
THREAT‑WATCH
Threat Actors
Akira
A closed ransomware-as-a-service operation active since April 2023 that became one of the most prolific ransomware groups globally by ransom proceeds in 2025.
Akira uses the standard double-extortion model, encrypting systems while also stealing data to pressure payment. The group generated an estimated $150 million in 2025 alone and has shown a consistent ability to adapt its targeting and tooling in response to law enforcement pressure. Activity has continued to accelerate into 2026, with monthly victim counts posted on its leak site more than doubling between February and March 2026.
Target Sectors
Manufacturing, professional services, healthcare, and education, with a pattern of exploiting VPN and remote-access vulnerabilities for initial access.