DreamWall Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The DreamWall Listed by akira Ransomware Group (reported May 30, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On May 30, 2024, DreamWall, a Belgian animation and graphics studio, appeared on the leak site of the akira ransomware group. The group claims it carried out a ransomware attack that included the exfiltration of internal files totaling about 15GB. Public detail on the incident remains limited: the number of people affected is unknown, and independent confirmation of the full scope has not been disclosed.
The listing matters because the files the group describes include categories that can contain sensitive personal and organisational information. For individuals whose data may have been held by the studio, the claim raises ordinary but concrete questions about exposure and next steps.
Inside the incident
The available public record consists of the akira group's listing of DreamWall and the accompanying summary. That summary states that internal files were exfiltrated in a ransomware attack and characterises the material as including personal data, medical files, contracts, agreements with other companies, and financial data. The volume is given as approximately 15GB, with an indication that the files would be made available soon. No further verified details have been released about the date the intrusion began, the initial access method, whether systems were encrypted, whether a ransom demand was issued, or whether any payment occurred. The number of people whose information may be involved is unknown. All specifics about what was taken therefore rest on the group's unverified claim rather than on independent reporting or official confirmation.
Who is akira?
Akira is a ransomware operation that became publicly active in 2023. Like many contemporary groups, it typically employs a double-extortion model: data is stolen before systems are encrypted, and the threat of publication is used to pressure victims. The group has been observed targeting a range of organisations across multiple countries and sectors, often leaving ransom notes that direct victims to Tor-based negotiation sites. Its leak site is used to name victims and, in some cases, to release samples or full archives when negotiations fail or stall. Public reporting has associated akira with both Windows and Linux-targeted encryptors and with the reuse of techniques seen in earlier ransomware families. None of this established pattern constitutes proof of any particular claim made about DreamWall; the listing of the studio remains an assertion by the group itself.
About DreamWall
DreamWall is an animation and graphics studio based in Charleroi, Belgium. It was formed through a partnership between the publishing house Dupuis and the public broadcaster RTBF. The studio works in media solutions, providing expertise in studio production and virtual creations for different markets. Organisations of this type routinely handle production files, contracts with clients and partners, financial records, and, depending on projects and personnel, personal and sometimes medical information relating to staff, freelancers, or collaborators. A breach affecting such a studio is consequential because creative and media companies often sit at the intersection of commercial agreements, intellectual property, and employee or contractor data, any of which can create lasting exposure if released.
What was likely exposed
The only named categories come from the akira group's own description: personal data, medical files, contracts, agreements with other companies, and financial data, said to total roughly 15GB of internal files. These claims have not been independently verified, and the precise contents of any archive remain unconfirmed. In the ordinary course of business an animation and graphics studio may hold employee and contractor records, payroll or banking details, client contracts, project agreements, and, in some cases, health-related information required for insurance or workplace compliance. Whether any of those specific items were present in the material the group says it took cannot be established from public sources. Readers should therefore treat the listed data types as alleged rather than proven.
Why it matters
If the claimed files are authentic and later published, individuals whose personal or medical information appears could face risks of identity misuse, targeted phishing, or unwanted contact. Financial data and contracts can enable fraud or competitive harm to the organisations involved. For DreamWall itself, the incident carries potential operational, legal, and reputational consequences common to any ransomware event involving exfiltration, including notification duties under data-protection rules and the need to secure systems against further access. Because the number of affected people is unknown and the exact contents unconfirmed, the practical impact cannot yet be quantified; the risk remains real but currently unmeasured.
What to do if you're exposed
Anyone who has worked with, contracted for, or supplied personal information to DreamWall should treat the listing as a prompt for basic precautions. Monitor bank and credit-card statements for unfamiliar activity, place fraud alerts with credit bureaus if available in your country, and change passwords on any accounts that may have used the same credentials. Be alert to phishing messages that reference the studio or related projects. If medical or other sensitive records are a concern, contact the relevant providers to note the possible exposure. As a further check, readers can run a free exposure scan of their email address to see whether that address has already appeared in known breach data sets. Official updates from DreamWall or Belgian authorities, if issued, should be followed for any specific guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Peikko Listed by akira Ransomware GroupDivimast Listed by akira Ransomware GroupDrywall Partitions Listed by akira Ransomware GroupJared Beschel and Associates Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the DreamWall Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.