Hitachi Vantara , a subsidiary of Japanese technology giant Hitachi , was forced to shut down its servers last weekend in an effort to limit the impact of a ransomware attack by the gang Akira .

The company, which offers data storage solutions, IT infrastructure, cloud management and cyber-attack recovery services , serves governments and leading organizations and enterprises worldwide (e.g. BMW, Telefónica, T-Mobile and China Telecom).
In an official statement to BleepingComputer, Hitachi Vantara confirmed that it was the victim of a cyberattack and that it is already working with independent cybersecurity experts to assess the extent of the damage and proceed with the restoration of the affected infrastructure.
See also: Interlock ransomware behind DaVita attack
“On April 26, 2025, Hitachi Vantara experienced a ransomware incident that affected a portion of our systems,” a company spokesperson said. “As soon as we detected suspicious activity, we immediately activated crisis management protocols and called in external experts to assist with the investigation and remediation processes. Additionally, as a precautionary measure, we took critical servers offline to limit the spread of the attack.”
The Hitachi Vantara spokesperson also said that the company and researchers are working intensively to fully restore services, support customers , and safely bring systems back online.
Although Hitachi Vantara did not name any specific group responsible for the attack, BleepingComputer has learned that a ransomware group called Akira. The attackers are said to have managed to extract data from the company's systems and left ransom notes on the compromised machines.
See also: Medusa Ransomware demands $4 million ransom from NASCAR
Additionally, BleepingComputer reported that while cloud services remain unaffected, some internal systems, as well as those of its subsidiary Hitachi Vantara Manufacturing, were taken offline as a precaution. The company's remote services and technical support services have also been temporarily suspended. However, customers using its solutions in their own environments still have uninterrupted access to their data.
Finally, a second independent source reported that the cyberattack also had an impact on several projects related to government agencies.

Akira Ransomware
The Akira ransomware gang emerged in March 2023 and quickly became known for its large number of victims on a global scale, covering many different sectors. To date, it has listed more than 300 organizations on its dark web leak site and has targeted major organizations such as Stanford University and Nissan.
See also: Arcus Media ransomware: Did it target the National Audit Office of Kiribati?
According to FBI estimates, by April 2024, Akira had extorted approximately $42 million in ransom, after attacking more than 250 organizations.
Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to the network
- Encryption of sensitive data
- Updating devices and systems with the latest security patches
- Conducting regular security audits and penetration testing
- Using strong, unique passwords
- Limiting user access to only necessary systems and information
- Use solutions email security for additional protection against phishing attacks
- Recovery plan for quick recovery
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
