LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Nobu Restaurants Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Nobu Restaurants Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 8, 2025
Nobu Restaurants Listed by akira Ransomware Group

Reported October 8, 2025.

HIGH
Severity
October 8, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Nobu Restaurants was listed on October 08, 2025 by the Akira ransomware group, which claims to have exfiltrated internal files. Individuals who may have personal or financial data on file with Nobu are advised to review the group’s claims and monitor their accounts for unusual activity.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 08, 2025, Nobu Restaurants was listed by the Akira ransomware group, which claims to have exfiltrated internal files in a ransomware attack. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the full scope or method has been released. The listing itself constitutes an unverified claim by the group that it holds corporate material and intends to publish it.

For a high-profile hospitality brand, even an unconfirmed listing raises practical concerns about the security of internal records and the potential exposure of people connected to the business. What is known so far rests on the group's own statements rather than verified forensic disclosure.

Breaking down the breach

According to the available record, Nobu Restaurants was named on Akira's leak site on October 08, 2025. The group states that internal files were exfiltrated as part of a ransomware attack and that it will upload more than 71 GB of corporate documents. It further claims the material includes employee and owners information such as passports, driver licenses, Social Security numbers and similar identifiers, detailed financials, confidential files, and NDAs. The group specifically asserts that Robert De Niro's Social Security number and details of his earnings from the business are among the data. No independent verification of these claims, the precise date of intrusion, the attack vector, or the total volume of data has been made public. The number of individuals potentially affected remains unknown.

The group behind it: akira

Akira is a ransomware operation that has been active since early 2023 and is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group typically posts victims on a dedicated leak site, often with sample files or volume claims, and has targeted a range of sectors including manufacturing, education, and professional services. Public reporting describes Akira as using relatively straightforward initial access methods such as compromised credentials or vulnerable remote-access tools, followed by lateral movement and data staging before encryption. In this case, the listing of Nobu Restaurants and the accompanying statements about 71 GB of documents and specific personal and financial records are claims made by the group; they have not been independently confirmed.

Nobu Restaurants and its sector

Nobu Restaurants is a world-renowned Japanese restaurant group recognized for pioneering a new-style Japanese cuisine. It began as a business partnership in 1994 between Chef Nobu Matsuhisa and partners including Academy Award-winning actor Robert De Niro, producer Meir Teper, and restaurateur Drew Nieporent. The brand operates high-end restaurants and related hospitality venues internationally. Organizations of this type routinely maintain employee records, owner and investor information, financial statements, contracts, NDAs, and operational documents. A breach claim against such a business is consequential because the hospitality sector handles both sensitive personal data of staff and partners and commercially valuable internal material; any confirmed exposure can affect individuals' privacy and the company's commercial relationships.

What was likely exposed

The facts name the exposed material only as "internal files exfiltrated in ransomware attack." The Akira group claims the data set exceeds 71 GB and includes employee and owners information (passports, driver licenses, Social Security numbers and similar identifiers), detailed financials, confidential files, and NDAs, and specifically asserts the presence of Robert De Niro's Social Security number and earnings information. These details remain unverified claims. Exact contents have not been independently disclosed. Organizations in the restaurant and hospitality sector typically hold employee personnel files, identification documents, payroll and tax records, ownership and partnership agreements, financial ledgers, vendor contracts, and non-disclosure agreements. Whether any or all of those categories were in fact taken in this incident is unconfirmed.

What's at stake

If the claimed material is authentic and later published, individuals whose personal identifiers appear could face elevated risk of identity theft, fraudulent account openings, or targeted social-engineering attempts. Owners and senior figures named in financial or ownership documents may encounter privacy and reputational exposure. For the organization itself, the release of confidential commercial files, NDAs, or detailed financials could affect negotiations, competitive position, and regulatory or contractual obligations. Because the number of people affected is unknown and the data have not been independently verified, the concrete scale of harm cannot yet be measured; the primary immediate risk is the uncertainty created by the group's public claims.

What to do if you're exposed

Anyone who has worked for, partnered with, or otherwise shared personal or financial information with Nobu Restaurants should treat the situation cautiously. Monitor bank and credit accounts for unusual activity, consider placing a fraud alert or credit freeze with the major credit bureaus, and be alert to phishing or social-engineering attempts that reference the company or its principals. If you receive notification from the company, follow its official guidance. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Until more verified detail emerges, these practical steps remain the most useful immediate response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyNobu Restaurants security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Nobu Restaurants’s full breach history →

More recent breaches

Panini Kabob Grill Listed by akira Ransomware GroupNovember 28, 2025Country Club Enterprises Listed by akira Ransomware GroupNovember 27, 2025Global Miami JV Listed by akira Ransomware GroupNovember 26, 2025Basin Harbor Listed by akira Ransomware GroupOctober 20, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Nobu Restaurants Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram