Skip to main content
See every side of every news story
Published loading...Updated

FBI Warns Akira Ransomware Stole $244M from Businesses

  • On Thursday, the Cybersecurity and Infrastructure Security Agency , Federal Bureau of Investigation , Department of Defense Cyber Crime Center and Department of Health and Human Services issued a joint advisory warning Akira encrypts Nutanix AHV virtual machines.
  • Akira ransomware affiliates gain initial access by stealing or brute-forcing VPN and SSH credentials on exposed routers and firewalls, exploiting SonicWall CVE-2024-40766 and targeting a VPN without multifactor authentication earlier this year.
  • Researchers observed Akira using nltest, AnyDesk, LogMeIn, Impacket and exploiting Veeam Backup & Replication CVE-2023-27532 and CVE-2024-40711 to delete backups and exfiltrate data within two hours via Ngrok.
  • Critical industries face active attacks as Akira exploits edge and backup vulnerabilities, with officials saying the group has claimed more than $244 million in proceeds and the FBI monitoring over 130 ransomware variants.
  • Officials cautioned that Akira collaborates with other threat groups and exploits six new vulnerabilities, urging stronger defenses against its double‑extortion model and Tor leak threats this month.
Insights by Ground AI

18 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

cisa.gov broke the news in on Thursday, November 13, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal