logo

Akira ransomware group can achieve initial access to data encryption in less than an hour

ID: d98ff3dc-0f08-5ced-bc30-baa97d0016f4

STIX ID: report--d98ff3dc-0f08-5ced-bc30-baa97d0016f4

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: djohnson

...
...

Akira is a prolific ransomware group active since 2023 that has compromised hundreds of victims and extorted roughly $245M; security firm Halcyon reports the group uses zero-day exploits, buys access from brokers, targets Veeam/Cisco/SonicWall products and unprotected VPNs, employs intermittent encryption and double-extortion, and can progress from initial access to full encryption in as little as one hour, severely reducing incident response time and increasing likelihood of ransom payment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.