Akira, one of the ransomware world’s most prolific extortion crews, added a new name to its dark web leak site on September 16, 2026: Manders, a family-owned contractor based in the Washington, D.C. metropolitan area. The listing, first spotted by the threat-tracking service ransomware.live and documented separately by RedPacket Security, claims the group extracted roughly 70GB of corporate data, including employee Social Security numbers, passports, driver’s licenses, financial records, confidential client files, contracts, and signed non-disclosure agreements.
Manders is a full-service maintenance, renovation, and painting contractor that works with multi-family, commercial, and residential property owners across the D.C. metro area, the kind of mid-sized regional operator that rarely makes cybersecurity headlines. That is precisely the point. Akira’s leak-site post does not claim to have encrypted Manders’ systems or specify a ransom figure, which points to a pure data-theft extortion play rather than a full-blown encryption event. But the incident lands at a moment when Akira has become one of the most consistently active ransomware operations tracked by federal authorities, and it offers a clear window into how a mid-market contractor with no obvious reason to expect a nation-state-grade cyberattack ends up on a leak site anyway.
What Akira’s Leak-Site Listing Actually Says
The Manders entry follows Akira’s standard playbook for its leak site: a short victim profile, a data-volume claim, and a description of what the stolen files supposedly contain, all designed to pressure a victim into contact before any files are published. According to the posting reviewed by ransomware.live and RedPacket Security, the group states it holds approximately 70GB of corporate data pulled from Manders’ network. The alleged contents span employee personal information (Social Security numbers, passport scans, and driver’s license images), financial records, confidential client files, contracts and agreements, and NDAs, the exact mix of records that turns a routine IT intrusion into a potential identity-theft and breach-notification headache for every employee and client whose paperwork passed through the company’s systems.
Notably, the post does not assert that Manders’ systems were encrypted, and no ransom demand or payment figure has been disclosed publicly. That distinction matters. Akira has historically run a double-extortion model, stealing data first and encrypting systems second, so a victim who restores from backup still faces the threat of stolen files going public. A listing with no encryption claim suggests this incident may be sitting at the data-exfiltration stage of that playbook, with the leak-site post itself serving as the leverage. Manders had not issued a public statement as of this writing, and neither Akira nor independent researchers have published a countdown timer or file sample, which is common practice on the group’s site when a victim stalls on negotiations.
Why a Regional Contractor Is a Realistic Target
It is tempting to assume ransomware crews chase hospitals, banks, and Fortune 500 names. The data says otherwise. Sophos-linked research cited in recent Akira coverage found manufacturing, legal and professional services, and construction and engineering among the group’s most frequently hit sectors in the months leading into late 2025, a pattern that fits a contracting and property-services firm like Manders almost exactly. FBI and CISA’s joint advisory on Akira similarly names manufacturing, education, information technology, healthcare, financial services, and food and agriculture as stated preferences, industries chosen less for their prestige and more for a common denominator: internet-facing remote access equipment, thin IT security staffing, and a strong incentive to pay quickly to avoid halting client-facing operations.
Construction and property-maintenance firms carry an added wrinkle that makes them attractive: they sit on a dense trove of third-party data. Client contracts, tenant records, vendor NDAs, and subcontractor financials all pass through a single back office, meaning one breach can implicate dozens of downstream organizations that never had a direct relationship with the attacker. That cascading exposure is part of why our recent analysis of ransomware’s true cost found that downtime and third-party notification expenses routinely dwarf the ransom demand itself.
How Akira Typically Gets In: The SonicWall VPN Playbook
No source has confirmed the specific intrusion method used against Manders, and readers should treat any claim about that vector as unverified. But Akira’s documented 2025-2026 campaigns give a strong sense of the group’s preferred entry point: SonicWall SSL VPN appliances. Researchers at Arctic Wolf and Rapid7 have tracked a sustained Akira campaign against SonicWall devices that began around July 21, 2025, and was still generating new infrastructure as recently as September 20, 2025, according to Arctic Wolf’s research.
