Ascoma Insurance Targeted by Akira Ransomware in Latest Cyberattack - cyberpress.org
cyberpress.orgArchived Mar 18, 2026✓ Full text saved
Ascoma Insurance Targeted by Akira Ransomware in Latest Cyberattack cyberpress.org
Full text archived locally
✦ AI Summary· Claude Sonnet
Ascoma Insurance Targeted by Akira Ransomware in Latest Cyberattack
By AnuPriya
March 13, 2025
Categories:
Cyber AttackCyber Security NewsCybersecurity
Ascoma Insurance Advisors, a leading Monaco-based insurance brokerage group, has reportedly fallen victim to a ransomware attack orchestrated by the Akira gang.
The incident, disclosed via a FalconFeedsio alert on March 12, 2025, highlights the relentless targeting of critical sectors by cybercriminals.
While Ascoma has not yet released an official statement, preliminary reports indicate that 12 GB of sensitive data was compromised.
The attack underscores Akira’s escalating global operations, which have impacted over 350 organizations and extorted $42 million since early 2023.
Attack Details and Immediate Implications
Akira, a ransomware-as-a-service (RaaS) group active since March 2023, has rapidly become one of the most prolific cybercrime enterprises.
Known for exploiting vulnerabilities in VPN services like Cisco ASA and VMware ESXi systems, the group has historically targeted industries ranging from healthcare to logistics.
In Ascoma’s case, the breach could expose client data, insurance agreements, and financial records, though specifics remain unconfirmed.
The Monaco-based firm, which operates across 21 African countries and manages risk solutions for multinational corporations, is now facing potential operational disruptions.
Akira’s dual-ransomware strategy—deploying both Windows and Linux variants—allows the group to encrypt diverse systems simultaneously, complicating recovery efforts.
Cybersecurity analysts suggest the attackers likely leveraged compromised VPN credentials or unpatched vulnerabilities to infiltrate Ascoma’s network, a tactic repeatedly observed in Akira’s campaigns.
Akira’s Growing Threat and Industry-Wide Recommendations
Akira’s attack on Ascoma follows a surge in activity, including a single-day leak of data from 32 victims in November 2024.
The group’s Tor-based leak site publicly shames non-compliant victims, amplifying pressure to pay ransoms.
CISA and Europol have flagged Akira’s use of tools like AnyDesk for persistence and Advanced IP Scanner for network reconnaissance, urging organizations to adopt multi-factor authentication (MFA) and patch known vulnerabilities.
The insurance sector remains a high-value target due to its access to sensitive client data.
Notably, French insurer AXA suffered a similar breach in 2021 after announcing it would cease ransomware payout coverage in France.
Joseph Carson, a cybersecurity expert, warns that ransomware’s financial toll has doubled since 2021, with average costs soaring to $1.85 million per incident.
Mitigation Strategies:
Enforce MFA on all remote access systems.
Regularly update VPN appliances and critical software.
Conduct employee training to identify phishing attempts.
Maintain offline backups to expedite recovery without ransom payments.
Also Read:
Alleged TurkNet Data Breach Exposes 2.8 Million Records
Share
Facebook
Twitter
Pinterest
WhatsApp
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.
Recent Articles
New Alert: Hackers Hijack Corporate M365 Accounts with OAuth Device Codes
ANY.RUN March 17, 2026
Windows 11 25H2/24H2 Update Fixes Bluetooth Visibility Problems
Cyber Security News March 17, 2026
Microsoft Introduces AI-Powered Troubleshooting for Purview Data Lifecycle Management
Cyber Security News March 17, 2026
Attackers Exploit Safe Links To Hide Phishing URLs Behind Rewriting Chains
Cyber Security News March 17, 2026
Payload Ransomware Uses Babuk-Inspired Encryption In Attacks On Windows and ESXi
Cyber Security News March 17, 2026
Related Stories
ANY.RUN
New Alert: Hackers Hijack Corporate M365 Accounts with OAuth Device Codes
Balaji - March 17, 2026
Cyber Security News
Windows 11 25H2/24H2 Update Fixes Bluetooth Visibility Problems
AnuPriya - March 17, 2026
Cyber Security News
Microsoft Introduces AI-Powered Troubleshooting for Purview Data Lifecycle Management
AnuPriya - March 17, 2026
Cyber Security News
Attackers Exploit Safe Links To Hide Phishing URLs Behind Rewriting Chains
Varshini - March 17, 2026
Cyber Security News
Payload Ransomware Uses Babuk-Inspired Encryption In Attacks On Windows and ESXi
Varshini - March 17, 2026
Cyber Security News
PylangGhost RAT Spread Through Malicious npm Packages In New Campaign
Varshini - March 17, 2026
LEAVE A REPLY
Comment:
Name:*
Email:*
Website: