DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Akira Ransomware Group Claimed $244 Million in Proceeds: What the FBI Advisory Says

The FBI’s $244.17 million Akira figure is a claimed, approximate proceeds estimate—not audited profit or total victim damage. Here is what the advisory says and what organizations should do.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: The FBI and partner agencies said Akira ransomware actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025. That is an approximate, government-reported claim—not an independently audited profit figure, a total of ransom demands, or the full economic damage to victims. The updated advisory was issued November 13, 2025, and remains the strongest primary source for the figure as of August 18, 2026.

What the $244 million figure actually measures

The safest wording is: “U.S. and international agencies said Akira actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025.” The qualifiers matter. “Claimed” does not mean every payment was independently verified, and “approximately” does not support false precision.

Term What it means What the figure does not establish
Ransom proceeds Money Akira says it received, or investigators associate with its ransomware activity. Audited net profit or a complete accounting of all payments.
Ransom demands Amounts requested from victims. Amounts actually paid; demands can be much higher than proceeds.
Net profit Proceeds after affiliate shares, access purchases, infrastructure, laundering and other costs. The advisory does not publish Akira’s costs or profit margin.
Victim impact Downtime, restoration, legal and notification costs, lost business, regulatory exposure and reputational harm. A dollar-for-dollar equivalent of the ransom figure.

The updated estimate superseded an April 2024 advisory that cited roughly $42 million in proceeds. The increase reflects updated intelligence and continued activity; it is not necessarily a clean measure of money earned between the two publication dates. See the 2024 FBI/CISA advisory and the November 2025 joint advisory.

Who Akira is and whom it targets

Akira has been active since at least March 2023. Agencies describe it as a financially motivated operation commonly associated with a ransomware-as-a-service model, in which core operators and affiliates divide responsibilities and payments. Threat researchers have assessed possible links to the former Conti ecosystem based on code, infrastructure or cryptocurrency similarities, but that is an attribution assessment—not proof of Akira’s leadership or membership.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Akira has affected organizations in North America, Europe and Australia. The FBI advisory lists manufacturing, education, information technology, healthcare and public health, financial services, food and agriculture, other businesses and critical-infrastructure organizations. Small and midsize businesses are a primary focus, but larger enterprises and essential-service operators are also at risk.

How Akira gets inside

Reported entry routes include stolen or compromised VPN credentials, missing or weak multifactor authentication, exposed remote-access systems and exploitation of internet-facing vulnerabilities. The 2025 advisory specifically highlights these vulnerabilities:

Vulnerability Affected technology or area
CVE-2024-40766 SonicWall
CVE-2020-3580 Cisco ASA and Firepower Threat Defense
CVE-2023-28252 Windows
CVE-2024-37085 VMware ESXi
CVE-2023-27532 Veeam Backup & Replication
CVE-2024-40711 Veeam Backup & Replication

These are not merely theoretical weaknesses: the advisory links Akira activity to exposed technologies and urges organizations to prioritize vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog. Patching a device today does not prove that an attacker who entered earlier has been removed.

What an Akira intrusion can do

A rapid attack chain

  1. Obtain valid credentials or exploit an exposed perimeter device.
  2. Establish persistence and map users, servers, virtual infrastructure and security controls.
  3. Disable or evade defenses and move laterally with elevated privileges.
  4. Identify domain controllers, hypervisors, storage and backup repositories.
  5. Steal data for extortion leverage.
  6. Encrypt systems and files where possible, then issue a ransom demand and publication threat.

Government and industry reporting describes some incidents moving from initial access to data theft or encryption in only a few hours. One reported account observed exfiltration in slightly more than two hours, while other reporting described encryption in less than four hours. Those are observed examples, not a guaranteed timeline for every intrusion; they show why an organization may have little time to investigate after a suspicious login.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Platforms and encryptors

Akira initially focused on Windows and later added a Linux variant aimed at VMware ESXi virtual machines. The updated advisory describes activity involving Windows, Linux, VMware ESXi, Hyper-V and Nutanix Acropolis Hypervisor (AHV). In a June 2025 incident, Akira encrypted Nutanix AHV virtual-machine disk files, demonstrating expansion beyond earlier VMware- and Hyper-V-focused activity.