The mechanics are almost mundane, which is exactly what makes them effective. Attackers log in through a VPN portal using stolen or reused credentials, in some cases tied to CVE-2024-40766, a SonicWall firewall flaw that was patched but whose associated credentials were never rotated on many appliances. From there, Akira affiliates move fast: Rapid7’s research describes malicious logins followed within minutes by port scanning and Impacket-based SMB activity for lateral movement, with ransomware deployment sometimes completed in an hour or less from initial access. There is no patch for a credential that was never reset after a vulnerability disclosure, which is precisely the gap Akira has been exploiting for over a year.
Akira by the Numbers: A Year of Escalating Attacks
Federal trackers and independent researchers paint a consistent picture of a group that has scaled up steadily since its debut. The table below summarizes the most recent verified figures.
| Metric | Figure | Source |
|---|---|---|
| Group active since | March 2023 | FBI / CISA advisory AA24-109A |
| Organizations compromised worldwide | 342+ (as of late September 2025) | FBI / CISA |
| Ransom proceeds collected to date | $244.17 million+ (as of late September 2025) | FBI / CISA |
| Victims linked to Akira in the 90 days before November 2025 | 149 | Sophos-linked research |
| Most frequently targeted sectors | Manufacturing, legal/professional services, construction and engineering | Sophos-linked research |
| Advisory status | Originally issued April 18, 2024; updated November 13, 2025 with new TTPs and IOCs | CISA |
| Standing among active ransomware variants | Named among the top five most active groups threatening U.S. businesses | CISA / FBI |
The advisory update in November 2025 is worth dwelling on. Federal agencies do not routinely refresh a ransomware advisory unless a group’s tactics have shifted enough to make the original guidance stale, a point HIPAA Journal’s coverage of the update also flagged for healthcare-sector defenders specifically. That Akira warranted a rewrite roughly 19 months after its first advisory signals that the group has kept adapting, moving from its early Linux-focused encryptors into a broader Windows and VPN-centric campaign that has proven durable against standard patching cycles, a shift also tracked by Cybersecurity Dive.
From 2023 Debut to Top-Five Threat: Historical Context
Akira emerged in March 2023 as a relatively conventional ransomware-as-a-service operation, initially drawing comparisons to the long-retired Conti group both for its interface style and its aggressive double-extortion tactics, according to background compiled on the group’s Wikipedia entry. Unlike many rivals that burn out within a year or two, Akira has shown unusual staying power. Its persistence through 2024 and into 2026, while other prominent groups collapsed or splintered, has made it one of the few ransomware brands that has outlasted three full cycles of law enforcement pressure, insurer pushback, and affiliate churn.
That longevity stands out against a backdrop of real turbulence in the ransomware-as-a-service market. RansomHub, which briefly rose to dominance among extortion brands, abruptly shut down in April 2025, scattering its affiliates to rival operations including Qilin, Akira, and DragonForce, according to threat-intelligence trackers following the shakeup. Akira absorbed some of that displaced talent without the operational disruption that has ended other groups’ runs, a resilience that helps explain why it remains a top-five threat well into its fourth year of operation.
Double Extortion Economics: Why Paying Doesn’t End the Risk
The Manders listing is a useful illustration of why the double-extortion model has become the industry default rather than the exception. In a pure encryption attack, a victim with solid backups can refuse to pay and restore operations within days. Data theft removes that escape hatch entirely. Even if Manders never loses access to a single file, the 70GB of employee and client records Akira claims to hold can still be published, sold, or used for follow-on fraud regardless of what happens on the negotiation front.
This is also why breach costs rarely track the ransom figure itself. Employee notification, credit monitoring for anyone whose Social Security number or passport data was exposed, forensic investigation, legal counsel, and client-relationship repair all stack on top of whatever a company pays or refuses to pay an extortion group. Ransomware’s downside has shifted from “will our systems come back online” to “how much of our data is now permanently outside our control,” a distinction that cyber insurers have been pricing into policies more aggressively through 2026.
Market Impact: Insurance, Client Trust, and the Small-Business Exposure Gap
For a mid-sized contractor like Manders, the financial exposure runs well beyond IT. Property-services firms hold multi-year contracts with commercial landlords and multi-family operators, relationships built on trust that a vendor can safely handle tenant and financial records. A confirmed breach involving contracts, NDAs, and financials creates real friction in that client base, independent of whatever ransom outcome occurs behind the scenes.
