Buffalo Niagara Convention Center Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Buffalo Niagara Convention Center has been listed by the Akira ransomware group, with internal files reported to have been exfiltrated. The incident was disclosed on May 22, 2026; anyone connected to the organization should review their exposure and take appropriate protective steps.
Inside the incident
The only confirmed public information is the appearance of the Buffalo Niagara Convention Center on the Akira group’s leak site on the reported date. The listing describes an operation in which files were removed from the organization’s systems prior to any encryption. No details on the initial access method, the duration of the intrusion, or the precise volume of data removed have been independently verified. The group’s post asserts that corporate records were taken but provides no evidence beyond the listing itself.
Inside akira
Akira is a ransomware operation that has conducted multiple campaigns against organizations in North America and Europe since 2023. Public reporting from cybersecurity firms shows the group typically gains access through phishing, compromised remote-access tools, or unpatched systems, then moves laterally to locate and copy data before deploying encryption. The group maintains a leak site where it lists victims and threatens to publish stolen files if ransom demands are not met. In this case, the listing attributes the claimed theft to Akira but remains an unverified assertion by the group.
Who is Buffalo Niagara Convention Center?
The Buffalo Niagara Convention Center operates as a public venue for meetings, trade shows, and large events in downtown Buffalo, New York. Organizations of this type routinely collect contact details, registration records, and payment information from event planners, exhibitors, and attendees, as well as employment records for staff. A compromise at such a facility can therefore involve data belonging both to the venue’s workforce and to thousands of external individuals who have used the space.
What data was at risk
The Akira listing claims that the exfiltrated material includes employee personal documents such as passports and driver’s licenses, client and partner records covering personal data of 180,000 people, contracts, financial documents, and project files. No independent confirmation of these data types or their volume has been published. Organizations in the convention and events sector commonly hold attendee registration lists, vendor agreements, and internal human-resources files; whether any of those specific categories were taken remains unconfirmed beyond the group’s statements.
Why it matters
Personal identifiers such as passports and driver’s licenses can be used for identity fraud or account takeover if they reach criminal marketplaces. Large sets of client contact information can also support targeted phishing or resale. For the convention center, the incident adds operational costs for investigation, potential regulatory notifications, and restoration of systems. Individuals named in any released files face the practical task of monitoring their accounts and credit reports for misuse.
What to do if you're exposed
Anyone who has registered for events at the Buffalo Niagara Convention Center or worked there should watch official communications from the organization for further details. Standard steps include changing passwords for any accounts tied to the venue, enabling multi-factor authentication, and reviewing bank and credit-card statements for unusual activity. Individuals can also run a free exposure scan of their email address against known breach data to determine whether their information has appeared in previously published datasets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Edge Solutions | Stone Ridge Payments Listed by akira Ransomware GroupRefinery Hotel Listed by akira Ransomware GroupPrecise Forms Listed by akira Ransomware GroupJMS Southeast Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.