TOP Ships Inc., Stock Symbol TOPS Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
TOP Ships Inc. (stock symbol: TOPS) was listed by the Akira ransomware group on 27 May 2025, with internal files reported to have been exfiltrated. Anyone connected to the company is advised to check their exposure and review their security measures.
Ransomware groups continue to pressure organizations by combining system encryption with the public threat of data exposure, a pattern that has become a routine feature of the modern cyber-threat landscape. In this environment, even listings that remain unverified can create lasting uncertainty for companies and the people connected to them. On May 27, 2025, the ransomware group known as akira listed TOP Ships Inc., the publicly traded shipping firm with stock symbol TOPS, among its claimed victims. Public detail remains limited, yet the listing itself raises clear questions about the security of corporate records and the potential exposure of individuals whose information may have been held by the company.
What is known so far rests on the group’s own statements and the basic public profile of the organization. No independent confirmation of the full scope, method, or exact timing of any intrusion has been provided in the available record. The episode therefore sits among the many recent incidents in which a ransomware actor asserts control over stolen files and promises to release them, leaving affected parties to assess risk with incomplete information.
What happened
According to the available record, TOP Ships Inc. was listed by the akira ransomware group on May 27, 2025. The group claims that it conducted a ransomware attack in which internal files were exfiltrated. In its statement the group asserts that it intends to upload approximately 65 GB of corporate data and describes the material as containing “lots of documents with detailed employee personal information, detailed financial data, contracts, certificates, etc.” The number of people affected is unknown. No further technical details—such as the initial access vector, the duration of any intrusion, or whether systems were encrypted—have been disclosed in the public facts. The listing therefore stands as an unverified claim by the threat actor rather than a confirmed forensic finding.
Inside akira
Akira is a ransomware operation that has been publicly documented since early 2023. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. The group has targeted organizations across multiple sectors, often focusing on mid-sized enterprises whose operational continuity and regulatory obligations make downtime or data exposure costly. Public reporting has associated akira with the use of common initial-access techniques, credential theft, and the rapid movement of data once inside a network. Its leak-site postings routinely include sample files and volume claims intended to demonstrate possession of stolen material. In the present case, the group’s assertion that it holds roughly 65 GB of TOP Ships data and that the files include employee personal information, financial records, contracts and certificates should be treated strictly as a claim made by the actor; independent verification of those contents has not been supplied in the available facts.
TOP Ships Inc. and its sector
TOP Ships Inc. is described as an international owner and operator of modern, fuel-efficient “ECO” tanker vessels that currently focus on the transportation of crude oil and petroleum products. As a publicly listed company (stock symbol TOPS), it operates within the global maritime and energy-logistics sector. Organizations of this type routinely manage vessel operations, crew and shore-side personnel records, commercial contracts, regulatory certificates, financial statements, and correspondence with charterers, insurers and port authorities. The sector is characterized by complex supply chains, international regulatory oversight, and the need to maintain continuous vessel schedules. A breach affecting such an entity can therefore touch both corporate commercial interests and the personal data of employees and contractors who work across multiple jurisdictions.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. The only more specific description comes from the group’s own claim that the material comprises approximately 65 GB of corporate data containing detailed employee personal information, detailed financial data, contracts, certificates and similar documents. Exact data types beyond this description have not been independently confirmed, and the number of individuals whose records may be involved remains unknown. Organizations in the tanker-shipping sector typically hold personnel files (names, contact details, identification documents, payroll and employment contracts), financial ledgers, vessel certificates, commercial agreements and operational correspondence. Whether any of those categories were in fact present in the claimed 65 GB archive is unconfirmed; the public record does not list verified file inventories or sample contents beyond the group’s statement.
Why it matters
If the claimed data are authentic, employees and contractors could face risks of identity misuse, targeted phishing, or unauthorized disclosure of personal details. Financial and contractual records, if exposed, may reveal commercial terms, banking relationships or regulatory filings that competitors or other parties could exploit. For the company itself, the incident creates potential regulatory scrutiny, contractual notification duties, and reputational pressure, particularly given its status as a publicly traded firm. Even when the precise contents remain unverified, the mere listing on a ransomware leak site can generate uncertainty among staff, investors and business partners. Because the number of people affected is unknown and the exact files have not been independently catalogued, the real-world impact cannot yet be quantified; the risk, however, is concrete enough to warrant practical caution by anyone who has had a professional or commercial relationship with the organization.
What to do if you're exposed
Individuals who believe their information may have been held by TOP Ships Inc. should monitor financial accounts and credit reports for unusual activity, enable multi-factor authentication on email and other critical services, and treat unsolicited messages that reference the company or the shipping sector with heightened skepticism. Changing passwords that may have been reused across personal and work accounts is a prudent first step. Because public confirmation of specific records is still lacking, the most reliable immediate action is simply to remain alert rather than to assume any particular document has been released. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an additional, independent signal of whether personal credentials have circulated more widely.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
TOP Ships Listed by akira Ransomware GroupJDC Air & Sea Freight (HEUEL LOGISTICS Group) Listed by akira Ransomware GroupFranman Listed by akira Ransomware GroupWatertech of America, WorldPoint ECC, Mastermedia, Garrett Leather, Guttenberg Industries. Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.