Ruag paid ransom to hacker group Akira despite federal warning
The federal company Ruag paid a ransom to the hacker group Akira following a data theft – despite recommendations against doing so from the Federal Office of Cybersecurity.

Ruag ignored federal recommendation and paid ransom after cyber attack
The hacker group Akira infiltrated the systems of US subsidiary Ruag LLC last autumn and stole "large quantities of data". According to 20 Minuten, the federal company then paid a ransom – and, according to its own account, received the data back in full.
Ruag board president Jürg Rötheli confirmed the payment to SRF and described the amount as "minor". According to the report, Akira typically demands a low six-figure sum. A screenshot from the dark web shows that the group obtained 24 gigabytes of "corporate documents", including social security numbers and passports belonging to employees.
The payment stands in direct contradiction to the recommendations of the Federal Office of Cybersecurity (BACS). Under the heading "Data exfiltration", the office states: "BACS generally advises against paying a ransom." The reasoning: there is no guarantee that criminals will not publish the data after payment. Furthermore, every successful extortion finances the further development of future attacks.
Ruag defended its decision. The payment had been agreed upon with internal company bodies as well as a "renowned US legal expert". The damage incurred was able to be kept to a minimum both financially and in terms of security, the company stated.
The Federal Department of Defence, Civil Protection and Sport (DDPS) states it was not informed of the payment. The department under Federal Councillor Martin Pfister initially declined to make further statements.
Criticism has come from IT entrepreneur and SVP National Councillor Mauro Tuena: "This hacker group now knows that the federal government is willing to pay ransom – this signal to the outside world is devastating," he told SRF.
Source: 20 Minuten