Akira Ransomware Data Theft: NC Contractor Defense 2026

Akira claimed 10GB of stolen data from a US petroleum contractor on July 22, 2026. Why backups alone won't save NC contractors. Call (336) 886-3282.

Cover Image for Akira Ransomware Data Theft: NC Contractor Defense 2026

TL;DR: On July 22, 2026, the Akira ransomware group claimed an attack on Kruse Construction, a US petroleum-industry mechanical contractor, and threatened to leak 10 GB of stolen data including employee passports and driver's licenses, projects, contracts, financials, and customer files. The lesson for North Carolina contractors and manufacturers is uncomfortable: modern ransomware steals your data before it encrypts anything, so a good backup restores your operations but does nothing to stop stolen records from being published. Defense in 2026 has to prevent the theft, not just recover from the outage.

Key takeaway: Backups answer "can we get running again?" They do not answer "did our clients' and employees' data just get published?" Those are two different risks, and industrial contractors need controls for both.

Worried a ransomware crew could steal your project and client data? Contact Preferred Data Corporation at (336) 886-3282 for a ransomware-readiness assessment. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What happened in the Akira attack on Kruse Construction?

On July 22, 2026, Akira listed Kruse Construction on its leak site and threatened to publish 10 GB of data unless the company negotiated. According to the leak-site listing reported by security researchers, the threatened data included employee passports and driver's licenses, project files, contracts, financials, and customer records. Kruse is described as a mechanical contractor with over 50 years in the petroleum and petrochemical industry, building and maintaining liquid-petroleum terminals, pump stations, and pipelines.

This is a claimed, leak-site listing rather than a confirmed public breach report, but the pattern is unmistakable and consistent with how Akira operates. Akira has been claiming a steady stream of manufacturers and construction firms in 2026, frequently gaining entry through internet-facing remote-access appliances. The relevance for a Piedmont Triad contractor is not the specific victim, it is the profile: an industrial firm with valuable project data, sensitive employee records, and a lean IT footprint.

The important detail is what was stolen, not what was locked. Passports, licenses, contracts, and customer files are exactly the material that turns an IT incident into a legal and reputational one.

Why won't backups protect us from this kind of attack?

Because the damage in a modern ransomware attack happens at exfiltration, and a backup cannot un-steal data that has already left your network. Ransomware crews now run a double-extortion model: they copy your files out first, then encrypt what remains, so even a business that restores perfectly from backup still faces the threat of its stolen data being published. Akira threatened to leak Kruse's 10 GB regardless of any recovery the company could perform.

This is not an edge case, it is the norm for small and midsize victims. Verizon's 2025 Data Breach Investigations Report found that ransomware was present in 88% of breaches at small and midsize businesses, versus 44% of breaches overall. And these groups increasingly reach in through the network edge: the same report found exploitation of edge-device and VPN vulnerabilities grew nearly eightfold, from 3% to 22% of exploitation-based intrusions, which is precisely the entry path Akira favors.

Key takeaway: A tested, immutable backup is essential, and it is still only half the plan. It restores uptime. It does not restore confidentiality once data has been exfiltrated, which is why prevention and detection matter as much as recovery.

Not sure whether your data could walk out the door unnoticed? Call Preferred Data at (336) 886-3282 or explore our Cybersecurity Services and Managed IT Services.

How often are contractors and manufacturers actually targeted?

Constantly, and the trend is up. Construction and manufacturing are now among the most-attacked sectors, driven by valuable data, tight project timelines that pressure firms to pay, and historically light security. GuidePoint Security's GRIT team reported 131 construction ransomware victims in the first quarter of 2026, a 44% increase over the 91 victims in the same quarter a year earlier, which pushed construction from sixth to fourth among the most-impacted industries.

Manufacturing is hit even harder. Dragos found that manufacturing accounted for 62% of all observed industrial ransomware victims in the first quarter of 2026, and Check Point's quarterly report likewise found manufacturing the most-impacted industry, with the top 10 ransomware groups responsible for 71% of all victims. Akira sits squarely in that top tier alongside Qilin, Play, and DragonForce.

Three numbers a North Carolina contractor should internalize:

  • 131 construction ransomware victims in Q1 2026, up 44% year over year, per GuidePoint GRIT.
  • 62% of industrial ransomware victims were in manufacturing, per Dragos.
  • 88% of SMB breaches involved ransomware, per the Verizon 2025 DBIR.

