Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop
AttackFeed by Joe Wagner | Akira ransomware group can achieve initial access to data encryption in less than an hour  - CyberScoop

Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop

Posted on April 2, 2026 By djohnson
Attack Feeds

The Akira ransomware group has compromised hundreds of victims over the past year with a well-honed attack lifecycle that has whittled down the time from initial access to encryption of data in less than four hours, according to cybersecurity firm Halcyon.

Akira has been active since 2023, racking up at least $245 million in ransom payments from victims through September 2025. The cybercriminal outfit likely includes former members and affiliates of the now-defunct Conti ransomware group, and is known for its polished approach to digital extortion.

A primary example can be found in the efficiency of Akira’s infection cycle, which has reduced incident response times to hours. According to Halcyon, Akira is known for using zero-day vulnerabilities, buying exploits from initial access brokers and exploiting VPNs lacking multifactor authentication to infect their victims. Akira also uses a process known as “intermittent encryption,” whereby large files can be encrypted faster in smaller blocks.

“Akira is more stealthy and less aggressive allowing the ransomware to move swiftly through the entire ransomware attack kill chain from initial access to exfiltration, and encryption in as little as 1 hour without detection,” Halcyon wrote in a blog published Thursday. “In most cases, the time from initial access to encryption was less than four hours.” 

Additionally, while most ransomware operators tend to spend “about 90-95%” of their time developing their encryption malware and 5-10% on crafting decryptors, Halcyon said Akira has made “extensive efforts to ensure the recovery of large files, like server images,” going so far as to temporarily auto-save files with custom .akira extensions to ensure they can be recovered if the encryption process is interrupted.

Halcyon’s blog notes that these efforts are likely less due to ethical principles than because the group believes offering functional decryptors increases the chance that a business will pay the ransom. Akira’s combination of rapid infection while offering firms a more reliable way to recover their data is something that “sets it apart from many ransomware operators.”

“The group’s ability to move from initial access to full encryption in under an hour, while maintaining recovery guarantees that incentivize victim payment, reflects a mature, business-driven criminal enterprise,” Halcyon said.

The group has been observed exploiting vulnerabilities in Veeam backup and replication servers, Cisco VPNs and SonicWall appliances. Like other ransomware groups, Akira uses a double-extortion model against victims, stealing their data before encrypting it, then threatening to publish the stolen data online if businesses don’t pay.

Last year, the FBI and the Cybersecurity and Infrastructure Security Agency flagged Akira as one of the top ransomware criminal groups in the world, primarily targeting small- and medium-sized businesses in the manufacturing, education, IT, health care, financial and agricultural sectors.

The post Akira ransomware group can achieve initial access to data encryption in less than an hour appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Medtech giant Stryker says it’s back up after Iranian cyberattack  – CyberScoop
Next Post: Lawmakers renew push for Labor Department-backed cyber apprenticeship grants  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | Pakistan’s Top News Channels Hacked and Hijacked With Anti-Military Messages  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Pakistan’s Top News Channels Hacked and Hijacked With Anti-Military Messages  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 2, 2026
AttackFeed by Joe Wagner | Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware  - The Hacker News
Attack Feeds
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware  – The Hacker News
March 5, 2026
AttackFeed by Joe Wagner | FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 16, 2026
AttackFeed by Joe Wagner | Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 7, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.