SYS::ONLINE
Wasteland.
Briefs2264
Issues25
SinceFeb 2026
LIVE
█ Ransomware DAVIS-FERBER-AKIRA 2026-08-26

Davis & Ferber: Akira Ransomware Leak Site Listing

"The Akira ransomware group added Long Island personal injury and malpractice firm Davis & Ferber LLP to its dark web leak site on August 25, 2026, claiming 60 GB of corporate data and detailed personal records for…"

The Akira ransomware group added Long Island personal injury and malpractice firm Davis & Ferber LLP to its dark web leak site on August 25, 2026, claiming 60 GB of corporate data and detailed personal records for "almost a thousand people." The listing is corroborated across four independent trackers (Cyber Threat Intelligence, Breach House, HookPhish and, via ThreatMon telemetry, UNDERCODE NEWS), all of which reproduce the same operator-written summary. As of this writing there is no statement from the firm, no regulator filing, and no confirmed victim notification. Every claim about scope originates with the attacker.

What Happened

Akira published a victim entry for Davis & Ferber (davisferber.com) on its leak site on August 25, 2026. HookPhish timestamps its capture of the post at 2026-08-25T12:22:44 UTC; UNDERCODE NEWS, relaying a ThreatMon alert, gives 19:01:42 UTC+3 the same day. Breach House logs discovery and publication both on August 25 and records the firm's disclosure status as "Not disclosed yet," giving a Window Zero of zero days so far, meaning the leak site post is still the only public account of the incident.

Two caveats matter. First, a leak site listing is a claim, not a confirmed intrusion. UNDERCODE NEWS states the point directly: the available information establishes only that a monitoring service detected an alleged victim listing, and does not establish whether files were encrypted, whether data was exfiltrated, or how much. Second, the tracker records are not internally consistent. Breach House categorises Davis & Ferber as "Retail / E-commerce" with "+1000" employees, which contradicts its own attack summary describing a New York law firm, and contradicts the "Professional Services" classification used by Cyber Threat Intelligence and HookPhish. Treat the Breach House sector and headcount fields as automated metadata errors, not intelligence.

Akira's own volume is also reported inconsistently. The Cyber Threat Intelligence record cites 1,418 total Akira victims in one field and 1,561 in another within the same page. Either way, the operation remains among the highest volume ransomware brands active in 2026, and Huntress assessed it as the single most active group it observed across 2025.

What Was Taken

All figures below are Akira's claims, quoted identically by Cyber Threat Intelligence, Breach House and HookPhish:

Breach House lists four proof-of-breach screenshots posted by the operator (file_tree.png, finance_2024.xlsx, passport_scan.jpg, contract_signed.pdf), though these are the same four filenames that appear on its Ericksen Krentel record, so they may be template placeholders rather than incident-specific evidence. Breach House's dark web cross-reference for Davis & Ferber returns zeroes across infostealer logs, traditional breaches and ransomware leaks, consistent with data that has been claimed but not yet dumped.

The sensitivity here is disproportionate to the volume. Sixty gigabytes is modest by ransomware standards, but a personal injury and medical malpractice practice holds medical records, settlement terms, and identity documents belonging to people who never chose to do business with the firm. Client data at a law firm also carries attorney-client privilege, which makes public exposure a professional liability event on top of a privacy one.

Why It Matters

Akira has been working the professional services sector methodically. Six days before the Davis & Ferber post, on August 19, 2026, the group listed New Orleans accounting firm Ericksen Krentel with a near-identical pitch: 30 GB of corporate data, client and employee passports, driver's licences, SSNs, financials, contracts and NDAs. The wording, the data categories and the "we will upload X GB soon" construction are effectively boilerplate. Akira has found a repeatable model in mid-sized firms that hold concentrated third-party PII and typically lack a dedicated security function.

The Alkegen case shows how the timeline usually runs. Akira listed the manufacturer on April 23, 2026 claiming 57 GB; Alkegen filed with the Vermont Attorney General on July 17 and began notifying individuals, confirming that Social Security numbers and health records were involved, roughly three months after the claim. CyberNetSec.io reports that class action attorneys began investigating on the strength of those notification letters. If Davis & Ferber follows the same curve, formal notification would land in late 2026, well after the data has had time to circulate.

For defenders, the practical read is that the leak site listing is the earliest reliable signal available, and it arrives months before anything official. Downstream organisations with matters at the firm should start assessing exposure now rather than waiting for a letter.

The Attack Technique

No source describes the intrusion vector at Davis & Ferber specifically. What follows is Akira's documented general playbook and should be read as pattern, not attribution.

Huntress, investigating a separate Akira intrusion on August 4, 2026, documented the affiliate chain in detail. Initial access came through an exposed SonicWall SSL VPN appliance with no MFA. Roughly two hours after a successful VPN login, the attacker reached the domain controller over RDP, enumerated Active Directory users and computers (dropping the recurring AdUsers.txt and AdComp.txt artefacts), then pivoted to an application server. Data staging used WinRAR to archive mapped file shares, with s5cmd pushing the archives to an attacker-controlled S3 bucket. AnyDesk was installed for persistent remote access.

The novel step, and the reason the case is worth studying, was anti-EDR. The affiliate used AnyDesk to reboot the host into Safe Mode with Networking, which stopped the Huntress agent and disabled Microsoft Defender real-time protection. Huntress calls this the first Safe Mode abuse it has tied to Akira, though families like Snatch and AvosLocker have used the technique for years. AnyDesk was added to the Safe Mode registry keys so remote access survived the reboot. BleepingComputer reports the host ran with no working EDR and blinded AV for about 10 minutes.

The tactic then backfired. akira.exe failed to launch in Safe Mode's stripped-down memory environment, throwing out-of-virtual-memory and PowerShell errors, and a scheduled Defender scan later flagged the executable even with real-time protection off. Encryption never happened. Huntress makes the critical point anyway: the attacker had already exfiltrated credentials and file shares, so extortion by threatened leak remained fully viable. That is exactly the posture Davis & Ferber appears to be in, with data claimed and no encryption event mentioned anywhere in the reporting.

What Organizations Should Do

  1. Enforce MFA on every VPN and remote access path, and audit SonicWall SSL VPN appliances first. Huntress identifies exposed SonicWall VPN without MFA as Akira's habitual front door. Patch to current firmware, rotate all local VPN credentials, and disable any account that predates your MFA rollout.
  2. Alert on Safe Mode boot configuration changes. Monitor for bcdedit /set safeboot, unexpected reboots into Safe Mode with Networking, and writes to HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network. A production server rebooting into Safe Mode outside a change window is an incident until proven otherwise.
  3. Treat EDR agent silence as an event, not a gap. Build detection on the absence of telemetry. In the Huntress case the defenders' visibility window closed for 10 minutes, which was the whole point of the technique. Server-side heartbeat monitoring catches what an agent that is no longer running cannot report.
  4. Hunt for the exfiltration toolset. Alert on s5cmd execution, unexpected WinRAR command line archiving of mapped shares, and outbound traffic to unfamiliar S3 endpoints. Block or tightly allowlist unsanctioned remote access tools, AnyDesk in particular, at the application control layer.
  5. Segment the domain controller and instrument AD enumeration. The two-hour VPN-to-DC path is only possible with flat internal routing. Restrict RDP to jump hosts, and alert on bulk user and computer enumeration writing to local text files.
  6. Third parties should start exposure assessment before notification arrives. Alkegen's individuals learned nearly three months after the leak site claim. Insurers, co-counsel, medical providers and clients with matters at an affected firm should identify what they shared, and plan credit monitoring and privilege review on the assumption the claim is accurate.

Sources: Davis & Ferber Ransomware Attack by Akira (2026) Cyber Threat Inte... | Akira Hits Safe Mode: Ransomware Rebooting Around EDR Huntress | Akira hackers disable EDR with Safe Mode, steal data but fail to en... | Davis & Ferber — AKIRA Ransomware Attack Breach House | Ransomware Group akira Hits: Davis and Ferber | Akira Ransomware Claims Davis & Ferber as a Victim as Genesis Adds... | Alkegen Data Breach Exposes Social Security Numbers,... - CyberNetS... | Ericksen Krentel — AKIRA Ransomware Attack Breach House