Healthcare Sector Warned of Changing Akira Ransomware Tactics
Another warning has been issued about the Akira ransomware group in light of evolving tactics and accelerated attacks. Akira first emerged in March 2023, and its tactics, techniques, and procedures (TTPs) have been constantly evolving. The Russian-speaking ransomware group has been highly successful, claiming over 1,100 victims and generating more than $244 million in ransom payments, and attacks have increased in recent months. Akira is currently one of the most prolific ransomware groups, having conducted at least 123 attacks in Q3, 2025, according to Check Point Research, which puts the group in second place behind Qilin (228 attacks) and ahead of Inc Ransom (116 attacks). While Akira has conducted attacks on large organizations, the group’s victim list also includes many small- to medium-sized businesses.
Akira conducts attacks on a wide range of industry sectors and has attacked many critical infrastructure entities in North America, Europe, and Australia. While initially focusing on Windows systems, Akira has developed a Linux version of its ransomware payload and is also targeting VMware Elastic Sky X Integrated (ESXi) virtual machines (VMs). According to the latest joint cybersecurity advisory from the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA) Department of Defense Cyber Crime Center (DC3), Department of Health and Human Services (HHS), Europol’s European Cybercrime Centre (EC3), and European law enforcement agencies, many of the groups attacks have been on the healthcare and public health (HPH), manufacturing, education, IT, financial services, and food and agriculture sectors.
This is the third advisory issued by the authorizing agencies about Akira due to the group’s changing tactics. The group conducts sophisticated attacks and poses a significant threat to the HPH sector. The attacks have caused major disruption to patient care and have put patient safety at risk, with victims having data stolen, putting patients at a long-term risk of identity theft and fraud. According to the Health Information Sharing and Analysis Center, Akira has conducted at least 24 attacks on healthcare organizations since March 2023, and the group has been actively targeting medical device manufacturers in recent months.
While the methods of initial access are varied, the group often gains access through virtual private network (VPN) services that do not have multifactor authentication configured. The group is also known to target unpatched vulnerabilities, mostly known vulnerabilities in Cisco products, rather than zero-days. Akira actors also use spear phishing to steal credentials, abuse valid credentials obtained through brute force attacks and initial access brokers, and external-facing services such as Remote Desktop Protocol are targeted.
The cybersecurity alert provides updated Indicators of Compromise (IoCs) and details of the latest TTPs. The authoring agencies suggest several mitigations, including securing and hardening security on Internet-exposed systems such as VPNs, firewalls, and remote access tools; implementing phishing-resistant multifactor authentication on all remote access points; and ensuring patches are applied promptly and all systems are running the most up-to-date software versions.