Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Rise in online radicalization fuels cyber-physical threat escalation

August 22, 2026

Empowering Defenders with OpenAI Cyber Models

August 21, 2026

Apollo suffers social engineering breach exposing sensitive data

August 21, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Akira Ransomware Group Earned $244 Million in Ransom Profits
Cybercrime and Ransomware

Akira Ransomware Group Earned $244 Million in Ransom Profits

Staff WriterBy Staff WriterNovember 15, 2025No Comments3 Mins Read4 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Top Highlights

  1. The Akira ransomware group has generated over $244 million through attacks targeting critical infrastructure since March 2023, mainly exploiting vulnerabilities in VMware ESXi, Nutanix AHV, SonicWall, Veeam, and Cisco devices.
  2. They utilize a variety of techniques, including password spraying, exploiting publicly disclosed vulnerabilities, stolen credentials, and brute-force attacks on VPNs and routers to gain initial access.
  3. Once inside, they establish footholds by creating admin accounts, escalating privileges via Veeam vulnerabilities, and moving laterally with tools like AnyDesk, LogMeIn, and RDP, often uninstalling endpoint detection to evade detection.
  4. The group exfiltrates data rapidly—within hours—before executing ransomware payloads that encrypt files and leave ransom notes, targeting enterprise and infrastructure environments globally.

The Core Issue

The Akira ransomware group has amassed over $244 million by conducting sophisticated cyberattacks primarily targeting organizations with critical infrastructure across North America, Europe, and Australia. Since March 2023, the group has specialized in encrypting virtualization servers such as VMware ESXi and Nutanix AHV, exploiting known vulnerabilities like CVE-2024-40766 in SonicWall firewalls, and leveraging stolen credentials, brute-force techniques, and other vulnerabilities in Cisco, Windows, VMware, and Veeam systems to gain access. Their tactics include deploying malicious scripts, creating admin accounts, exploiting backups, and unhooking security detection tools to deepen their foothold.

Once inside, they typically escalate privileges quickly—sometimes within hours—by copying sensitive files like the NTDS.dit and SYSTEM hive to compromise domain administrator accounts, then encrypt a victim’s data with custom extensions such as .akira and .powerranges, while leaving ransom notes. The story of these attacks is primarily told by government agencies in the US, France, Germany, and the Netherlands, which have issued advisories detailing these techniques and emphasizing the threat posed by Akira’s expanding arsenal and relentless pursuit of financial gain. This narrative underscores how intentional vulnerabilities, coupled with advanced tactics, enable the group to exfiltrate and encrypt critical data efficiently, causing significant disruption to targeted organizations.

Potential Risks

The notorious Akira Ransomware Group’s staggering $244 million haul underscores a harsh reality: any business, regardless of size or industry, is vulnerable to a devastating cyberattack that can cripple operations, compromise sensitive data, and inflict substantial financial loss. Such ransomware incidents can lock crucial systems, halt productivity, and force businesses to pay hefty ransoms—or face prolonged downtime and reputation damage—while exposing confidential information to malicious actors. As cybercriminals continually refine their tactics, your enterprise’s defenses must be equally sophisticated; neglecting this risk leaves your organization exposed to the same catastrophic outcome that has million-dollar consequences elsewhere, demonstrating that cybersecurity is not just a technical issue but a critical business imperative.

Possible Next Steps

Addressing ransomware threats promptly is critical to minimizing financial loss, protecting sensitive data, and maintaining trust. Delays in remediation can lead to expanded breaches, increased costs, and long-term damage to an organization’s reputation.

Containment and Eradication

  • Isolate affected systems to prevent further spread
  • Identify and eliminate malicious files and tools

Assessment and Analysis

  • Conduct comprehensive incident analysis to determine scope
  • Evaluate impacted assets and data

Recovery and Restoration

  • Restore systems from secure backups
  • Verify integrity before bringing systems online

Communication and Notification

  • Inform stakeholders and regulatory bodies as required
  • Maintain transparent communication with employees and clients

Improvement and Prevention

  • Patch vulnerabilities exploited by attackers
  • Implement enhanced detection and response strategies
  • Conduct regular security training for staff

Continue Your Cyber Journey

Discover cutting-edge developments in Emerging Tech and industry Insights.

Understand foundational security frameworks via NIST CSF on Wikipedia.

Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.

Cyberattacks-V1cyberattack-v1-multisource

Akira CISO Update cyber risk cybercrime Cybersecurity MX1 Ransomware risk management
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRevolutionizing Cybersecurity: The AI Workforce Shift
Next Article China’s ‘Autonomous’ AI Hacks Still Rely on Heavy Human Effort
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Rise in online radicalization fuels cyber-physical threat escalation

August 22, 2026

Empowering Defenders with OpenAI Cyber Models

August 21, 2026

Apollo suffers social engineering breach exposing sensitive data

August 21, 2026

Comments are closed.

Latest Posts

New Agent Data Injection Attack Traps AI Agents Into Mischief

August 20, 2026

New ENCFORGE Ransomware Threat Targets AI Model Files via Langflow RCE Attack

August 17, 2026

Urgent: Critical SharePoint RCE CVE-2026-50522 Under Active Attack

August 14, 2026

AI Models Escape Sandbox and Accuse Hugging Face of Benchmark Cheating

August 11, 2026
Don't Miss

Rise in online radicalization fuels cyber-physical threat escalation

By Staff WriterAugust 22, 2026

Summary Points Cyber activity, especially online radicalization, can escalate into physical threats and cyber terrorism.…

Empowering Defenders with OpenAI Cyber Models

August 21, 2026

Apollo suffers social engineering breach exposing sensitive data

August 21, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Rise in online radicalization fuels cyber-physical threat escalation
  • Empowering Defenders with OpenAI Cyber Models
  • Apollo suffers social engineering breach exposing sensitive data
  • Microsoft Defender driver exploited to disable security at boot
  • New AI Controls: Long Overdue, Finally Here
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Rise in online radicalization fuels cyber-physical threat escalation

August 22, 2026

Empowering Defenders with OpenAI Cyber Models

August 21, 2026

Apollo suffers social engineering breach exposing sensitive data

August 21, 2026
Most Popular

Gefährliche Angriffe: Wie Cyberkriminelle Ihre Identität angreifen

January 29, 2026108 Views

Cyber Threats Unleashed: Chrome 0-Day, AI Hacking, DDR5 Vulnerabilities & npm Worm

September 22, 202536 Views

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202634 Views

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.