Cyber insurers have also grown less forgiving of exactly this profile: a company with internet-facing remote access infrastructure and no dedicated security team, a description that fits a large share of the U.S. construction and property-services sector. As ransomware gangs increasingly favor mid-market targets over hardened enterprises, insurers have pushed multi-factor authentication and credential-rotation requirements into policy renewals, sometimes denying coverage outright to applicants that cannot demonstrate basic controls on VPN and remote-access systems, the same class of infrastructure Akira has spent over a year exploiting through SonicWall appliances.
Competitive Landscape: How Akira Stacks Up in the 2026 Ransomware Market
Akira operates inside a ransomware-as-a-service market that has consolidated sharply in 2026. Threat-intelligence trackers, including Check Point Research and Industrial Cyber, have documented a leadership shuffle atop the leaderboard: Qilin held the top spot for three consecutive quarters, at one point logging 338 victims in a single quarter, before TheGentlemen overtook it in June 2026. A newer entrant, DeadLock, debuted directly at the number-two position that same month. LockBit, once the industry’s dominant brand, posted 163 victims in the first quarter of 2026, enough to hold fourth place but a fraction of its earlier peak activity.
| Group | 2026 Standing | Notable Data Point |
|---|---|---|
| Qilin | Led the leaderboard for three consecutive quarters | 338 victims logged in a single quarter at its peak |
| TheGentlemen | Overtook Qilin for the top spot in June 2026 | Became the most active group tracked that month |
| DeadLock | New entrant, debuted June 2026 | Entered the leaderboard directly at number two |
| Akira | Ranked among the top four most active groups | Combined with Qilin, TheGentlemen, and LockBit for roughly 41% of all tracked victims |
| LockBit | Fourth place in Q1 2026 | 163 victims logged in Q1 2026, down from earlier peaks |
| RansomHub | Defunct since April 2025 | Affiliates redistributed to Qilin, Akira, and DragonForce |
Two structural trends stand out. First, concentration is rising: the top 10 ransomware groups now account for roughly 71.1% of all tracked victims, the highest share since the first quarter of 2024, even as the total number of active groups fell from 85 to 71. Second, mid-tier groups are consolidating rather than proliferating, with DragonForce publicly proposing a coalition-style arrangement with LockBit and Qilin in September 2025 on dark web forums. Akira’s ability to hold a top-four position through all of this turnover, absorbing RansomHub’s displaced affiliates without visible disruption, sets it apart from brands like LockBit that have visibly lost ground. That contrasts with the pattern we tracked in our coverage of Panzer’s record August 2026, where a newer entrant scaled quickly but without Akira’s multi-year track record.
Comparing This Incident to Recent CISA-Flagged Ransomware Activity
The Manders listing arrives in a stretch of 2026 that has already seen CISA push multiple ransomware-linked vulnerabilities onto its Known Exploited Vulnerabilities catalog, including flaws in VMware vCenter and WatchGuard Firebox appliances that ransomware affiliates raced to weaponize within days of disclosure, as detailed in our coverage of the VMware vCenter KEV deadline and the WatchGuard Firebox ransomware listing. The common thread across all of these incidents, including Akira’s SonicWall campaign, is that ransomware affiliates are increasingly targeting edge devices, VPN gateways, firewalls, and remote-access appliances, rather than phishing employees directly. That shift means patch management and credential hygiene on perimeter hardware now matter as much as endpoint security for companies that have never considered themselves high-value targets.
What Manders, and Companies Like It, Should Do Now
Manders has not issued a public statement as of this writing, and it is not yet known whether the company is engaging with Akira, has notified affected employees and clients, or has brought in outside incident-response support. For organizations watching this incident unfold, the practical playbook is well established even if Manders’ own next steps remain unconfirmed: isolate and audit any internet-facing VPN or firewall appliance, force a full credential reset rather than a partial one (the SonicWall campaign specifically exploited credentials left over from before a patch was applied), enable multi-factor authentication on every remote-access account, and assume that data-theft notification obligations apply the moment exfiltration is confirmed, not only after encryption is confirmed.
For employees and clients of Manders specifically, the practical guidance mirrors what security researchers recommend after any confirmed personal-data exposure: monitor credit reports, watch for unsolicited contact referencing contract or financial details that would only be known to the company, and treat any unexpected password-reset or account-verification request tied to Manders as a phishing attempt until proven otherwise.
