Ondunova Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Ondunova was listed by the Akira ransomware group on January 21, 2025, with internal files reported as exfiltrated from the organisation. Individuals connected to Ondunova should check whether their information is involved and take any recommended protective steps.
On January 21, 2025, the manufacturing group Ondunova was listed on a leak site operated by the ransomware group known as akira. Public reporting indicates that the listing concerns a ransomware attack in which internal files were claimed to have been exfiltrated. The number of people affected remains unknown, and independent confirmation of the full scope is limited.
The listing matters because Ondunova operates in industrial packaging production and holds corporate records that can include employee and customer contact details. When a ransomware group claims possession of such material, the practical risk is that sensitive business and personal information could be published or misused if the claim is accurate.
Breaking down the breach
According to the available record, Ondunova was listed by the akira ransomware group on January 21, 2025. The reported summary states that internal files were exfiltrated in a ransomware attack. The group claims it is ready to upload more than 31 GB of essential corporate documents. Specifics about the initial intrusion method, the exact date of compromise, and whether any ransom demand was paid or negotiations occurred have not been publicly disclosed in the material provided.
The listing itself is an assertion by the threat actor rather than a verified forensic report. No independent count of affected individuals has been released, and the precise timeline of the incident beyond the January 21, 2025 reporting date remains unconfirmed.
The group behind it: akira
Akira is a ransomware operation that has been active in recent years and is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. The group typically targets organizations across manufacturing, professional services, and other sectors, posting victim names and sample file descriptions to increase pressure. Public reporting has documented multiple prior listings in which akira claimed large volumes of corporate documents, financial records, and contact data.
In this case, the group claims it holds more than 31 GB of Ondunova material and lists categories such as NDAs, financial data, internal correspondence, and employee and customer contact details. Those claims should be treated as assertions by the actor until corroborated by the victim or independent investigators. No further statements attributed specifically to this incident beyond the leak-site listing appear in the available facts.
Who is Ondunova?
Ondunova is described as one of the leading corrugated cardboard packaging manufacturing groups in Catalonia. It is formed by the companies Ondunova and Wondu, with production centers in Santa Margarida i Els Monjos, Barcelona. Organizations of this type typically manage supplier contracts, production schedules, quality and compliance records, employee information, and customer order and contact data.
A breach involving a packaging manufacturer is consequential because the sector sits in supply chains that serve other businesses. Exposure of internal files can disrupt commercial relationships, reveal pricing or payment arrangements, and place employees and customers at risk of targeted phishing or social-engineering attempts that use authentic-looking contact details.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. The group claims the material includes more than 31 GB of essential corporate documents such as NDAs, financial data (audits, payment details, reports), internal correspondence, and contact numbers and e-mail addresses of employees and customers. Exact file inventories, the full set of data types, and any confirmation that every listed category is present have not been independently verified in the public record.
Organizations in manufacturing commonly hold payroll and HR records, vendor contracts, invoices, and customer lists. Because the precise contents remain unconfirmed beyond the actor’s description, it is not possible to state with certainty which specific records of which individuals are involved.
What's at stake
For employees and customers whose contact details or correspondence may be among the claimed files, the immediate risks include phishing, business-email compromise attempts, and unwanted contact that leverages real names, numbers, or addresses. Financial documents, if authentic, could expose payment practices or audit findings that competitors or fraudsters might exploit. For the organization, the stakes include operational disruption, potential regulatory notification duties under applicable data-protection rules, and reputational damage if the claimed data is published.
Because the number of people affected is unknown and the full data set is unconfirmed, the scale of personal impact cannot yet be quantified. The prudent assumption is that anyone who has worked with or for Ondunova or Wondu should treat the possibility of exposure seriously until clearer information emerges.
Were you affected?
If you are an employee, former employee, customer, or supplier of Ondunova or Wondu, consider the following practical steps:
- Monitor email and phone contacts for unusual messages that reference packaging orders, invoices, or internal company matters.
- Change passwords on work-related and personal accounts that may have been used in correspondence with the company, and enable multi-factor authentication where available.
- Review bank and payment accounts for unexpected activity if you have shared financial details with the firm.
- Treat unsolicited requests for further personal or payment information with caution, even if they appear to come from known contacts.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach data sets.
Public detail on this incident remains limited to the January 21, 2025 listing and the group’s claim of more than 31 GB of internal files. Further official statements from Ondunova, if issued, will provide the most reliable guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Saxun by Giménez Ganga Listed by akira Ransomware GroupLaboratoriosBelloch (Nelly, Yunsey,Fresh feel) Listed by akira Ransomware GroupAv Alumitran Listed by akira Ransomware GroupTaylor Clay Products Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Ondunova Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.