York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Akira Ransomware Hits Pennsylvania Steel Fabricator PennFab — 40GB of Employee and Client Data at Risk

York Computer

A Pennsylvania steel fabricator just landed on a ransomware leak site, and the details should get every small-business owner in the region paying attention. On September 2, the Akira ransomware group publicly claimed an attack on PennFab, a Pennsylvania-based structural steel manufacturer, and threatened to publish roughly 40 gigabytes of stolen corporate data — including employee Social Security numbers, client contracts, and financial records. Akira has spent the last two years quietly working through Pennsylvania's mid-market, and PennFab is only the latest name on the list.

What happened at PennFab

On September 2, 2026, the ransomware group Akira listed PennFab, a Pennsylvania-based manufacturing company specializing in structural steel fabrication, on its leak site. The post describes PennFab as offering engineering, welding, and custom metal-fabrication services for sectors including railroad and transportation.

The attackers say they will upload 40gb of corporate data, including employee personal information (scanned passports, driver's licenses, SSNs and so on of 53 employees), clients information, contacts and agreements, financials, and NDAs. The listing indicates a data-leak and extortion event; it does not claim that PennFab's systems were encrypted. That distinction matters — it suggests a data-theft-only extortion play, which is a pattern Akira has increasingly favored in 2026.

Why this matters for small businesses in south-central PA

Akira is not a group that chases Fortune 500 names. According to a joint U.S. and European advisory, Akira is primarily targeting small- and medium-sized businesses, but has also impacted larger organizations across various sectors, with a notable preference for organizations in the manufacturing, educational institutions, information technology, healthcare and public health, financial services, and food and agriculture sectors.

The group has been hammering Pennsylvania specifically. Akira's leak site earlier this year listed a Chambersburg insurance agency and other regional victims, and PennFab now joins that list. As of late September 2025, Akira ransomware has claimed approximately $244.17 million in ransomware proceeds.

If you run a York County shop with 20 to 500 employees, a VPN for remote access, and a couple of file servers, you look exactly like the profile Akira targets. This is the kind of exposure York Computer's managed IT and cybersecurity services are designed to cut down before an attacker ever gets a foothold.

How Akira gets in — and what your IT provider should be locking down this week

Akira's playbook is well-documented and mostly boring, which is the good news: the fixes are known. Akira targets both Windows and Linux environments, including VMware ESXi servers, and most often gains initial access through VPN accounts without multi-factor authentication or by exploiting known vulnerabilities in edge devices. In prior incidents, Akira threat actors likely abused CVE-2024-40766, a SonicWall vulnerability, for initial access.

A report by Halcyon released in April 2026 claimed the group could move rapidly and encrypt a victim organization's data within an hour after initial compromise. One hour. That is your entire detection and response window if they get in.

Ask your managed-IT provider — whether that's an in-house tech, an outside MSP, or a co-managed IT arrangement — to confirm the following are done and documented, not just "on the list":

- Every VPN and remote-access account has multi-factor authentication enforced. No exceptions for the owner or the sales manager. - Your SonicWall, Fortinet, Cisco, or other edge firewall is on current firmware, and CVE-2024-40766 (and this week's new SonicWall SMA1000 flaws) are patched. - Local administrator accounts on servers and workstations are unique per machine and monitored. - Backups are immutable, tested, and stored offline or in a separate cloud tenant — because a backup an attacker can encrypt is not a backup. - Someone is actually watching endpoint alerts after 5 p.m. and on weekends. Ransomware crews prefer Friday nights.

If you get a call from your IT team about "unusual VPN logins"

Do not wait to see what happens. Akira's speed from initial access to encryption leaves no room for a Monday-morning meeting. Disconnect the affected accounts, isolate the machine, and get an incident-response call started the same hour. If you carry cyber insurance, notify the carrier before you touch anything — most policies require it, and the carrier will assign a breach coach who can steer the next 48 hours.

What York Businesses Should Do

York County's manufacturing base — the fabricators, machine shops, and industrial suppliers along the Route 30 corridor — fits Akira's target profile almost exactly. This week is a good time to sit down with whoever handles your IT and get a straight answer on VPN MFA, firewall patch status, and whether your backups would actually survive a ransomware event.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles