict serious damage on businesses, including critical infrastructure operators and public institutions. Notably, the group’s
attacks this year have ranged from opportunistic mass-exploitation campaigns to carefully orchestrated intrusions that
brought entire companies to collapse.

Download this report










