Selig Enterprises; AAA Parking Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Selig Enterprises and AAA Parking were listed by the Akira ransomware group on 23 September 2025 after internal files were exfiltrated in a ransomware attack; the date of the intrusion itself has not been established. Individuals connected to either organisation should check for any contact from the companies and review their accounts and personal information for signs of misuse.
People whose personal or financial details sit inside the systems of a real-estate firm or a parking operator may now face a concrete risk of exposure. On 23 September 2025 the ransomware group known as akira listed Selig Enterprises and AAA Parking on its leak site, claiming it had taken internal files from both organisations. The number of individuals affected remains unknown, yet the types of material the group says it holds—employee identity documents and client records that include names, dates of birth and Social Security numbers—carry lasting consequences for identity theft, fraud and privacy loss.
Public detail is limited to the group’s own listing and a short accompanying description. No independent confirmation of the intrusion, the volume of data, or any ransom demand has been released by the companies themselves. What follows is a careful account of what is known, what is claimed, and what ordinary people can do next.
Inside the incident
According to the listing published on 23 September 2025, akira asserts that it has exfiltrated internal files belonging to two related entities: Selig Enterprises and AAA Parking. The group states it is prepared to upload 81 GB of corporate documents. The description supplied with the listing characterises the material as employee personal documents such as passports and driver’s licences, client personal information including full names, dates of birth, Social Security numbers and telephone numbers, together with detailed accounting and financial records and credit-related data. The listing does not disclose the date of the initial intrusion, the method of access, or whether systems were encrypted in addition to the claimed data theft. No statement from either company confirming or denying the claims has been made public, and the number of people whose information may be involved remains unknown.
Inside akira
Akira is a ransomware operation that first drew wide attention in 2023. Like many contemporary groups, it typically employs a double-extortion model: after gaining access to a network it steals data, encrypts systems, and then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has previously targeted organisations across manufacturing, education, healthcare and professional services in North America and Europe. Its operators commonly exploit known vulnerabilities, weak remote-access credentials or compromised third-party software to enter networks, then move laterally to locate valuable file shares and databases. Public reporting has documented both Windows and Linux variants of its ransomware. The appearance of Selig Enterprises and AAA Parking on the group’s site is therefore a claim by the actors themselves; it does not by itself constitute independent verification that the intrusion occurred or that the stated volume of data was taken.
Selig Enterprises; AAA Parking and its sector
Selig Enterprises is described in the listing as a real-estate company whose portfolio exceeds 15 million square feet of retail, industrial, residential, hotel, office and mixed-use properties across the southeastern United States. AAA Parking, headquartered in Atlanta and founded in 1956, is a parking-management firm. Organisations of this kind routinely maintain large volumes of tenant, customer and employee records, lease and payment histories, insurance documentation, and operational financial data. Because parking and property-management businesses interact daily with the public and with commercial tenants, they often hold identity and payment information that can be reused for fraud if it falls into the wrong hands. A breach affecting either firm therefore carries implications not only for staff but also for clients and property users whose personal details may have been stored for billing, access control or background-check purposes.
What data was at risk
The only data types named in the public record are “internal files exfiltrated in a ransomware attack.” The group’s own listing elaborates that the 81 GB package it claims to hold includes employee personal documents (passports and driver’s licences), client personal information (full name, date of birth, Social Security number, telephone number and similar fields), detailed accounting and financial records, and credit-related material. These categories are presented solely as the group’s assertion; independent confirmation of the precise contents or completeness of the archive has not been published. Organisations in real estate and parking management typically retain precisely such records for employment, leasing, payment processing and regulatory compliance, so the claimed categories are consistent with ordinary business practice. Exact file counts, the presence or absence of any particular individual’s data, and whether the material has already been released remain unconfirmed.
The real-world impact
If the claimed data are authentic and subsequently published or sold, affected employees could face identity theft, fraudulent loan applications or tax-refund fraud that exploit passport, driver’s-licence or Social Security details. Clients whose names, dates of birth and contact information appear in the archive may experience targeted phishing, account takeovers or unsolicited credit applications. Financial and accounting files could expose banking relationships, vendor contracts or internal cost structures, creating secondary risks of business-email compromise or competitive harm. For the organisations themselves, the incident may trigger regulatory notification duties, contractual obligations to tenants and customers, and the operational cost of forensic investigation and system restoration. Because the number of people affected is unknown and the data have not been independently verified, the scale of these harms cannot yet be quantified; the practical risk, however, is real for anyone whose information was stored in the systems described.
What to do if you're exposed
Anyone who has been an employee, tenant, customer or vendor of Selig Enterprises or AAA Parking should treat the possibility of exposure seriously. Begin by placing a free fraud alert with the major credit bureaus and reviewing recent credit reports for unfamiliar accounts. Monitor bank and credit-card statements closely and enable multi-factor authentication on email and financial accounts. If you receive unexpected requests for personal information or notices of password resets you did not initiate, treat them as potential phishing. Consider freezing your credit if you believe sensitive identifiers such as a Social Security number may have been involved. Finally, readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an early indication of whether further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Phillips Scales Listed by akira Ransomware GroupAdelman & Gettleman Listed by akira Ransomware GroupRodenburg Law Firm Listed by akira Ransomware GroupThe Minor Firm Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.