Quick Summary
AllegedExecutive Summary
Akira ransomware actors listed Borchert & LaSpina, a U.S.-based law firm, on their leak site on August 18, 2026. While the firm operates within Akira’s typical geographic targeting of the United States, its industry classification as a legal entity places it at the periphery of the ransomware group’s historical focus, which tends to be more heavily weighted towards manufacturing and commercial services. In the 60 days preceding this listing, Akira claimed responsibility for 40 other victims. The group’s activity has been concentrated in Business Services, Manufacturing, and Technology sectors, predominantly in the United States, United Kingdom, and Canada. Notable recent victims include Cozad Asset Management, Keystops, CF Supply, and Belasco Electric. This broad targeting pattern indicates that Akira continues to engage with a wide range of small and mid-market organizations across North America without strict adherence to specific industry verticals.
Technical Analysis
SOCRadar’s investigation utilized a stealer-log query targeting the domain borchertlaw[.]com. The query returned no records within the sampled dataset. It is important to note that this sample represents a paginated slice of data and not a comprehensive census of all available logs. Therefore, the absence of records in this specific query does not definitively confirm that the organization is unaffected. Credentials may exist under alternate corporate domains or through personal email aliases used by staff, which were not included in this particular sample. Consequently, a null result does not rule out the possibility of compromised credentials. Akira ransomware actors frequently leverage stolen credentials as an initial access vector. These credentials are often acquired from underground marketplaces and are then tested against corporate access points such as VPNs or Microsoft 365 portals prior to the deployment of ransomware. The current query’s lack of positive findings does not preclude this method of intrusion. Continued monitoring of dark web stealer logs and proactive credential hygiene checks are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.