Everest

Active
350 victims named on the leak site
17 in the last 30 days
127 in the last 12 months
Oct 2021 first victim we recorded
Aug 5, 2026 most recent victim posted
15 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

40% of Everest victims whose domain we can identify (140 of 350) had employee credentials leak in the 12 months before Everest named them as a victim.

We don't know whether any of these credentials were how Everest gained initial access.

What industries Everest targets

Sector identified for 171 of 350 victims.

Healthcare39
Financial Services32
Manufacturing26
Technology14
Construction10
Legal10
Energy8
Retail6

Where the victims are located

Country identified for 195 of 350 victims.

United States56
Italy15
Canada12
United Arab Emirates12
United Kingdom11
France11
Germany10
Spain7

Most recent Everest victims

VictimSectorCountryPosted
Keysight Technologies keysight.comManufacturingUnited StatesAug 5, 2026
Al-Futtaim alfuttaim.comEducationUnited Arab EmiratesJul 31, 2026
Allied Telesis alliedtelesis.comHealthcareNot identifiedJul 31, 2026
Conway Analytics conwayanalytics.comFinancial ServicesUnited StatesJul 31, 2026
Dharma Group dharmagroup.co.idManufacturingIndonesiaJul 31, 2026
Emirates Flight Catering emiratesflightcatering.comHospitalityUnited Arab EmiratesJul 31, 2026
EPM epm.com.coEnergyColombiaJul 31, 2026
NIMR Oil nimroil.comEnergyNot identifiedJul 31, 2026
Stadler Rail stadlerrail.comNot identifiedNot identifiedJul 29, 2026
Mansfield Family Dentistry mansfielddentistry.comHealthcareUnited StatesJul 24, 2026
Powerweave powerweave.comNot identifiedUnited StatesJul 24, 2026
Aptara aptaracorp.comMediaUnited StatesJul 23, 2026
Ingersoll Rand irco.comManufacturingSwedenJul 23, 2026
Omnicell omnicell.comHealthcareUnited StatesJul 23, 2026
Rx Networks rxnetworks.comNot identifiedCanadaJul 22, 2026
Alzone Software alzonesoftware.comTechnologyIndiaJul 20, 2026
Rodschinson Investment rodschinson.comFinancial ServicesBelgiumJul 13, 2026
TechCorr techcorr.comManufacturingUnited StatesJul 10, 2026
Conway Data conway.comFinancial ServicesUnited StatesJul 8, 2026
Formulatrix formulatrix.comHealthcareUnited StatesJul 8, 2026

Showing the 20 most recent of 350. Browse recent data breaches for more.

Everest leak sites

Addresses we've seen Everest publish victims from. Any .onion address needs the Tor Browser.

  • ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion
  • gofile.io
  • dropmefiles.com.ua
  • everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion
  • dropmefiles.com
  • fex.net
  • wealthdepotllc.sharefile.com
  • ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion.ws
  • ransomoefralti2zh5nrv7iqybp3d5b4a2eeecz5yjosp7ggbepj7iyd.onion
  • file.kiwi
  • example.com
  • anonfiles.com
  • bifpwatchoxp7tsb2kpes37b23ogjrb2kj4wgr7yncf4hhgsfahu7jad.onion
  • 2vqamwfdpis5rkjtpkutigykp56n6hkxfurm6qukdxp6uz5uff5kkaid.onion
  • rransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion

Everest questions

Is Everest still active?

Yes. Everest posted its most recent victim on August 5, 2026. That's 17 victims in the last 30 days.

How many victims has Everest claimed?

Everest has named 350 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 127 of them were posted in the last 12 months.

When did Everest first appear?

The first victim we recorded for Everest was posted on October 7, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Everest target?

Healthcare accounts for the most victims we can classify, with 39. Financial Services follows at 32. We could identify a sector for 171 of 350 victims, so treat this as the shape of the targeting rather than a full census.

Has Everest already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.