Threat actor
Akira
FBI, CISA and international partners say Akira ransomware actors have hit a wide range of businesses and critical infrastructure entities in North America, Europe and Australia since March 2023.Source [1]
What authorities and investigators report
- The November 2025 update says Akira actors primarily target small and medium-sized businesses, with a notable preference for educational institutions and organizations in sectors such as critical manufacturing and information technology.Source [1]
- The FBI and researchers observed Akira actors gaining initial access through VPN services that did not have multifactor authentication configured, mostly by exploiting known vulnerabilities.Source [1]
- The advisory says Akira actors also used spearphishing and valid credentials for initial access, and used password spraying tools such as SharpDomainSpray to gain account credentials.Source [1]
- According to the authoring organizations and open source reporting, Akira actors attempted to establish persistence by creating new domain accounts, used post-exploitation techniques such as Kerberoasting, and used credential scraping tools like Mimikatz to aid privilege escalation.Source [1]
- The advisory says that, after exfiltrating data, Akira actors used a double-extortion model: encrypting systems and threatening to leak sensitive information.Source [1]
Techniques
Attack vectors
Sources
- #StopRansomware: Akira Ransomware (AA24-109A) — CISA, 2025-11-13
Last reviewed Oct 2, 2026