A&A Global Industries, a US-based toys and candy distribution company, experienced a data breach that was discovered on February 18, 2026, when the Akira ransomware group claimed responsibility for the attack. The breach was publicly reported on dark web monitoring sites on the same day.
According to statements from the threat actors, the breach involved corporate data and detailed personal files of employees, including SSNs, passports, driver's licenses, and medical information. The number of affected individuals has not been publicly disclosed and remains unclear. No official breach notification details or timeline have been disclosed.
The ransomware actors have indicated an intentional data exfiltration scenario, threatening to upload corporate data if their demands are not met. Limited information is publicly available regarding the full scope of the breach, specific data categories, or the identities of affected individuals, and further details may emerge.