Swiss defense contractor Ruag paid a ransom to the Akira ransomware group despite federal authorities advising against such payments. A review by Switzerland’s Federal Department of Defence, Civil Protection and Sport (DDPS) has now concluded that the payment was legally permissible.
The Swiss state owned defense company Ruag paid a ransom following a cyberattack on one of its US subsidiaries, going against the explicit recommendation of Swiss authorities. A review conducted by the Federal Department of Defence, Civil Protection and Sport (DDPS) found that the company did not violate any laws by making the payment, according to SRF.
Attack Targeted US Subsidiary in Fall 2025
The attack targeted a Ruag subsidiary in the US state of Virginia in fall 2025. The Akira ransomware group gained access to the company’s IT systems and stole data in the process. The attackers then followed a common ransomware playbook: They threatened to publish the stolen information on the dark web unless a ransom was paid.
Payment Made Despite Federal Recommendation
The case attracted attention because the Swiss government, as Ruag’s owner, generally advises against complying with ransom demands from cybercriminals. Despite this guidance, Ruag decided to make the payment.
Ruag CEO Jürg Rötheli did not disclose the exact amount in an interview with Radio SRF but described it as a “small” and “limited” sum.
The DDPS subsequently reviewed both the incident and the company’s handling of the situation. Its conclusion: Ruag cannot be accused of violating the law. As a privately incorporated company, Ruag assessed the payment for compliance with US regulations and made the decision as part of its corporate responsibility. Separate approval from the Swiss government as the company’s owner was not required.
DDPS Criticizes Lack of Coordination
However, the review did not leave Ruag without criticism. The DDPS stated that coordinated communication with the federal government before the payment would have been appropriate. According to the department, Ruag did not sufficiently consider the broader implications of its decision, including potential political consequences, reputational risks and other strategic interests.
Cybersecurity Measures to Be Reviewed
Following the incident, Ruag will work with the Swiss Federal Office for Cyber Security to review and improve its security measures and internal processes. The goal is to prevent similar situations in the future. As part of this cooperation, the company’s overall resilience against cyberattacks will also be assessed to determine whether existing protections are sufficient.
(lb)