Ascoma Group Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Ascoma Group was listed on March 12, 2025, by the Akira ransomware group, which claims to have stolen internal files. Individuals who may have shared personal or business information with Ascoma are advised to monitor their accounts and consider protective steps.
On March 12, 2025, the Ascoma Group was listed by the akira ransomware group, which claims responsibility for a ransomware attack involving the exfiltration of internal files. Public reporting indicates that the number of people affected remains unknown, and the precise scope of the incident has not been independently confirmed beyond the group's assertions. The listing matters because Ascoma operates in insurance and healthcare cost management, sectors that routinely handle sensitive personal and corporate records; any confirmed exposure could create lasting risks for employees, customers, and partners.
What is known so far rests largely on the ransomware group's own statements. Akira asserts it is prepared to release more than 12 GB of corporate material. No official confirmation of the breach's full extent, technical method, or remediation status has been detailed in the available record.
Inside the incident
According to the reported listing, Ascoma Group was named by akira as a victim of a ransomware attack in which internal files were exfiltrated. The date associated with the public report is March 12, 2025. The group states it holds more than 12 GB of essential corporate documents and is ready to upload them. No further public detail has been provided on the initial intrusion vector, the duration of unauthorized access, encryption of systems, or any ransom demand. The number of individuals whose information may be involved is listed as unknown. Because the primary source of these claims is the threat actor's leak-site posting, the details remain unverified assertions rather than independently established facts.
Ascoma itself has not been quoted in the available summary with any public statement acknowledging or denying the claims. Timing of the actual compromise, if it occurred, is undisclosed. Scale beyond the claimed data volume is likewise unconfirmed. In the absence of additional reporting, the incident is best understood as a claimed ransomware event centered on data theft rather than a fully documented operational disruption.
Inside akira
Akira is a ransomware operation that became active in early 2023 and has since been documented in multiple public cybersecurity analyses. The group typically employs a double-extortion model: it encrypts victim systems while simultaneously exfiltrating data, then threatens to publish the stolen material on a dedicated leak site if payment is not made. Akira has been observed targeting organizations across manufacturing, education, professional services, and other sectors, often gaining initial access through compromised credentials, vulnerable remote-access services, or phishing. Once inside a network, operators move laterally, disable security tools where possible, and stage large volumes of data for theft before deploying the ransomware payload.
The group maintains a Tor-based leak site where it posts victim names, sample files, and countdown timers. Listings are claims by the operators and do not by themselves prove successful compromise or the authenticity of every file set. Akira has previously released data from victims who did not pay, contributing to its reputation for following through on threats. Public knowledge of the group's tactics does not, however, extend to inventing specific statements about Ascoma beyond the content of the March 2025 listing itself. That listing asserts possession of more than 12 GB of Ascoma-related documents and readiness to publish them; those assertions should be treated as unverified claims until corroborated by independent sources or the victim organization.
About Ascoma Group
Ascoma Group maintains two cross-functional divisions. ASCOMA International serves as a coordination center for international operations. ASCOMA Health/PACTILIS functions as the group's competence center for health insurance, healthcare cost management, and personal insurance more broadly. Organizations of this type operate at the intersection of insurance underwriting, claims processing, and international coordination, routinely handling personal identifiers, policy details, medical-cost data, and corporate correspondence.
A breach involving such an entity is consequential because the data typically processed includes both employee records and customer information that can be sensitive or regulated. Even when the exact contents of any stolen set remain unconfirmed, the sector's reliance on accurate personal and health-related records means that unauthorized access can affect individuals' privacy, financial standing, and ability to manage insurance matters. The international dimension of Ascoma's operations further raises the possibility that data subjects in multiple jurisdictions could be implicated, though no geographic breakdown has been disclosed.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack. Akira specifically claims readiness to upload more than 12 GB of essential corporate documents, listing examples that include contact numbers and e-mail addresses of employees and customers, internal correspondences, passports, and other employee and customer documents. These categories are presented as the group's own description of the material; they have not been independently verified.
Because the precise contents remain unconfirmed, it is useful to note what organizations in health insurance and personal-insurance coordination typically hold: policyholder names and contact details, identification documents, medical-cost or claims-related records, employee personnel files, and internal business communications. Whether any of those categories actually appear in the claimed 12 GB set is unknown. Public detail on file types, volume of personal records, or presence of financial or medical data beyond the group's listed examples is limited. Readers should therefore treat the named categories as claimed rather than established fact.
The real-world impact
If the claimed data set is authentic, employees and customers whose contact details, correspondence, or identity documents appear could face elevated risks of phishing, social-engineering attempts, and identity misuse. Passport images or similar documents, if present, can be reused for fraudulent applications or account takeovers. Internal correspondence may reveal business relationships, negotiation details, or operational practices that competitors or fraudsters could exploit. For the organization itself, the incident—if confirmed—could entail regulatory notification obligations, potential contractual liabilities, and the operational cost of investigating and containing the event.
Because the number of people affected is unknown and the exact data types unconfirmed, the concrete scale of harm cannot yet be quantified. Even so, the combination of employee and customer records in an insurance context means that any verified exposure would require careful monitoring of credit activity, insurance accounts, and unsolicited communications. The absence of public confirmation does not eliminate risk; it simply leaves the full picture incomplete.
If your data was in this claimed breach
Individuals who have had dealings with Ascoma Group as employees or customers should remain alert for unexpected messages that reference insurance policies, personal details, or urgent requests for verification. Practical first steps include changing passwords on related accounts, enabling multi-factor authentication where available, and monitoring financial and insurance statements for irregularities. If identity documents such as passports are believed to be involved, consider placing fraud alerts with relevant credit or identity-protection services according to local procedures.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan provides an additional data point but does not confirm or rule out involvement in this specific incident. Stay informed through official channels from Ascoma or competent authorities rather than relying solely on threat-actor claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Trubee Wealth Advisors Listed by akira Ransomware GroupRosland Capital Listed by akira Ransomware GroupMD Manouel InsuranceAgency Listed by akira Ransomware GroupStanding Chapter 13 Trustee Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Ascoma Group Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.