Akira ransomware lists Italian ERP consultancy Divimast on its leak site

Organization
Divimast
Exploit
Ransomware
Industry
Information Technology

Divimast, an Italian software house that implements Microsoft Dynamics 365 Business Central enterprise resource planning systems for small and medium sized businesses, was named on the Akira ransomware group's leak site on January 17, 2025.

Akira said it had taken roughly 8GB of data from the company. In its listing the group described private corporate documents and confidential agreements, internal financial records and human resources files, and said it also held employee personal information including contact numbers, email addresses and passport details, as well as customer data.

As is standard for the group, the post functioned as an extortion notice, with Akira threatening to publish the material on its dark web site if it was not paid. No sample files or ransom figure were made public alongside the listing.

Divimast did not publicly acknowledge the claim, confirm what had been taken or indicate how many people might be affected. The incident drew no coverage from Italian mainstream press and no regulatory notice was identified. As of the reporting date the only account of the attack came from Akira itself, relayed by security researchers and leak site monitoring services.

Sources