What is the real cost when project and employee data is stolen?

The cost extends well past downtime into breach-notification duties, contract and surety consequences, and lasting reputational harm with clients. When Akira threatens to publish passports, driver's licenses, and customer contracts, the exposure is legal and relational, not merely operational. For a North Carolina business, exposure of personal information about employees or customers can trigger N.C.G.S. Section 75-65 breach-notification obligations.

The contrast between a reactive and a proactive posture is the whole argument:

FactorReactive (backups only)Proactive (prevent + detect + recover)
Encryption / downtimeRestore from backupRestore from immutable backup
Data theftStolen data still publishedExfiltration blocked or caught early
Entry pointExposed VPN or RMM toolHardened edge, MFA, monitored access
DetectionFound when files lock24/7 monitoring flags the intrusion
Notification / liabilityScramble after the leakRehearsed plan, evidence ready

How should an NC contractor or manufacturer defend against Akira-style attacks?

Layer six controls that address theft and recovery together, not a single backup product. The goal is to close the common entry points, catch an intruder before exfiltration, and be ready to respond if one gets through. This is the core of what a managed IT and security partner delivers for a business too small to run a 24/7 security team in-house.

  1. Immutable, tested backups. Keep offline or immutable copies and actually test restores, so encryption is a recoverable event, not an extinction event.
  2. 24/7 managed detection and response. Most SMBs cannot watch their own network overnight, which is when intrusions escalate. Managed detection catches the theft phase before the encryption phase.
  3. Phishing-resistant MFA and controlled remote access. Since Akira favors exposed VPNs and remote-management tools, put multi-factor authentication on everything, and inventory and lock down every remote-access path into your network.
  4. Segment OT and office networks. Separate plant-floor and jobsite systems from business IT so one compromised laptop cannot reach everything, a priority for manufacturers and contractors alike.
  5. A rehearsed incident-response plan. Know in advance who to call, how to isolate systems, and how to meet breach-notification duties. A plan tested once beats a plan written during a crisis.
  6. Vendor and subcontractor access governance. Contractors share systems like project management and accounting with partners, so limit and monitor third-party access that attackers love to abuse.

Ready to protect your project and client data, not just your uptime? Contact Preferred Data Corporation at (336) 886-3282. We deliver Cybersecurity, Managed IT, and Backup and Disaster Recovery for contractors and manufacturers across the Piedmont Triad. Serving the region since 1987, BBB A+ rated.

Frequently Asked Questions

What is the Akira ransomware group?

Akira is one of the most active ransomware groups of 2026, known for double-extortion attacks that steal data before encrypting systems and for frequently breaking in through internet-facing VPNs and remote-access appliances. It has claimed a steady stream of manufacturers and construction firms this year, including a July 22, 2026 leak-site listing of a US petroleum-industry contractor.

Why don't backups stop ransomware anymore?

Backups restore encrypted systems, but modern ransomware steals a copy of your data first and threatens to publish it. A perfect restore brings your operations back yet does nothing to prevent stolen customer and employee records from being leaked, which is why prevention and detection are now as important as recovery.

Are construction and manufacturing companies really targeted more than other businesses?

Yes. GuidePoint's GRIT team recorded 131 construction ransomware victims in Q1 2026, up 44% year over year, and Dragos found manufacturing made up 62% of industrial ransomware victims in the same period. Valuable project data, deadline pressure, and lighter security make these sectors attractive targets.

What is double extortion?

Double extortion is when attackers both encrypt your systems and steal your data, then demand payment to decrypt and to keep the stolen data from being published. It means a victim can face a leak even after recovering from backups, raising the stakes for prevention and for breach-notification readiness.

What are the first three things a small contractor should do?

Put phishing-resistant multi-factor authentication on all remote access, add 24/7 managed detection so an intrusion is caught before data is exfiltrated, and confirm you have immutable, tested backups. Together these address the most common Akira entry point, the theft phase, and the recovery phase.

Can Preferred Data help protect our contracting or manufacturing business?

Yes. We combine managed IT, 24/7 cybersecurity monitoring, hardened remote access, network segmentation, immutable backups, and a rehearsed incident-response plan for contractors and manufacturers across High Point, Greensboro, Charlotte, Raleigh, and the greater Piedmont Triad.

Support