Novasport s.r.o. Listed by akira Ransomware Group: What Was Exposed & What To Do
Novasport s.r.o. was listed by the Akira ransomware group on July 21, 2026, with internal files reported as exfiltrated. Individuals should check whether their information was involved and take appropriate protective steps.
Ransomware groups continue to pressure organisations by pairing encryption with the threat of public data leaks, a pattern that has become a fixture of the current cyber-threat landscape. Listings on criminal leak sites often surface before independent confirmation, leaving employees, partners and customers to weigh incomplete claims against real personal and commercial risk.
On 21 July 2026, the ransomware group known as Akira listed Novasport s.r.o. among its claimed victims. Public detail remains limited: the number of people affected is unknown, and the only concrete assertions about what was taken come from the group’s own statement. That statement matters because it alleges the exfiltration of internal corporate files, including material that could identify employees and business relationships.
Breaking down the breach
According to the listing reported on 21 July 2026, Akira claims to have conducted a ransomware attack against Novasport s.r.o. in which internal files were exfiltrated. The group stated it would upload approximately 17 GB of corporate data and described the material as including detailed employee information (passports and other information), projects, contracts, financials, and client information. No independent confirmation of the intrusion method, the precise date of compromise, or the full scope of systems involved has been made public. The number of individuals potentially affected is undisclosed. The listing itself constitutes a claim by the threat actor rather than a verified disclosure by the company.
Who is akira?
Akira is a ransomware operation that emerged in public reporting in 2023 and has since been associated with double-extortion tactics: encrypting victim systems while also stealing data and threatening to publish it if a ransom is not paid. The group typically maintains a leak site on which it names organisations and, in many cases, posts samples or larger archives of stolen files. Its victims have spanned manufacturing, professional services and other sectors across multiple countries. Akira affiliates have been observed using common initial-access routes such as compromised VPN or remote-access credentials, followed by lateral movement and data staging before encryption. None of these general patterns has been independently confirmed as the method used against Novasport s.r.o.; they describe only the group’s established public profile. Any specific assertions about this incident—volume of data, categories of files, or planned publication—remain claims made by the group on its listing.
About Novasport s.r.o.
Novasport s.r.o. presents itself, in the material quoted on the leak site, as a global manufacturer of LEKI-brand ski, hiking and Nordic walking poles. The same text states that the company was founded in 1992 by Klaus Lenhart, owner of the LEKI brand, and notes LEKI’s history of collaboration with top athletes. Organisations of this type typically hold employee records, supplier and customer contracts, product and project documentation, and financial data necessary to run an international manufacturing and distribution business. A breach affecting such a firm is consequential because it can expose both the personal data of staff and the commercial details of partners and clients who rely on the company’s supply chain and brand relationships.
The information in question
The facts available name the exposed material only in general terms: internal files said to have been exfiltrated in a ransomware attack. The group’s own description claims the forthcoming 17 GB archive would contain detailed employee information including passports and other information, together with projects, contracts, financials and client information. Exact contents have not been independently verified, and no confirmed inventory of files or affected individuals has been published. Manufacturers in the sporting-goods sector commonly retain personnel files, identity documents for travel or compliance, commercial agreements, pricing and customer lists, and internal financial records; whether any or all of those categories were in fact taken in this case remains unconfirmed beyond the actor’s claim.
Why it matters
If the claimed data are authentic, employees could face risks of identity misuse, targeted phishing or fraud that exploits passport details and other personal identifiers. Business partners and clients named in contracts or project files may become targets for social-engineering attempts that reference genuine commercial relationships. For the organisation, publication of financials, contracts and internal projects can damage negotiating positions, reveal competitive information and create regulatory or contractual notification obligations. Even when the full scale is unknown, the combination of personal and commercial data in a single alleged archive raises concrete downstream harms that individuals and counterparties cannot simply ignore.
Were you affected?
If you are a current or former employee, contractor or business contact of Novasport s.r.o., treat the listing as a signal to increase vigilance rather than as proof that your specific records were taken. Monitor financial and identity accounts for unusual activity, be cautious of unsolicited messages that reference the company or its brands, and consider placing fraud alerts where appropriate. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Official confirmation from the company or competent authorities, if and when it arrives, should guide any further steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Finer & Finer Listed by akira Ransomware GroupVandalia Rental Listed by akira Ransomware GroupUniversity Sprinkler Systems Listed by akira Ransomware GroupKruse Construction Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Novasport s.r.o. Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.