Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

June 13, 2026

Transform Specs into Agent Evals with ASSERT

June 12, 2026

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Akira Ransomware Group Earned $244 Million in Ransom Profits
Cybercrime and Ransomware

Akira Ransomware Group Earned $244 Million in Ransom Profits

Staff WriterBy Staff WriterNovember 15, 2025No Comments3 Mins Read3 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Top Highlights

  1. The Akira ransomware group has generated over $244 million through attacks targeting critical infrastructure since March 2023, mainly exploiting vulnerabilities in VMware ESXi, Nutanix AHV, SonicWall, Veeam, and Cisco devices.
  2. They utilize a variety of techniques, including password spraying, exploiting publicly disclosed vulnerabilities, stolen credentials, and brute-force attacks on VPNs and routers to gain initial access.
  3. Once inside, they establish footholds by creating admin accounts, escalating privileges via Veeam vulnerabilities, and moving laterally with tools like AnyDesk, LogMeIn, and RDP, often uninstalling endpoint detection to evade detection.
  4. The group exfiltrates data rapidly—within hours—before executing ransomware payloads that encrypt files and leave ransom notes, targeting enterprise and infrastructure environments globally.

The Core Issue

The Akira ransomware group has amassed over $244 million by conducting sophisticated cyberattacks primarily targeting organizations with critical infrastructure across North America, Europe, and Australia. Since March 2023, the group has specialized in encrypting virtualization servers such as VMware ESXi and Nutanix AHV, exploiting known vulnerabilities like CVE-2024-40766 in SonicWall firewalls, and leveraging stolen credentials, brute-force techniques, and other vulnerabilities in Cisco, Windows, VMware, and Veeam systems to gain access. Their tactics include deploying malicious scripts, creating admin accounts, exploiting backups, and unhooking security detection tools to deepen their foothold.

Once inside, they typically escalate privileges quickly—sometimes within hours—by copying sensitive files like the NTDS.dit and SYSTEM hive to compromise domain administrator accounts, then encrypt a victim’s data with custom extensions such as .akira and .powerranges, while leaving ransom notes. The story of these attacks is primarily told by government agencies in the US, France, Germany, and the Netherlands, which have issued advisories detailing these techniques and emphasizing the threat posed by Akira’s expanding arsenal and relentless pursuit of financial gain. This narrative underscores how intentional vulnerabilities, coupled with advanced tactics, enable the group to exfiltrate and encrypt critical data efficiently, causing significant disruption to targeted organizations.

Potential Risks

The notorious Akira Ransomware Group’s staggering $244 million haul underscores a harsh reality: any business, regardless of size or industry, is vulnerable to a devastating cyberattack that can cripple operations, compromise sensitive data, and inflict substantial financial loss. Such ransomware incidents can lock crucial systems, halt productivity, and force businesses to pay hefty ransoms—or face prolonged downtime and reputation damage—while exposing confidential information to malicious actors. As cybercriminals continually refine their tactics, your enterprise’s defenses must be equally sophisticated; neglecting this risk leaves your organization exposed to the same catastrophic outcome that has million-dollar consequences elsewhere, demonstrating that cybersecurity is not just a technical issue but a critical business imperative.

Possible Next Steps

Addressing ransomware threats promptly is critical to minimizing financial loss, protecting sensitive data, and maintaining trust. Delays in remediation can lead to expanded breaches, increased costs, and long-term damage to an organization’s reputation.

Containment and Eradication

  • Isolate affected systems to prevent further spread
  • Identify and eliminate malicious files and tools

Assessment and Analysis

  • Conduct comprehensive incident analysis to determine scope
  • Evaluate impacted assets and data

Recovery and Restoration

  • Restore systems from secure backups
  • Verify integrity before bringing systems online

Communication and Notification

  • Inform stakeholders and regulatory bodies as required
  • Maintain transparent communication with employees and clients

Improvement and Prevention

  • Patch vulnerabilities exploited by attackers
  • Implement enhanced detection and response strategies
  • Conduct regular security training for staff

Continue Your Cyber Journey

Discover cutting-edge developments in Emerging Tech and industry Insights.

Understand foundational security frameworks via NIST CSF on Wikipedia.

Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.

Cyberattacks-V1cyberattack-v1-multisource

Akira CISO Update cyber risk cybercrime Cybersecurity MX1 Ransomware risk management
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRevolutionizing Cybersecurity: The AI Workforce Shift
Next Article China’s ‘Autonomous’ AI Hacks Still Rely on Heavy Human Effort
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Transform Specs into Agent Evals with ASSERT

June 12, 2026

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026

Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets

June 12, 2026

Comments are closed.

Latest Posts

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026

Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets

June 12, 2026

Conti Ransomware Member Faces 20 Years After Guilty Plea

June 12, 2026

Fancy Bear Exploits EdgeRouters and Cloud Services for Stealth Cyberattacks

June 12, 2026
Don't Miss

Transform Specs into Agent Evals with ASSERT

By Staff WriterJune 12, 2026

ASSERT transforms natural-language behavioral specifications into detailed, executable evaluation pipelines by automatically generating test cases,…

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026

Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets

June 12, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security
  • Transform Specs into Agent Evals with ASSERT
  • FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost
  • Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets
  • Conti Ransomware Member Faces 20 Years After Guilty Plea
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

June 13, 2026

Transform Specs into Agent Evals with ASSERT

June 12, 2026

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202633 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202528 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.