Full Report
Seit April vergangenen Jahres führt die Bundesanwaltschaft (BA) ein Strafverfahren, wie der Bund am Donnerstag mitteilte. Die Ermittlungen werden unter Koordination des Bundesamtes für Polizei (Fedpol) in enger Zusammenarbeit mit dem Bundesamt für Cybersicherheit (Bacs) und den Behörden verschiedener mitwirkender Länder geführt. Die Hackergruppe Akira tauchte im März 2023 erstmals auf. Sie arbeitet mit spezieller und eigens entwickelter Software und verfügt über eine IT-Infrastruktur, die international über mehrere Länder verteilt ist. Dabei praktiziert sie die sogenannte doppelte Erpressung, bei der Daten des Opfers zuerst entwendet und dann verschlüsselt werden.
Analysis Summary
# Incident Report: Akira Ransomware Campaign in Switzerland
## Executive Summary
The threat group Akira has significantly intensified ransomware activities targeting approximately 200 companies in Switzerland, leading to multi-million Swiss Franc losses. The group employs a "double extortion" technique, involving both data exfiltration and encryption. Swiss federal authorities, coordinated by Fedpol and Bacs, have opened a criminal investigation into these coordinated international attacks.
## Incident Details
- **Discovery Date:** The ongoing investigation by the Federal Prosecutor's Office (BA) started around April of the previous year (implied long-running criminal investigation related to Akira's emergence). The specific intensification of attacks against Swiss entities is current as of the article date (October 16, 2025).
- **Incident Date:** Akira group activity first observed globally in **March 2023**.
- **Affected Organization:** Approximately **200 companies in Switzerland**. (Specific organizations not disclosed, victims often pay ransom due to reputational concerns).
- **Sector:** Undisclosed (Widespread impact across varied sectors).
- **Geography:** Switzerland (Primary focus of this report), infrastructure is international.
## Timeline of Events
### Initial Access
- **Date/Time:** March 2023 (First appearance of Akira). Official legal investigation by BA started April [Previous Year].
- **Vector:** Not explicitly detailed, but generally achieved via custom ransomware deployment.
- **Details:** Akira uses specialized, self-developed software for its operations.
### Lateral Movement
- **Details:** Not specified in detail, but part of the standard operational procedure that precedes encryption.
### Data Exfiltration/Impact
- **Date/Time:** Occurs prior to encryption.
- **Details:** The attackers practice **double extortion**: 1. Data is first **stolen (exfiltrated)**. 2. Data is then **encrypted**. If the ransom is not paid by the deadline, the stolen data is published on the "Data Leak Site" (DLS) on the Darknet.
### Detection & Response
- **Date/Time (Investigation Start):** Since April of the previous year.
- **Details:** A criminal proceeding is being conducted by the **Federal Prosecutor's Office (BA)**. Investigations are coordinated by the **Federal Office of Police (Fedpol)** in close cooperation with the **Federal Office for Cybersecurity (Bacs)** and authorities from various participating countries.
## Attack Methodology
- **Initial Access:** Not explicitly detailed, but relies on proprietary software infrastructure.
- **Persistence:** Not explicitly detailed.
- **Privilege Escalation:** Not explicitly detailed.
- **Defense Evasion:** Not explicitly detailed.
- **Credential Access:** Not explicitly detailed.
- **Discovery:** Not explicitly detailed.
- **Lateral Movement:** Not explicitly detailed.
- **Collection:** **Data theft (Exfiltration)** is a mandatory precursor step.
- **Exfiltration:** Data is stolen before encryption.
- **Impact:** **Data Encryption** and **Data Leakage** (via the DLS blog) if ransom demands are unmet.
## Impact Assessment
- **Financial:** Damage in Switzerland currently amounts to **several million Swiss Francs**; globally, tens of millions of US Dollars.
- **Data Breach:** Sensitive data is exfiltrated, leading to a significant risk of public disclosure if payment fails.
- **Operational:** Encryption causes operational disruption, forcing victims potentially to pay ransom to regain access.
- **Reputational:** Victims often pay the ransom due to fear of reputational damage from public data leaks.
## Indicators of Compromise
*Note: The provided text details the threat actor's behavior, not specific technical IoCs like hashes or IPs.*
- **Network Indicators:** Infrastructure is distributed internationally across several countries.
- **File Indicators:** Custom, self-developed software used for execution.
- **Behavioral Indicators:** Execution of double extortion ransomware scheme (Exfiltration followed by Encryption). Publication of data on the Darknet blog named "DLS" (Data Leak Site). Ransom payment typically demanded in Cryptocurrency, usually **Bitcoin**.
## Response Actions
- **Containment:** Not specified, beyond standard incident response procedures associated with ransomware.
- **Eradication:** Not specified.
- **Recovery:** Victims may recover data upon payment of ransom (usually in Bitcoin), but this is discouraged by authorities.
- **Legal/Investigative:** A criminal investigation is active under the coordination of Fedpol, involving Bacs and international partners, active since April last year.
## Lessons Learned
- **Visibility on Ransomware Payment:** A significant number of incidents likely go unreported ("Dunkelziffer") because victims choose to pay to protect their reputation, obscuring the true scale of impact.
- **Use of Custom Tools:** Akira utilizes specialized and self-developed software, potentially making generic detection signatures less effective.
- **Effectiveness of Double Extortion:** The threat of public data release remains a powerful coercive tool, driving ransom payments.
## Recommendations
- **Proactive Data Protection:** Implement robust backup and recovery strategies that are segmented or immutable, limiting the impact of encryption.
- **Threat Intelligence Integration:** Continuously monitor for known TTPs associated with the Akira group, especially their proprietary toolsets.
- **Public Disclosure Policy:** Establish a clear internal and communication policy regarding data breach disclosure versus the financial risk of paying ransoms, in alignment with government advisories.
- **International Cooperation:** Maintain close ties with national cybersecurity agencies (Bacs) and law enforcement (Fedpol) given the internationally distributed nature of the threat actor's infrastructure.