Harmony Gold Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Harmony Gold Listed by akira Ransomware Group (reported May 22, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In May 2023, the gold-mining company Harmony Gold appeared on a ransomware group’s leak site, with the group claiming it had taken a large volume of internal files. For employees, contractors, partners, and others whose information may sit inside corporate systems, that kind of listing raises immediate practical questions: what was copied, who might see it, and what steps reduce the chance of fraud or misuse. Public detail on this incident remains limited, and the number of people affected has not been disclosed.
What is known comes largely from the group’s own claim and from basic facts about the organisation. No independent confirmation of the full scope has been set out in the available record, so anyone who deals with Harmony Gold is left to treat the episode as a serious but still partly opaque risk rather than a fully documented breach.
Breaking down the breach
According to reporting dated 22 May 2023, Harmony Gold was listed by the ransomware group known as akira. The group claimed that internal files had been exfiltrated in a ransomware attack and described a haul of 3.5 TB of data taken from the company. The available summary presents that figure and the characterisation of the material as the group’s assertion on its leak site; it does not constitute independent verification of volume, contents, or whether encryption or other disruption also occurred.
The number of people affected is unknown. Exact timing of any intrusion, the initial access method, and whether systems were restored from backups or otherwise recovered are not detailed in the public facts. What can be stated plainly is that a well-known ransomware actor publicly associated Harmony Gold with data theft and threatened further disclosure. Beyond the claim of internal files and the stated 3.5 TB figure, specifics remain undisclosed.
Who is akira?
Akira is a ransomware operation that emerged in public reporting in 2023 and has been linked to double-extortion tactics: encrypting victim systems while also copying data and threatening to publish it if a ransom is not paid. The group has typically listed victims on a dark-web leak site, sometimes with sample files or descriptions meant to pressure organisations into negotiation. Like other ransomware crews of this type, it has been associated with attacks on a range of sectors, often after initial access through compromised credentials, exposed remote-access services, or similar common entry points—though the precise method used against any single victim is not always confirmed.
In this case, the group’s listing of Harmony Gold and its claim of 3.5 TB of internal data should be read as an unverified claim unless separately confirmed. No additional statements attributed to akira about this specific victim appear in the provided facts beyond that leak-site style description.
About Harmony Gold
Harmony Gold is a gold mining and exploration company with operations and assets in South Africa and Papua New Guinea. Public descriptions note more than 68 years of industry experience and identify it as the second-largest gold producer in South Africa. Mining companies of this scale routinely manage complex operational technology, geological and production data, commercial contracts, supplier and joint-venture arrangements, and substantial workforces across multiple jurisdictions.
A breach involving such an organisation is consequential because mining firms hold both business-critical operational information and personal and administrative data tied to employees, contractors, and partners. Disruption or exposure can affect safety systems, production continuity, regulatory obligations, and the privacy of people whose details sit in HR, payroll, access-control, or vendor systems. The company’s role as a major regional producer means any serious cyber incident can also draw attention from investors, regulators, and communities near its operations.
What data was at risk
The facts name the exposed material only as internal files exfiltrated in a ransomware attack, together with the group’s claim of approximately 3.5 TB. No inventory of file types, databases, or categories—such as employee records, financial documents, or operational plans—has been disclosed in the available record. Exact contents are therefore unconfirmed.
Organisations in large-scale mining typically hold personnel data, contractor and supplier information, internal correspondence, technical and geological materials, commercial agreements, and various forms of operational reporting. That is the general profile of data such a company might possess; it is not a confirmed list of what akira obtained. Until Harmony Gold or another authoritative source publishes a clearer accounting, affected individuals and partners cannot know with certainty which of their details, if any, were included.
Why it matters
For people whose data may have been among internal files, the concrete risks include targeted phishing, identity fraud, and social-engineering attempts that misuse names, roles, contact details, or internal context. Even when full identity documents are not confirmed as exposed, fragments of corporate information can make fraudulent messages more convincing. Contractors and suppliers face similar exposure if commercial or contact records were copied.
For the organisation, a claimed multi-terabyte exfiltration raises concerns about intellectual property, competitive information, regulatory notification duties, and trust with employees and partners. Ransomware incidents can also interrupt operations, though whether production systems were affected here is not stated. Because the people-affected count is unknown and the precise data types remain undisclosed, the prudent stance is to assume elevated risk for anyone closely tied to the company until more is known, without treating every possible harm as proven.
Were you affected?
If you work or have worked for Harmony Gold, or if you are a contractor, supplier, or partner who shared personal or business information with the company, monitor accounts for unusual activity, treat unexpected messages that reference the firm with caution, and consider placing fraud alerts or credit monitoring where that is available in your country. Change passwords on work-related and personal accounts if you reused credentials, and enable multi-factor authentication where you can. Official notices from the company, if issued, should take priority over unverified third-party claims.
Public detail on this incident is limited. Readers who want a practical next check can run a free exposure scan of their email address to see whether their information has already surfaced in known breach datasets, and then follow up on any confirmed hits with password changes and closer account monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Goiasa Listed by akira Ransomware GroupAqualectra Holdings Listed by akira Ransomware GroupBioPower SustainableEnergy Corporation Listed by akira Ransomware GroupREV Engineering Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Harmony Gold Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.