Predictions: Where This Story Goes From Here
Based on Akira’s established pattern and the broader 2026 ransomware market, several outcomes look likely in the weeks ahead.
- Akira will likely publish a partial file sample from the Manders data set if the company does not engage in negotiations within its typical window, a tactic the group has used consistently to pressure stalled victims on its leak site.
- Expect at least one more SonicWall-linked Akira victim disclosure within 30 days, given that Arctic Wolf and Rapid7 both describe the underlying campaign as still active with fresh infrastructure appearing as recently as September 2025.
- Regulatory attention on mid-market contractors is likely to increase, following the same pattern seen after other 2026 breaches involving personal identification documents, where state attorneys general opened inquiries within weeks of public disclosure.
- Akira will probably remain in the top five most active ransomware groups through the rest of 2026, based on its demonstrated ability to absorb displaced affiliates from collapsed operations like RansomHub without losing operational tempo.
- Cyber insurers are likely to tighten underwriting requirements further for construction, property management, and contracting firms specifically, given the sector’s repeated appearance in Akira’s victim profile alongside manufacturing and professional services.
The Bigger Picture for Small and Mid-Sized Businesses
The Manders incident is unremarkable in isolation, a mid-sized contractor added to a leak site, no confirmed encryption, no disclosed ransom figure. That is exactly why it matters. Akira, and the ransomware market broadly, has moved decisively away from headline-grabbing attacks on hospitals and pipelines toward a volume business built on companies that store sensitive data but lack dedicated security teams. CISA’s decision to keep updating its Akira advisory more than 18 months after the group’s debut, combined with the group’s continued presence among the top four most active ransomware brands tracked through 2026, suggests this is not a one-off event but a durable, ongoing threat pattern that regional contractors, property managers, and professional-services firms should expect to keep encountering.
Frequently Asked Questions
What is Akira ransomware?
Akira is a ransomware-as-a-service operation that emerged in March 2023 and uses a double-extortion model, stealing data before encrypting or threatening to leak it. The FBI and CISA have named it among the top five most active ransomware variants threatening U.S. businesses, per advisory AA24-109A, last updated November 13, 2025.
What company was targeted in this incident?
Manders, a family-owned contractor providing maintenance, renovation, and painting services in the Washington, D.C. metropolitan area, was listed on Akira’s leak site on September 16, 2026, according to ransomware.live and RedPacket Security.
How much data does Akira claim to have stolen?
The group’s leak-site posting claims approximately 70GB of corporate data, including employee personal information, financial records, confidential client files, contracts, and NDAs.
Was Manders’ data encrypted?
No. The leak-site listing does not claim that Manders’ systems were encrypted, and no ransom demand or payment figure has been publicly disclosed, which points to a data-theft extortion attempt rather than a confirmed encryption event.
How does Akira typically gain initial access to victim networks?
Documented Akira campaigns have relied heavily on compromising SonicWall SSL VPN appliances, using stolen or improperly rotated credentials, in some cases tied to CVE-2024-40766, according to research from Arctic Wolf and Rapid7. No source has confirmed the specific method used in the Manders incident.
How much money has Akira made from ransomware attacks?
The FBI and CISA reported that Akira had collected more than $244.17 million in ransom proceeds from at least 342 compromised organizations worldwide as of late September 2025.
How does Akira compare to other ransomware groups in 2026?
Akira ranks among the top four most active ransomware groups in 2026, alongside Qilin, TheGentlemen, and LockBit, which together account for roughly 41% of all tracked ransomware victims, according to industry threat-intelligence trackers.
What should employees or clients of a breached company do?
Security researchers generally recommend monitoring credit reports for signs of identity theft, treating unexpected password-reset or verification requests as potential phishing attempts, and watching for unsolicited contact referencing internal contract or financial details that would only be known to the affected company.
Related Coverage
- Panzer Ransomware Hits 16 Firms as August Sets 997-Attack Record [2026]
- Ransomware Costs $5.08M as Downtime Hits 50X Ransom [2026]
- CISA: WatchGuard Bug Hits Ransomware List, 265 Days [2026]
- CISA Gives Agencies 3 Days as Ransomware Hits VMware Bug [2026]
- Cloudflare WAF vs AWS WAF vs Azure WAF: $310 Price Gap [2026]