Short answer: The FBI and partner agencies said Akira ransomware actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025. That is an approximate, government-reported claim—not an independently audited profit figure, a total of ransom demands, or the full economic damage to victims. The updated advisory was issued November 13, 2025, and remains the strongest primary source for the figure as of August 18, 2026.
What the $244 million figure actually measures
The safest wording is: “U.S. and international agencies said Akira actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025.” The qualifiers matter. “Claimed” does not mean every payment was independently verified, and “approximately” does not support false precision.
| Term | What it means | What the figure does not establish |
|---|---|---|
| Ransom proceeds | Money Akira says it received, or investigators associate with its ransomware activity. | Audited net profit or a complete accounting of all payments. |
| Ransom demands | Amounts requested from victims. | Amounts actually paid; demands can be much higher than proceeds. |
| Net profit | Proceeds after affiliate shares, access purchases, infrastructure, laundering and other costs. | The advisory does not publish Akira’s costs or profit margin. |
| Victim impact | Downtime, restoration, legal and notification costs, lost business, regulatory exposure and reputational harm. | A dollar-for-dollar equivalent of the ransom figure. |
The updated estimate superseded an April 2024 advisory that cited roughly $42 million in proceeds. The increase reflects updated intelligence and continued activity; it is not necessarily a clean measure of money earned between the two publication dates. See the 2024 FBI/CISA advisory and the November 2025 joint advisory.
Who Akira is and whom it targets
Akira has been active since at least March 2023. Agencies describe it as a financially motivated operation commonly associated with a ransomware-as-a-service model, in which core operators and affiliates divide responsibilities and payments. Threat researchers have assessed possible links to the former Conti ecosystem based on code, infrastructure or cryptocurrency similarities, but that is an attribution assessment—not proof of Akira’s leadership or membership.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Akira has affected organizations in North America, Europe and Australia. The FBI advisory lists manufacturing, education, information technology, healthcare and public health, financial services, food and agriculture, other businesses and critical-infrastructure organizations. Small and midsize businesses are a primary focus, but larger enterprises and essential-service operators are also at risk.
How Akira gets inside
Reported entry routes include stolen or compromised VPN credentials, missing or weak multifactor authentication, exposed remote-access systems and exploitation of internet-facing vulnerabilities. The 2025 advisory specifically highlights these vulnerabilities:
| Vulnerability | Affected technology or area |
|---|---|
| CVE-2024-40766 | SonicWall |
| CVE-2020-3580 | Cisco ASA and Firepower Threat Defense |
| CVE-2023-28252 | Windows |
| CVE-2024-37085 | VMware ESXi |
| CVE-2023-27532 | Veeam Backup & Replication |
| CVE-2024-40711 | Veeam Backup & Replication |
These are not merely theoretical weaknesses: the advisory links Akira activity to exposed technologies and urges organizations to prioritize vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog. Patching a device today does not prove that an attacker who entered earlier has been removed.
What an Akira intrusion can do
A rapid attack chain
- Obtain valid credentials or exploit an exposed perimeter device.
- Establish persistence and map users, servers, virtual infrastructure and security controls.
- Disable or evade defenses and move laterally with elevated privileges.
- Identify domain controllers, hypervisors, storage and backup repositories.
- Steal data for extortion leverage.
- Encrypt systems and files where possible, then issue a ransom demand and publication threat.
Government and industry reporting describes some incidents moving from initial access to data theft or encryption in only a few hours. One reported account observed exfiltration in slightly more than two hours, while other reporting described encryption in less than four hours. Those are observed examples, not a guaranteed timeline for every intrusion; they show why an organization may have little time to investigate after a suspicious login.
Rank #3
Platforms and encryptors
Akira initially focused on Windows and later added a Linux variant aimed at VMware ESXi virtual machines. The updated advisory describes activity involving Windows, Linux, VMware ESXi, Hyper-V and Nutanix Acropolis Hypervisor (AHV). In a June 2025 incident, Akira encrypted Nutanix AHV virtual-machine disk files, demonstrating expansion beyond earlier VMware- and Hyper-V-focused activity.
Early samples were written in C++ and commonly used the .akira extension. Later campaigns used the Rust-based Megazord encryptor, associated with .powerranges. The advisory says Akira, Megazord, Akira_v2 and related tooling have been used interchangeably across incidents. Ransom notes may be named fn.txt or akira_readme.txt; filenames are detection clues, not conclusive attribution because they can be copied.
Rank #4
Why backups do not solve every problem
Akira uses double extortion: operators steal data before or during encryption and threaten to publish it. A clean, isolated backup can reduce the pressure created by encrypted systems, but it cannot automatically erase copied data or prove that exfiltration did not occur. Data theft can create notification, contractual, regulatory and reputational obligations even when the organization refuses to pay.
- Backups may be encrypted or deleted if attackers obtain backup-administrator credentials.
- A successful backup job does not prove that applications can be restored consistently.
- Restoring files without resetting compromised credentials and closing the entry route can lead to reinfection.
- A ransom note may appear after theft even when encryption is incomplete.
Priority defenses for organizations
Secure the perimeter and identity systems
- Patch internet-facing VPNs, firewalls, hypervisors and backup products first, using CISA’s Known Exploited Vulnerabilities catalog to set urgency.
- Require phishing-resistant MFA for VPN, remote-access, administrator, cloud, backup and identity-provider accounts. Audit legacy protocols, service accounts and unmanaged devices that bypass the policy.
- Remove unnecessary internet exposure from ESXi, Hyper-V, Nutanix AHV, storage controllers and backup consoles.
Contain lateral movement and protect recovery
- Segment critical servers and restrict east-west traffic.
- Use separate privileged accounts, eliminate unnecessary local-administrator rights and monitor new administrator creation.
- Maintain offline, isolated or immutable backup copies with separate administrative credentials.
- Test application restoration regularly, including dependencies, recovery time and recovery point objectives.
Detect behavior, not just file extensions
- Use endpoint detection and response where supported and monitor for mass file renaming, security-tool tampering, unusual remote-service use and abnormal administrative activity.
- Alert on impossible-travel events, unusual VPN logins, access to backup repositories and large outbound data transfers.
- Ensure someone investigates alerts; an unmonitored EDR deployment does not provide the same protection as an actively staffed response capability.
What to do during a suspected intrusion
- Isolate affected hosts and restrict remote access without destroying volatile evidence.
- Preserve ransom notes, logs, cryptocurrency addresses, forensic images and records showing data access or transfer.
- Use a coordinated incident-response process to identify the initial-access route, persistence, compromised accounts and exfiltrated data.
- Reset credentials in a controlled sequence, beginning with privileged, VPN, identity-provider and backup accounts.
- Contact legal counsel, insurers, relevant regulators and law enforcement. The advisory directs victims to report suspected incidents to the FBI and use its indicators and mitigation guidance.
- Before any payment decision, conduct sanctions screening and legal review and assess whether recovery and notification obligations can be met without payment.
Payment does not guarantee full decryption, deletion of stolen information, an end to extortion, freedom from legal consequences or prevention of a second compromise.
Recommended Free Tools
Best Value
What remains uncertain about the headline
The FBI’s published figure has a late-September-2025 cutoff. Later threat-intelligence reporting continues to describe Akira’s lifetime proceeds as exceeding $244 million, but no newer official FBI total was identified as of August 18, 2026. The $244.17 million number should therefore not be presented as money collected through 2026, as audited profit or as the total cost imposed on victims.
Frequently Asked Questions
Did Akira make $244 million in profit?
No. The FBI and partner agencies reported that Akira actors had claimed approximately $244.17 million in ransomware proceeds as of late September 2025. The advisory does not establish net profit, which would require subtracting operating and affiliate costs.
Does multifactor authentication stop Akira?
MFA materially reduces credential-based risk, especially when it is phishing-resistant, but coverage gaps, legacy protocols, service accounts, exposed appliances and vulnerabilities can still provide an entry route.
Are organizations safe if they have backups?
No. Isolated, tested backups improve recovery from encryption, but they do not remove stolen data, notification duties or the risk of reinfection through compromised credentials and unclosed access paths.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




