Apache OpenOffice Breach: Akira Ransomware Steals 23GB of Data

by priyanka.patel tech editor

Akira Ransomware Claims Breach of Apache OpenOffice, 23GB of Data at Risk

A sophisticated cyberattack targeting the Apache openoffice project has been claimed by the Akira ransomware group, potentially exposing a massive 23 gigabytes of sensitive corporate data. The incident, announced on October 29, 2025, highlights the growing vulnerability of even non-profit organizations to increasingly aggressive cyber threats.

Apache OpenOffice, a widely used, free, and open-source office suite developed under the Apache Software Foundation, serves as a popular option to commercial products like microsoft Office. The software suite includes applications for word processing (Writer), spreadsheets (Calc), presentations (Impress), vector graphics (Draw), databases (Base), and formulas (Math), supporting over 110 languages across multiple operating systems.

The alleged breach does not currently appear to affect the public download servers, meaning end-users’ existing installations are, for now, considered safe. Though, the potential compromise of internal systems raises serious concerns about the security of sensitive employee and organizational data.

Details of the Alleged Data Breach

According to a post by the Akira group on a dark web leak site, the stolen data includes a trove of highly personal information belonging to Apache OpenOffice employees. This encompasses physical addresses, phone numbers, dates of birth, driver’s license details, Social Security numbers, and even credit card information.

beyond personal data, the group claims to have exfiltrated financial records, internal confidential documents, and detailed reports outlining request bugs and ongoing advancement issues. “We will upload 23 GB of corporate documents soon,” the group boasted, underscoring the scale of the alleged intrusion.

Foundation Remains Silent Amidst Uncertainty

As of November 1, 2025, the Apache Software Foundation has not confirmed or denied the breach. Spokespeople have declined to provide immediate comment to cybersecurity news outlets, leaving the authenticity of Akira’s claims unverified.

Independent cybersecurity experts are currently working to determine whether the data is genuine or potentially repurposed from previous leaks. While the open-source nature of OpenOffice may limit the direct risk to the software’s core code, a confirmed data breach could still have meaningful repercussions, potentially fueling identity theft and targeted phishing campaigns against staff.

Akira: A Rising Threat in the Ransomware Landscape

The Akira ransomware operation first surfaced in March 2023 and has as amassed tens of millions of dollars through hundreds of attacks across the United States,Europe,and other regions. The group is known for its double-extortion tactics,which involve both encrypting victim systems and stealing data for potential release.

Akira specializes in data exfiltration before encryption, deploying ransomware variants compatible with both Windows and Linux/ESXi environments. Reports indicate the group has even compromised victim webcams to exert additional pressure. Notably, Akira communicates in Russian on underground forums and appears to avoid targeting systems with Russian keyboard layouts, suggesting a degree of geopolitical selectivity.

Implications for Open-Source Security

This incident arrives amidst a broader trend of increasing ransomware attacks targeting open-source projects. The reliance on volunteer contributors and community funding often leaves these ecosystems vulnerable to security gaps. The situation is prompting calls for enhanced security measures within volunteer-driven development models.

Organizations currently utilizing Apache OpenOffice are advised to closely monitor their systems for any unusual activity and ensure that data backups are securely isolated. The cybersecurity community remains on high alert, awaiting further confirmation – or fallout – that could significantly impact trust in collaborative software development.

Leave a Comment