LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pacific Summit Energy, Sumitomo Corporation affiliate Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Pacific Summit Energy, Sumitomo Corporation affiliate Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 22, 2025
Pacific Summit Energy, Sumitomo Corporation affiliate Listed by akira Ransomware Group

Reported April 22, 2025.

HIGH
Severity
April 22, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pacific Summit Energy, a Sumitomo Corporation affiliate, was listed by the akira ransomware group on April 22, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; anyone who has done business with the company should verify whether their data was exposed and consider protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target energy and commodities firms as part of a broader pattern of double-extortion attacks that combine system disruption with the threat of data publication. In this landscape, listings on criminal leak sites have become a routine pressure tactic, even when independent confirmation of the underlying intrusion remains limited.

On 22 April 2025, the ransomware group known as akira listed Pacific Summit Energy, an affiliate of Sumitomo Corporation, among its claimed victims. Public detail is limited: the number of people affected is unknown, and the only confirmed description is that internal files were allegedly exfiltrated in a ransomware attack. The group asserts it will publish more than 163 GB of corporate data; that assertion has not been independently verified.

Inside the incident

According to the available record, Pacific Summit Energy was listed by the akira ransomware group on 22 April 2025. The organisation is described as a Sumitomo Corporation affiliate active in natural gas, power, crude oil and LNG markets. The sole technical detail provided is that internal files were allegedly exfiltrated during a ransomware attack. No public information has been released about the initial access method, the duration of the intrusion, the encryption status of systems, or any ransom demand. The scale of impact on individuals is listed as unknown.

The group’s own statement claims it intends to upload more than 163 GB of material and enumerates categories that include detailed employee personal information, Sumitomo Corporation internal files, financial records, client data, confidential agreements, project information and NDAs. These remain claims made on the leak site rather than confirmed findings from the victim or independent investigators.

Inside akira

Akira is a ransomware operation that emerged in early 2023 and has since conducted numerous double-extortion campaigns. The group typically encrypts systems while simultaneously exfiltrating data, then pressures victims by threatening to publish the stolen material on a dedicated leak site. Public reporting has associated akira with attacks across multiple sectors, including manufacturing, professional services and energy-related firms. Its operators are known to negotiate ransoms and to release data samples when payments are not made. In the present case the group has listed Pacific Summit Energy and asserted the volume and nature of the data; those assertions have not been corroborated by external sources.

Who is Pacific Summit Energy?

Pacific Summit Energy operates as an affiliate of Sumitomo Corporation and provides expertise in natural gas, power, crude oil and liquefied natural gas markets. Organisations of this type routinely handle commercial contracts, trading data, financial documentation and personal information belonging to employees and counterparties. Because energy-trading firms sit at the intersection of commodity markets and large corporate networks, a breach can affect both the immediate company and related entities within a wider corporate group. The listing therefore carries potential consequences beyond a single office or business unit.

What data was at risk

The public record states only that internal files were exfiltrated. The akira group claims the material exceeds 163 GB and includes detailed employee personal information such as passports, driver licences and credit-card details, numerous Sumitomo Corporation internal files, financial data including audits, reports and invoices, client data, confidential agreements, project information and large numbers of NDAs. These categories are presented solely as the group’s assertions. No independent inventory of the files has been published, and the exact contents remain unconfirmed. Firms in the energy-trading sector typically retain precisely the kinds of records the group describes—employee identity documents, financial statements, client contracts and non-disclosure agreements—so the claimed categories are plausible, yet they cannot be treated as Reported Facts.

Why it matters

If the claimed data were released, employees could face identity-theft and fraud risks arising from passport, licence and payment-card details. Counterparties and clients might see sensitive commercial terms or project information exposed, potentially affecting negotiations or competitive positions. For Pacific Summit Energy and its parent group, the publication of financial audits, invoices and internal files could create regulatory, contractual and reputational complications. Because the number of affected individuals is unknown and the precise contents unconfirmed, the practical harm cannot yet be quantified; the risk, however, is concrete for anyone whose personal or commercial records were among the exfiltrated files.

Were you affected?

Individuals who have worked for or contracted with Pacific Summit Energy or related Sumitomo entities should monitor financial accounts and credit reports for unusual activity and consider placing fraud alerts if identity documents may have been involved. Organisations that shared confidential agreements or project data with the firm may wish to review those materials for sensitivity. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if any are issued by the company, remain the most reliable source of confirmation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPacific Summit Energy security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Pacific Summit Energy’s full breach history →

More recent breaches

Pearl River Valley Electric Power Association Listed by akira Ransomware GroupNovember 19, 2025Agralite Electric Cooperative Listed by akira Ransomware GroupDecember 24, 2025Watertech of America, WorldPoint ECC, Mastermedia, Garrett Leather, Guttenberg Industries. Listed by akira Ransomware GroupDecember 24, 2025Household & Commercial Products Association Listed by akira Ransomware GroupDecember 18, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Pacific Summit Energy, Sumitomo Corporation affiliate Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram