Hello
Hello. You've reached Akira support chat. Currently, we are preparing the list of data we took from your network. For now you have to know that dealing with us is the best possible way to settle this quick and cheap. Keep in touch and be patient with us. Do you have a permission to conduct a negotiation on behalf of your organization? Once we get your reply you will be provided with all the details.
Please confirm you have a permission to conduct a negotiation on behalf of your organization and we will provide the details.
Please note that if you stay silent, we will have to announce the incident. We are waiting for your reply.
You have 24 hours to give us your decision regarding this deal. If you stay silent, we will announce the breach on our blog.
Hello we found your note. Yes I have permission
Hello. You've reached Akira support chat. Currently, we are preparing the list of data we took from your network. For now you have to know that dealing with us is the best possible way to settle this quick and cheap. Keep in touch and be patient with us. Do you have a permission to conduct a negotiation on behalf of your organization? Once we get your reply you will be provided with all the details.
List.7z // 2.97 MB
These files were taken from your network prior to encryption. You can pick 2-3 random files up to 10 MB each from the list and we will upload them to this chat as a proof of possession. To prove that we can properly decrypt your data you can upload 2-3 encrypted files up to 10 MB each to our chat and we will upload decrypted copies back. We're looking through your financial papers to come up with a reasonable demand to you. We offer: 1) full decryption assistance;
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future. Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
We are reviewing the list. Given the weekend we do not have much support for this large list. I expect to have names for you on Monday
Standing by.
Are you going to provide file names?
Yes. We tried to login but your site was down earlier. Please provide the following: [redacted].docx [redacted].docx [redacted].html [redacted].docx [redacted].pdf [redacted].pdf [redacted].pdf
Files.rar // 1.94 MB
Here are the files. Do you want to test our decryption tool?
We're willing to set a $6,900,000 price for ALL the services we offer. We accept payments in BTC. To gain bitcoins you need to go to any exchange platform as binance or coinbase. Here are the guides: https://www.coinbase.com/how-to-buy/bitcoin
https://www.binance.com/en/how-to-buy/bitcoin You also can buy bitcoin from any local brokers. If you withdraw funds from your bank account, then you have to inform the bank that you need this money for investment purposes only.
Hello. Are you going to work with us?
Your site was down until just a little bit ago
Just a technical maintenance. Let's proceed further.
Well that is an impossible amount. We have spent years not profitable so every dollar goes to liabilities and back in the business. Here are some files for you to show ability to unlock but we will need to come to a much more reasonable amount if we are going to consider payment
[redacted].log.__ // 1.99 MB
[redacted].log.__ // 1.99 MB
[redacted].vmdk.__ // 2.54 MB
decrypted.7z // 378 KB
Now back to reality, where you have active cyber insurance with $5 million dollars of coverage. Let's look at the balance of one of your bank accounts: Ending balance as of March 31, 2025 - $7,969,498.39
Should we increase our demand?
The money we have is used for operations, debt obligations, and now for costs associated with your attack. That policy does not cover payments to attacks but rather the restoration and litigation costs. We are willing to pay you but given our situation, the amount you are asking for is impossible
Who are you trying to fool? Do you really think we don't know how this insurance works? Do you really think we haven't received insurance payments? You even have this wording: Cyber breach or extortion reward. 5,000,000 dollars is our bottom line, so we can end these games of back and forth.
We have no doubt you have received many payments. We googled your group and you clearly are one of the most prolific ransomware groups. We are not trying to fool you, we are just telling you what we have been told. Our policy cannot go to just making a payment to you. We are willing to pay you a large amount of money though, we just have to take into considerations liabilities, budgets, and future litigation costs. We do appreciate you attempting to come to a more reasonable number but $5M is still impossible. We think we can absorb and survive if we pay you $500,000. While this is less than you are expecting it is still a large unaccounted-for amount for us. How do we pay you?
Do you really think you can resolve this for 10% of the price?
We're glad you googled us and got to know us better and familiarize yourself with our business reputation. You've also probably googled a lot of "smart" articles about negotiating. 10% at the start, then 20% and so on up to 50%. We can save time and decide your offer is $2,500,000. The problem is that our original demand was $6,900,000. The problem is that you run the risk of running into the biggest problem of all and damaging not only your business, but also Carlyle, which has recently successfully taken you over and your stock price has skyrocketed. The mere mention of that data leak on our blog will crash your stock by 20-30%. The subsequent publicity and reputational damage will bury your business and leave a black stain on Carlyle's reputation.
118 of your servers and 787 workstations are locked down. 120 TB of backups were deleted. You just don't have any alternatives. Entering into an agreement with us is the only way to get back up and running, save your reputation and avoid litigation. But you are not in such a bad position as it may seem. We can accept $5 million of your insurance coverage and $500,000 out of your pockets.
We are not following any playbooks here, we are just trying to work out an agreement with you. You are refusing to listen to us about the insurance policy. If you look closer you will see we do not have $5mm coverage for a payment. We cannot come up with $2.5mm let alone $5.5mm. Your efforts have cost us significant unexpected losses that we have to take into account and will go way above our coverage. We are willing to improve our offer to you but cannot go much higher. If you give us a target closer to our original offer we will work as hard as possible to try and make it work. Let us know and we will meet with the finance team to see what we need to do
First of all, we aren't going to deal with 6 figures. Second, let's imagine you don't have 5 million coverage and you can still handle our demand without impacting your operations. Our price is justified, and we have proven it. If you can't come up with even 2.5 million, you could log out and face consequences that will empty your pockets significantly.
We do not have $5 million coverage for this and we do not have enough unallocated funds to pay your $2.5mm out of pocket. As we said before, we are willing to come to an agreement. We have been able to budget for $775k which we can put together relatively quickly if you accept. Lets be done with this
No, thank you. There won't be a 6 figure deal, hundred percent.
You want $1 million? That is impossible because it would require us to make public notifications. We don't need your decryptor at this point. So our only choice is to either pay you something less than $1 million or just go ahead and make a public announcement. Let us know what you will accept
Don't tell stories about payments. We have received many payments of $1,000,000 or more without any notifications and kept incidents confidential. If you don't need our tool, we can accept $1,500,000. Let us know asap.
Your other victims have nothing to do with us. You have already caused us a lot of unexpected costs, more than 0.8M on top and we are obligated to make a public notification. Thus if we paid you $1.5mm it would be worthless to us. We were able to fund a crypto account on Friday with $800k. We could get that to you soon if you accept
Decisions?
Our price is $1,500,000. Hope you will find the way to gather that amount. Otherwise, you will have to make a public notification about your data leak. Let's not complicate things.
Hello. Have you managed to increase your amount?
We cannot pay that much. Right now we still have $800k
The leadership has agreed to accept $800,000 if you pay within 24 hours. If you are able to make the transaction, here is our BTC wallet bc1qysnvj464v30tnanzvraklnu5f5m2h0hp6wraqc. Let us know asap.
Hello. How's your progress?
We are actively working on it. Hoping to have funds wired and converted today or tomorrow
Keep us posted on your progress.
Guys, what's your progress? It seems to take too long already.
I understand. I apologize for the delay. We are dealing with legal department who is holding it up. We are going to pay you they are just forcing us to check many boxes before giving green light. I will come back daily to update you so you do not feel in the dark
Hopefully we won't have to raise the demand because of these delays.
OK it is looking like we will be ready today maybe tomorrow at the latest. Please confirm what we get for paying you $800,000
You will receive a deletion log which means the raid drives that contained the only copy of your data are fully formatted and erased. But what is more valuable for you it is our security report. This includes information about how we were able to penetrate your network, as well as exclusive first-hand information about the state of your network, the vulnerabilities that we found. This is like a professional audit, so you do not need to invest any more money in your security. What's more, you'll receive high-quality technical recommendations on eliminating any vulnerabilities and strengthening your network to secure your internal and external infrastructure. You will also receive written guarantees that we will not sell or publish your data, keep this conversation private, and delete this chat later. We won't come back for more money after payment and we won't attack you again. Keep us posted.
OK we are preparing to send
Received. Please wait for deliverables.
Waiting
Deletion.7z // 1.7 MB
Initial access to your network was purchased on the dark web. Then kerberoasting was carried out and we got passwords hashes. Then we just bruted these and got domain admin password. Spending weeks inside of your network we've managed to detect some fails we highly recommend to eliminate: 1. None of your employees should open suspicious emails, suspicious links or download any files, much less run them on their computer.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc. We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
Now, delete the chat!!!
Wait, let our team decrypt the files fully. Thanks!
No problem.
How did you gain initial access to our system? Was it via any exploit or any infostealer?
We've been provided with your VPN credentials. We've purchased them.
From where did you purchase it?