Early samples were written in C++ and commonly used the .akira extension. Later campaigns used the Rust-based Megazord encryptor, associated with .powerranges. The advisory says Akira, Megazord, Akira_v2 and related tooling have been used interchangeably across incidents. Ransom notes may be named fn.txt or akira_readme.txt; filenames are detection clues, not conclusive attribution because they can be copied.

Why backups do not solve every problem

Akira uses double extortion: operators steal data before or during encryption and threaten to publish it. A clean, isolated backup can reduce the pressure created by encrypted systems, but it cannot automatically erase copied data or prove that exfiltration did not occur. Data theft can create notification, contractual, regulatory and reputational obligations even when the organization refuses to pay.

  • Backups may be encrypted or deleted if attackers obtain backup-administrator credentials.
  • A successful backup job does not prove that applications can be restored consistently.
  • Restoring files without resetting compromised credentials and closing the entry route can lead to reinfection.
  • A ransom note may appear after theft even when encryption is incomplete.

Priority defenses for organizations

Secure the perimeter and identity systems

  • Patch internet-facing VPNs, firewalls, hypervisors and backup products first, using CISA’s Known Exploited Vulnerabilities catalog to set urgency.
  • Require phishing-resistant MFA for VPN, remote-access, administrator, cloud, backup and identity-provider accounts. Audit legacy protocols, service accounts and unmanaged devices that bypass the policy.
  • Remove unnecessary internet exposure from ESXi, Hyper-V, Nutanix AHV, storage controllers and backup consoles.

Contain lateral movement and protect recovery

  • Segment critical servers and restrict east-west traffic.
  • Use separate privileged accounts, eliminate unnecessary local-administrator rights and monitor new administrator creation.
  • Maintain offline, isolated or immutable backup copies with separate administrative credentials.
  • Test application restoration regularly, including dependencies, recovery time and recovery point objectives.

Detect behavior, not just file extensions

  • Use endpoint detection and response where supported and monitor for mass file renaming, security-tool tampering, unusual remote-service use and abnormal administrative activity.
  • Alert on impossible-travel events, unusual VPN logins, access to backup repositories and large outbound data transfers.
  • Ensure someone investigates alerts; an unmonitored EDR deployment does not provide the same protection as an actively staffed response capability.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do during a suspected intrusion

  1. Isolate affected hosts and restrict remote access without destroying volatile evidence.
  2. Preserve ransom notes, logs, cryptocurrency addresses, forensic images and records showing data access or transfer.
  3. Use a coordinated incident-response process to identify the initial-access route, persistence, compromised accounts and exfiltrated data.
  4. Reset credentials in a controlled sequence, beginning with privileged, VPN, identity-provider and backup accounts.
  5. Contact legal counsel, insurers, relevant regulators and law enforcement. The advisory directs victims to report suspected incidents to the FBI and use its indicators and mitigation guidance.
  6. Before any payment decision, conduct sanctions screening and legal review and assess whether recovery and notification obligations can be met without payment.

Payment does not guarantee full decryption, deletion of stolen information, an end to extortion, freedom from legal consequences or prevention of a second compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What remains uncertain about the headline

The FBI’s published figure has a late-September-2025 cutoff. Later threat-intelligence reporting continues to describe Akira’s lifetime proceeds as exceeding $244 million, but no newer official FBI total was identified as of August 18, 2026. The $244.17 million number should therefore not be presented as money collected through 2026, as audited profit or as the total cost imposed on victims.

Frequently Asked Questions

Did Akira make $244 million in profit?

No. The FBI and partner agencies reported that Akira actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025. The advisory does not establish net profit, which would require subtracting operating and affiliate costs.

Does multifactor authentication stop Akira?

MFA materially reduces credential-based risk, especially when it is phishing-resistant, but coverage gaps, legacy protocols, service accounts, exposed appliances and vulnerabilities can still provide an entry route.

Are organizations safe if they have backups?

No. Isolated, tested backups improve recovery from encryption, but they do not remove stolen data, notification duties or the risk of reinfection through compromised credentials and unclosed access paths.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.