Quick Summary
AllegedExecutive Summary
Akira listed Davis & Ferber on its leak portal on August 25, 2026, an incident identified through SOCRadar Dark Web Monitoring. As a US professional services firm, Davis & Ferber aligns with Akira’s known targeting patterns, which have repeatedly focused on small to mid-sized US-based professional services organizations in recent months. This alignment suggests the firm’s sector and operational profile may have attracted the threat actor’s attention. Over the preceding 60 days, Akira claimed 41 other victims. The group’s activity has been concentrated in the Business Services, Manufacturing, and Retail and E-Commerce sectors, primarily impacting organizations in the United States, United Kingdom, and Canada. Recent listings that share a similar profile, particularly in the US or professional services segment, include Ericksen Krentel, JC Sales, Cascade Coffee, and Borchert & LaSpina. Davis & Ferber’s inclusion fits well within this established pattern of targeting.
Technical Analysis
SOCRadar’s stealer-log query specifically for the domain davisferber[.]com returned no records. It is important to note that this dataset is sampled and paginated. Therefore, the absence of records in this specific query does not definitively rule out the existence of credentials elsewhere. Such credentials could potentially reside in other data feeds or be associated with aliases not captured by the domain filtering used in the query. The lack of positive signal from this particular stealer-log search should not be interpreted as confirmation that the organization has not experienced credential exposure. Continued monitoring and proactive credential hygiene checks for davisferber[.]com remain the recommended response. This approach is crucial because credentials may exist in feeds outside the queried dataset, or they might have been used and subsequently rotated before indexing, making them undetectable in the sampled search.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.