LG Energy Solution, a major South Korean battery manufacturer, experienced a ransomware attack that disrupted operations at one of its overseas facilities. The company confirmed that the incident was isolated to a single location, with headquarters and other facilities remaining unaffected. After implementing recovery measures, the impacted facility resumed normal operations, and ongoing security investigations are underway to assess the full scope of the breach.
The Akira ransomware gang claimed responsibility for the attack, stating they exfiltrated 1.7 terabytes of sensitive data, including corporate documents and employee databases. The FBI recently highlighted Akira's activities, noting the group has extorted over $244 million from various sectors, including manufacturing. The incident underscores the increasing targeting of battery manufacturers by ransomware groups, as seen in previous attacks on industry peers.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
AhnLab's ASEC blog included the Akira group's threat to leak data allegedly stolen from LG Energy Solution in its Week 3 November 2025 ransomware and dark web roundup. This reflected public reporting and monitoring of the incident on cybercrime channels.
LG Energy Solution said a ransomware attack targeted one of its overseas facilities, while stating that its headquarters and other sites were not affected. The company said the impacted facility had resumed normal operations after recovery measures and that a security investigation was ongoing.
The Akira ransomware group posted that it had stolen 1.7 TB of data from a South Korean lithium-ion battery and energy solutions company identified in reporting as LG Energy Solution, and threatened to leak the data. The claimed haul included corporate documents and employee database information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.