Nobu Restaurants Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Nobu Restaurants was listed on October 08, 2025 by the Akira ransomware group, which claims to have exfiltrated internal files. Individuals who may have personal or financial data on file with Nobu are advised to review the group’s claims and monitor their accounts for unusual activity.
On October 08, 2025, Nobu Restaurants was listed by the Akira ransomware group, which claims to have exfiltrated internal files in a ransomware attack. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the full scope or method has been released. The listing itself constitutes an unverified claim by the group that it holds corporate material and intends to publish it.
For a high-profile hospitality brand, even an unconfirmed listing raises practical concerns about the security of internal records and the potential exposure of people connected to the business. What is known so far rests on the group's own statements rather than verified forensic disclosure.
Breaking down the breach
According to the available record, Nobu Restaurants was named on Akira's leak site on October 08, 2025. The group states that internal files were exfiltrated as part of a ransomware attack and that it will upload more than 71 GB of corporate documents. It further claims the material includes employee and owners information such as passports, driver licenses, Social Security numbers and similar identifiers, detailed financials, confidential files, and NDAs. The group specifically asserts that Robert De Niro's Social Security number and details of his earnings from the business are among the data. No independent verification of these claims, the precise date of intrusion, the attack vector, or the total volume of data has been made public. The number of individuals potentially affected remains unknown.
The group behind it: akira
Akira is a ransomware operation that has been active since early 2023 and is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group typically posts victims on a dedicated leak site, often with sample files or volume claims, and has targeted a range of sectors including manufacturing, education, and professional services. Public reporting describes Akira as using relatively straightforward initial access methods such as compromised credentials or vulnerable remote-access tools, followed by lateral movement and data staging before encryption. In this case, the listing of Nobu Restaurants and the accompanying statements about 71 GB of documents and specific personal and financial records are claims made by the group; they have not been independently confirmed.
Nobu Restaurants and its sector
Nobu Restaurants is a world-renowned Japanese restaurant group recognized for pioneering a new-style Japanese cuisine. It began as a business partnership in 1994 between Chef Nobu Matsuhisa and partners including Academy Award-winning actor Robert De Niro, producer Meir Teper, and restaurateur Drew Nieporent. The brand operates high-end restaurants and related hospitality venues internationally. Organizations of this type routinely maintain employee records, owner and investor information, financial statements, contracts, NDAs, and operational documents. A breach claim against such a business is consequential because the hospitality sector handles both sensitive personal data of staff and partners and commercially valuable internal material; any confirmed exposure can affect individuals' privacy and the company's commercial relationships.
What was likely exposed
The facts name the exposed material only as "internal files exfiltrated in ransomware attack." The Akira group claims the data set exceeds 71 GB and includes employee and owners information (passports, driver licenses, Social Security numbers and similar identifiers), detailed financials, confidential files, and NDAs, and specifically asserts the presence of Robert De Niro's Social Security number and earnings information. These details remain unverified claims. Exact contents have not been independently disclosed. Organizations in the restaurant and hospitality sector typically hold employee personnel files, identification documents, payroll and tax records, ownership and partnership agreements, financial ledgers, vendor contracts, and non-disclosure agreements. Whether any or all of those categories were in fact taken in this incident is unconfirmed.
What's at stake
If the claimed material is authentic and later published, individuals whose personal identifiers appear could face elevated risk of identity theft, fraudulent account openings, or targeted social-engineering attempts. Owners and senior figures named in financial or ownership documents may encounter privacy and reputational exposure. For the organization itself, the release of confidential commercial files, NDAs, or detailed financials could affect negotiations, competitive position, and regulatory or contractual obligations. Because the number of people affected is unknown and the data have not been independently verified, the concrete scale of harm cannot yet be measured; the primary immediate risk is the uncertainty created by the group's public claims.
What to do if you're exposed
Anyone who has worked for, partnered with, or otherwise shared personal or financial information with Nobu Restaurants should treat the situation cautiously. Monitor bank and credit accounts for unusual activity, consider placing a fraud alert or credit freeze with the major credit bureaus, and be alert to phishing or social-engineering attempts that reference the company or its principals. If you receive notification from the company, follow its official guidance. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Until more verified detail emerges, these practical steps remain the most useful immediate response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Panini Kabob Grill Listed by akira Ransomware GroupCountry Club Enterprises Listed by akira Ransomware GroupGlobal Miami JV Listed by akira Ransomware GroupBasin Harbor Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Nobu Restaurants Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.