Alkegen, a specialty materials manufacturer operating as ASP Unifrax Holdings, has confirmed it was the victim of a data breach that may have exposed highly sensitive personal information, including Social Security numbers and health records. The Akira ransomware group has claimed responsibility for the attack, asserting on their dark web leak site that they stole 57 gigabytes of data. The company began notifying affected individuals in July 2026, more than two months after the initial claim by the threat actor. The breach has prompted an investigation by class action attorneys due to the sensitive nature of the compromised data.
The incident follows a typical ransomware attack pattern involving a data breach and extortion.
Akira is a prominent ransomware group known for its double extortion tactics. While the specific TTPs used against Alkegen are not public, Akira's typical attack chain involves:
T1190 - Exploit Public-Facing Application). They are also known to use stolen credentials purchased from initial access brokers.net, nltest, and PowerShell to map the internal network and identify high-value data stores and domain controllers.T1048 - Exfiltration Over C2 Channel).T1486 - Data Encrypted for Impact).The impact on Alkegen is multi-faceted, including significant business disruption, reputational damage, and substantial financial costs associated with incident response, recovery, and potential legal fees. For the individuals whose data was stolen, the consequences are severe. The exposure of Social Security numbers and health records creates a long-term risk of sophisticated identity theft, financial fraud, and targeted phishing attacks. The incident is now being investigated for a potential class action lawsuit, which could add significant financial penalties for the company.
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
To hunt for Akira ransomware activity, security teams can look for the following patterns:
akira.log or akira_readme.txt*.akiravssadmin.exe delete shadows /all /quietAnyDesk.exe, Radmin.exeSecure VPNs and other remote access points with MFA to defend against Akira's primary initial access vector.
Mapped D3FEND Techniques:
Maintain a robust patch management program to close vulnerabilities before they can be exploited.
Mapped D3FEND Techniques:
The Akira ransomware group lists Alkegen on its dark web leak site, claiming a data breach.
Alkegen files a data breach notification with the Vermont Attorney General's Office.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.