Davis & Ferber Data Breach

Alleged

Ransomware claim involving Davis & Ferber

Published: Aug 25, 2026 Akira
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Davis & Ferber
Industry
Business Services
Threat Actor
Akira
Date of Incident
Aug 25, 2026

Executive Summary

Akira listed Davis & Ferber on its leak portal on August 25, 2026, an incident identified through SOCRadar Dark Web Monitoring. As a US professional services firm, Davis & Ferber aligns with Akira’s known targeting patterns, which have repeatedly focused on small to mid-sized US-based professional services organizations in recent months. This alignment suggests the firm’s sector and operational profile may have attracted the threat actor’s attention. Over the preceding 60 days, Akira claimed 41 other victims. The group’s activity has been concentrated in the Business Services, Manufacturing, and Retail and E-Commerce sectors, primarily impacting organizations in the United States, United Kingdom, and Canada. Recent listings that share a similar profile, particularly in the US or professional services segment, include Ericksen Krentel, JC Sales, Cascade Coffee, and Borchert & LaSpina. Davis & Ferber’s inclusion fits well within this established pattern of targeting.

Technical Analysis

SOCRadar’s stealer-log query specifically for the domain davisferber[.]com returned no records. It is important to note that this dataset is sampled and paginated. Therefore, the absence of records in this specific query does not definitively rule out the existence of credentials elsewhere. Such credentials could potentially reside in other data feeds or be associated with aliases not captured by the domain filtering used in the query. The lack of positive signal from this particular stealer-log search should not be interpreted as confirmation that the organization has not experienced credential exposure. Continued monitoring and proactive credential hygiene checks for davisferber[.]com remain the recommended response. This approach is crucial because credentials may exist in feeds outside the queried dataset, or they might have been used and subsequently rotated before indexing, making them undetectable in the sampled search.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.