The Akira ransomware group has claimed responsibility for breaching Apache OpenOffice and exfiltrating 23 GB of sensitive data, including employee records, financial documents, internal confidential files, and reports related to application issues. The stolen employee data reportedly contains physical addresses, phone numbers, driver’s licenses, social security cards, and credit card information. Akira has threatened to leak these corporate files, but as of now, the Apache Software Foundation has not confirmed the breach or the authenticity of the claims. Users have been advised to download OpenOffice only from official sources to avoid potential compromise, and there is no indication that the public download infrastructure has been affected.
Akira, a ransomware-as-a-service operation known for double extortion tactics, has previously targeted hundreds of organizations worldwide, typically avoiding Russian-speaking countries. The group’s claims about the Apache OpenOffice breach remain unverified, and it is unclear whether the data is newly compromised or recycled from previous incidents. The situation is being monitored, and the Apache Software Foundation has been contacted for comment, but no official response has been issued at this time.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
The Akira ransomware group allegedly added Apache OpenOffice to its leak site and claimed it stole 23GB of data from the project. The available references do not provide a more specific incident date beyond the reporting timeframe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.