« All threats

Ransomware group

Everest

Everest is a ransomware group active since at least December 2020, known for its double-extortion tactics. The group initially operated as a typical ransomware outfit, encrypting files with strong cryptography and appending victim-specific extensions, but later shifted toward pure data extortion—threatening to sell or release stolen data without necessarily deploying encryption. Everest targets a wide range of sectors, including government, healthcare, manufacturing, and IT services, with confirmed victims in North America, Europe, and Asia. Initial access vectors include exploitation of vulnerable public-facing applications, phishing campaigns, and credential theft for remote access services. The group maintains a Tor-based leak site to publish stolen information and advertise access to compromised networks.

Victims in the last 90 days40

Most affected countries

  1. United States5
  2. France2
  3. United Arab Emirates2
  4. Japan2
  5. Germany1
  6. Taiwan1
  7. Belgium1
  8. Peru1

Most affected sectors

  1. Technology12
  2. Other8
  3. Professional services6
  4. Manufacturing3
  5. Telecommunications2
  6. Finance & insurance2
  7. Healthcare2
  8. Energy & utilities2

Recent victims

OrganisationCountrySectorClaimedStatus
Morula IVF—Healthcare9/25/2026◌ Claimed (unverified)
Securitas Group—Professional services9/25/2026◌ Claimed (unverified)
🔒 Empresa de servicios profesionales—Professional services9/25/2026◌ Claimed (unverified)
UNIRITAJapanTechnology9/25/2026◌ Claimed (unverified)
CENELECBelgiumProfessional services9/25/2026◌ Claimed (unverified)
🔒 Organización o entidad—Other9/25/2026◌ Claimed (unverified)
🔒 Entidad de sector no determinado—Other9/7/2026◌ Claimed (unverified)
KörberGermanyManufacturing9/7/2026◌ Claimed (unverified)
🔒 Entidad sin información suficiente—Other9/7/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other9/4/2026◌ Claimed (unverified)
🔒 Entidad o iniciativa desconocida—Other9/1/2026◌ Claimed (unverified)
VIVOTEKTaiwanTechnology9/1/2026◌ Claimed (unverified)
Italtel PeruPeruTelecommunications9/1/2026◌ Claimed (unverified)
CCA Bank—Finance & insurance8/20/2026◌ Claimed (unverified)
Capgemini EngineeringFranceProfessional services8/20/2026◌ Claimed (unverified)
Grupo DT—Other8/20/2026◌ Claimed (unverified)
Kingston TechnologyUnited StatesTechnology8/20/2026◌ Claimed (unverified)
Experts EntreprendreFranceProfessional services8/20/2026◌ Claimed (unverified)
KeysightUnited StatesTechnology8/4/2026◌ Claimed (unverified)
EPMColombiaEnergy & utilities7/30/2026◌ Claimed (unverified)
AKM Enterprises INC—Other7/30/2026◌ Claimed (unverified)
Formulatrix—Technology7/30/2026◌ Claimed (unverified)
Oasis Legal Group—Legal7/30/2026◌ Claimed (unverified)
Conway Analytics—Professional services7/30/2026◌ Claimed (unverified)
Greenbotz—Technology7/30/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.