Apricorn Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Apricorn was listed by the Akira ransomware group on September 05, 2025, with internal files reported as exfiltrated; the date of the actual intrusion has not been established. Individuals should check whether their data was exposed and take appropriate protective steps.
Ransomware groups continue to target organisations of every size by combining data theft with encryption, then publicising victims on leak sites to increase pressure. In this landscape, even firms that specialise in data protection can appear on those lists, raising questions for employees, clients and partners about what may have been taken.
On 5 September 2025 Apricorn was listed by the akira ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack; the number of people affected remains unknown. The group has claimed it will publish corporate material that includes detailed employee records and other sensitive business data. Because the listing is an unverified claim, the precise scope and authenticity of any stolen material have not been independently confirmed.
What happened
According to the available record, Apricorn was named on the akira leak site on 5 September 2025. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. No further technical details—such as the initial access vector, the exact date of intrusion, the volume of data taken, or whether systems were encrypted—have been disclosed in the public summary. The number of individuals potentially affected is listed as unknown. The group’s own statement asserts that it intends to upload corporate data, but that assertion has not been verified by independent sources.
The group behind it: akira
Akira is a ransomware operation that has been active since early 2023. Like many contemporary groups, it typically employs a double-extortion model: data are stolen before systems are encrypted, and the threat of public release is used to compel payment. Victims are routinely listed on a dedicated leak site, often accompanied by sample files or descriptive claims about the material held. Public reporting has linked the group to attacks across manufacturing, professional services, education and technology sectors. Tactics commonly include exploitation of remote-access services, credential theft and living-off-the-land techniques once inside a network. In this case the group claims it will release Apricorn’s corporate data; that claim should be treated as an assertion by the actors rather than established fact until corroborating evidence appears.
About Apricorn
Apricorn designs and supplies secure storage products—primarily hardware-encrypted USB drives and related solutions—intended to protect data at rest for companies and organisations. Its customer base includes enterprises and institutions that require strong physical and cryptographic controls over portable media. Organisations of this type routinely hold employee records, client contracts, product designs, financial information and non-disclosure agreements. A breach involving such a firm is consequential because the company itself markets tools meant to safeguard sensitive material; any compromise can affect both its own workforce and the trust of clients who rely on its products for their own data protection.
The information in question
Public reporting characterises the exposed material simply as “internal files exfiltrated in a ransomware attack.” The akira listing goes further, claiming that the data include detailed employee information (medical records, tests, EEGs, MRIs, CTs, SSN scans and other personal information), financials, client information, contracts and agreements, projects and NDAs. These specifics originate solely from the group’s statement and have not been independently verified. Exact contents, file counts and whether any of the claimed medical or identity documents are authentic remain unconfirmed. Organisations that manufacture secure storage devices typically maintain personnel files, customer lists, technical documentation and commercial agreements; the presence of any of those categories cannot be asserted as fact beyond the actors’ own description.
The real-world impact
If the claimed material is genuine, employees could face risks of identity theft, medical-privacy exposure or targeted social-engineering attempts that reference personal or health details. Clients and partners named in contracts or project files might experience secondary phishing or competitive intelligence risks. For Apricorn itself, the incident can disrupt operations, require costly forensic and legal work, and damage the reputation of a firm whose core offering is data security. Because the number of affected individuals is unknown and the data types are unconfirmed, the scale of personal harm cannot yet be quantified. Even limited exposure of internal documents can still enable further attacks against the organisation or its contacts.
Were you affected?
Anyone who has worked for, contracted with, or supplied Apricorn should monitor financial accounts and credit reports for unusual activity and be alert to unsolicited messages that reference personal or medical details. Consider placing fraud alerts with credit bureaus and reviewing any recent communications that request sensitive information. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official notifications, if any are issued by Apricorn or regulators, will provide the most reliable guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Itasca Consulting Group Listed by akira Ransomware GroupMOBI Technologies Listed by akira Ransomware GroupApache OpenOffice Listed by akira Ransomware GroupGeneral Micro Systems Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Apricorn Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.