Summit Almonds Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Summit Almonds Listed by akira Ransomware Group (reported March 13, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
People whose contact details, personal documents or business records may have been taken in a ransomware incident involving Summit Almonds face practical risks that can surface months later: unwanted calls, targeted phishing that references real names or contracts, or attempts to misuse identity information. Public reporting places the listing on 13 March 2024, yet the number of individuals affected remains unknown and the precise scope of what left the company’s systems has not been independently confirmed.
What is known so far comes largely from a claim posted by the ransomware group that says it holds the data. For anyone who has dealt with Summit Almonds as a grower, handler, partner or employee, the immediate question is whether their own information is among the material the group says it will publish.
Breaking down the breach
On 13 March 2024 Summit Almonds appeared on a leak site operated by the Akira ransomware group. The listing asserts that internal files were exfiltrated during a ransomware attack and that 33 GB of data would be released. No further technical details—such as the initial access method, the duration of the intrusion, or whether encryption was also deployed—have been made public by the company or by independent investigators. The number of people whose records may be involved is listed as unknown. All statements about volume and content originate from the group’s own claim rather than from a verified disclosure by Summit Almonds.
Who is akira?
Akira is a ransomware operation that has been active since early 2023. Like many contemporary groups it practices double extortion: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group typically posts victims on a dedicated leak site, often with sample files and a countdown, and has targeted organisations across manufacturing, professional services and agriculture-related sectors. Public reporting has linked Akira to the use of common initial-access techniques such as compromised VPN credentials and exploitation of unpatched remote-access software. Claims made on its leak site, including the assertion that 33 GB of Summit Almonds material will be released, remain unverified assertions by the actors themselves.
Who is Summit Almonds?
Summit Almonds assists California almond, walnut and other tree-nut growers and handlers in marketing high-quality product to partners and end users around the world. Companies in this sector routinely maintain supplier lists, shipping and quality records, contracts, non-disclosure agreements and contact databases that include growers, buyers, logistics partners and internal staff. Because the business sits at the intersection of agriculture and international trade, a compromise can expose both commercial information and personal details of individuals who may never have expected their data to leave a specialised marketing firm. The consequential nature of the incident therefore extends beyond the company itself to the wider network of California nut producers and their overseas customers.
The information in question
Public detail on the exact contents remains limited to the group’s own description. Akira claims the material consists of personal documents, NDAs, forms containing personal information, and a database with more than 10 000 lines of phone numbers and email addresses. The organisation has not independently confirmed these categories or the 33 GB figure. Organisations of this type typically hold grower and customer contact lists, contractual paperwork, shipping documentation and internal administrative files; whether any of those specific categories left Summit Almonds’ systems is unconfirmed. Until a fuller accounting is provided, the only named data types that can be reported are the internal files the group says it exfiltrated.
Why it matters
For individuals whose phone numbers or email addresses appear in the claimed database, the most immediate risks are phishing and social-engineering attempts that reference real business relationships. Personal documents and NDAs, if authentic, could enable more targeted fraud or reputational pressure. For Summit Almonds the exposure of commercial contracts and partner lists can undermine trust with growers and buyers and create longer-term competitive and regulatory concerns. Because the total number of affected people is unknown, the practical impact may range from a handful of contacts to thousands of growers and staff whose details were stored for ordinary business purposes. The absence of confirmed containment or notification details leaves those individuals without clear guidance on whether their own records are involved.
If your data was in this claimed breach
Treat any unsolicited contact that references Summit Almonds, almond or walnut contracts, or personal forms as potentially malicious until verified through a known channel. Change passwords on accounts that share the same email address used with the company, enable multi-factor authentication where available, and monitor financial and credit statements for unexpected activity. If you receive documents that appear to be internal Summit Almonds files, do not open them; report them to the company through an official contact method. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets, which can provide an early indication of wider exposure even when a specific incident remains only partially documented.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
A Bar A Ranch Listed by akira Ransomware GroupTillamook Country Smoker Listed by akira Ransomware GroupTillamook Country Smoker (tcsmoker.com) Listed by akira Ransomware GroupAstor Chocolate Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Summit Almonds Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.