In brief: Swiss arms manufacturer Ruag paid ransom to the ransomware group Akira despite a contrary federal recommendation, which the Federal Department of Defence, Civil Protection and Sport (DDPS) classifies as legally permissible but insufficiently coordinated with the federal government.
The Swiss arms manufacturer Ruag paid ransom to the group Akira following a ransomware attack on a US subsidiary, even though the federal government, as owner, generally advises against such payments. A review by the Federal Department of Defence, Civil Protection and Sport (DDPS) concludes that the payment was legally permissible.
In autumn 2025, the ransomware group Akira attacked a subsidiary of the Ruag Group in the US state of Virginia. The attackers gained access to the company’s IT systems and exfiltrated data. They then threatened to publish the stolen data on the darknet unless a ransom was paid – an approach consistent with the established pattern of ransomware-as-a-service groups. Group CEO Jürg Rötheli confirmed to Radio SRF the payment of what he described as a “small” and “modest” amount, without naming a specific sum.
What is notable about the case is the contradiction with the recommendation of the Swiss federal government, which as owner of Ruag generally advises against paying ransoms to cybercriminals. Nevertheless, the subsequent review by the DDPS found that the company could not be accused of any legal violation. As a private-law stock corporation, Ruag independently reviewed the payment for compliance with US law and made the decision within the scope of its corporate responsibility. Separate approval from the federal government was not required for this.
For security officers at companies with state participation or critical infrastructure, the case illustrates a legal tension: even where payments to ransomware groups may be legally permissible, the owner does not automatically consider them appropriate. In its report, the DDPS criticises the fact that coordinated communication with the federal government ahead of the payment would have been appropriate. In the department’s view, Ruag did not sufficiently take into account political implications, potential reputational damage and overarching interests when making its decision.
As a consequence of the incident, Ruag is to revise its protective measures and internal processes together with the Federal Office for Cybersecurity in order to avoid comparable situations in the future. As part of this cooperation, an assessment will also be made as to whether the group is adequately protected against cyberattacks overall. For CISOs in comparable situations, the case underscores the need for clear escalation and communication channels with owners or supervisory authorities before deciding on ransom payments.
Source: www.it-daily.net · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.