Ransomware dossier

Everest

Data-extortion and initial-access broker; energy, utilities and financial targets.

Claimed victims

305

Top region

US

Top sector

Technology

Suspected origin

Unattributed

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-09-25Securitas GroupProfessional ServicesSE
2026-09-25Morula IVFHealthcareZA
2026-09-25Reliance AuditProfessional Services—
2026-09-25UNIRITATechnologyJP
2026-09-25CENELECProfessional ServicesBE
2026-09-25ETSEducation—
2026-09-07GGSNot Found—
2026-09-07KÖRBERManufacturingDE
2026-09-07GENESILICOTechnologyIT
2026-09-01Rise UPTechnology—

Regions targeted

US 21JP 4DE 4IT 3IN 3AE 3BE 2FR 2

Sectors targeted

Technology 17Professional Services 11Financial Services 9Healthcare 7Manufacturing 5Transportation 3

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups