In the fall of 2025, a subsidiary of Ruag, a state-owned Swiss defense conglomerate, was targeted by a cyberattack carried out by the hacker group Akira. The hackers accessed data from the subsidiary's systems in Virginia and threatened to publish the information on the dark web unless a ransom was paid. Despite federal recommendations against paying ransoms, Ruag proceeded with the payment. According to the Federal Department of Defence, Civil Protection and Sports (VBS), Ruag acted within legal boundaries under US law as a private corporation. However, the VBS noted that Ruag could have provided more coordinated information to the federal authorities, considering potential political and reputational impacts. As part of improving cybersecurity measures, Ruag plans to review its protection strategies alongside the Federal Office for Cybersecurity. Ruag's board chairman stated the ransom amount was small but did not disclose the exact figure.
Bias read (Center): The article presents the situation factually, citing the VBS investigation and quoting Ruag's board chairman. It does not exhibit overtly biased language or one-sided sourcing. The framing remains neutral, focusing on the legal and procedural aspects rather than taking a stance on whether paying the





