Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

RUAG Pays Ransom to Akira Cybergang Following Data Theft

Swiss defense company RUAG admits to paying ransom to the Akira ransomware group after sensitive data from US subsidiary Mecanex USA was stolen.

What happened?

Swiss defense company RUAG has reportedly paid ransom to the Akira cybergang following a cyberattack on its US subsidiary Mecanex USA. The data theft occurred in early November 2025, with Swiss broadcaster SRF attributing the breach to the US subsidiary RUAG LLC. The attackers published the extortion attempt on their darknet site, claiming to have copied around 24 GB of data.

RUAG board chairman Jürg Rötheli admitted to the payment on SRF's "Samstagsrundschau" program: "We paid, a small amount, fortunately, and got all the data back," he said. The ransom demands reportedly amounted to a low six-figure sum.

The details

According to the attackers, the stolen data included social security numbers, IDs, driver's licenses, phone numbers, addresses and other personal information belonging to employees. Additionally, classified military information as well as contracts and manuals on handling explosives are said to have been affected.

Rötheli explained that the ransom payment had been coordinated internally with the company's governing bodies. In addition, consultation with US legal experts had taken place. The Swiss Federal Department of Defence, Civil Protection and Sport (DDPS) declined to comment on the payment but stated that it had not been informed in advance.

The Akira cybergang uses its own ransomware and continues to encrypt victims' data, rather than limiting itself—as many other groups do—to data theft and extortion through the threat of publication. The group last made headlines in late 2025 when it deployed its ransomware on SonicWall firewalls despite active multi-factor authentication. Since then, Akira appears to have shifted its focus toward smaller companies and has been operating in a less conspicuous manner.

Assessment

The case contradicts the standard recommendation from IT security experts and Swiss cybersecurity authorities not to pay ransom in such situations. In Germany as well, the relevant authorities strongly advise against it. Back in 2022, IT security experts from academia and industry even called for concrete measures against ransom payments by victims in an open letter—a letter that attracted considerable attention at the time.

Mauro Tuena, a national councillor for the SVP party and IT entrepreneur, told SRF that the Akira group now knows the Swiss federal government is willing to pay ransom—a signal he considers devastating. RUAG countered that the decision had been correct, since all data was recovered and damage was minimized.

This contradiction between official recommendations and the actual behavior of a federally affiliated company highlights the dilemma facing victims of such attacks: on the one hand, extortionists' business model should not be strengthened through payments; on the other hand, companies face considerable pressure not to let sensitive data—particularly data related to military information—become public.

Practical tips

  • Regardless of the acute pressure of a crisis, companies should familiarize themselves in advance with the official recommendations of cybersecurity authorities and establish internal decision-making processes for emergency situations.
  • Early involvement of oversight bodies and—as in the RUAG case—legal counsel can help ensure that decisions made during a crisis are documented in a comprehensible manner.
  • Companies handling sensitive or security-relevant data in particular should assess whether upstream security measures such as multi-factor authentication are sufficiently hardened—the SonicWall firewall case shows that Akira can bypass even established protective mechanisms.
  • Transparent communication with higher-level bodies, such as ministries or regulatory authorities, should be ensured even within internal decision-making processes, in order to avoid loss of trust as seen in the case of the uninformed DDPS.

Outlook

The RUAG case is likely to reignite the debate over how to handle ransom demands, particularly since it involves a company with ties to the Swiss federal government. National councillor Tuena's statement that Akira now knows the federal government is willing to pay suggests that similar attacks on state-affiliated or security-relevant institutions may become more likely in the future.

At the same time, the behavior of the Akira group, which has recently increasingly targeted smaller companies, shows that the threat landscape for organizations of various sizes continues to intensify. Details on further possible consequences for RUAG or any regulatory responses are not yet known at this time.