Everest

Active
367 victims named on the leak site
12 in the last 30 days
127 in the last 12 months
Oct 2021 first victim we recorded
Sep 28, 2026 most recent victim posted
15 leak sites tracked

Data as of October 1, 2026.

Credential exposure before the attack

39.8% of Everest victims whose domain we can identify (146 of 367) had employee credentials leak in the 12 months before Everest named them as a victim.

We don't know whether any of these credentials were how Everest gained initial access.

What industries Everest targets

Sector identified for 183 of 367 victims.

Healthcare40
Financial Services35
Manufacturing28
Technology17
Construction10
Legal10
Energy8
Retail6

Where the victims are located

Country identified for 210 of 367 victims.

United States59
Italy16
France14
Canada12
United Arab Emirates12
United Kingdom11
Germany11
Spain8

Most recent Everest victims

VictimSectorCountryPosted
CEN and CENELEC cencenelec.euNon-profitBelgiumSep 28, 2026
Educational Testing Service ets.orgNon-profitUnited StatesSep 28, 2026
Morula IVF morulaivf.co.idHealthcareIndonesiaSep 28, 2026
Reliance Audit relianceaudit.com.sgFinancial ServicesSingaporeSep 28, 2026
Securitas securitas.comNot identifiedSwedenSep 28, 2026
UNIRITA unirita.co.jpTechnologyJapanSep 28, 2026
GeneSilico genesilico.aiNot identifiedPolandSep 8, 2026
GGS Information Services ggsinc.comNot identifiedUnited StatesSep 8, 2026
Körber koerber.comManufacturingGermanySep 8, 2026
Italtel italtel.comTechnologyItalySep 2, 2026
Rise UP riseup.aiNot identifiedFranceSep 2, 2026
Vivotek vivotek.comNot identifiedNot identifiedSep 2, 2026
Capgemini capgemini.comTechnologyFranceAug 21, 2026
CCA Bank cca-bank.comFinancial ServicesNot identifiedAug 21, 2026
Experts Entreprendre experts-entreprendre.comFinancial ServicesFranceAug 21, 2026
Grupo Desguaces Tenerife grupodt.esAutomotiveSpainAug 21, 2026
Kingston Technology kingston.comManufacturingUnited StatesAug 21, 2026
Keysight Technologies keysight.comManufacturingUnited StatesAug 5, 2026
Al-Futtaim alfuttaim.comEducationUnited Arab EmiratesJul 31, 2026
Allied Telesis alliedtelesis.comHealthcareNot identifiedJul 31, 2026

Showing the 20 most recent of 367. Browse recent data breaches for more.

Everest leak sites

Addresses we've seen Everest publish victims from. Any .onion address needs the Tor Browser.

  • ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion
  • gofile.io
  • everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion
  • dropmefiles.com.ua
  • dropmefiles.com
  • fex.net
  • wealthdepotllc.sharefile.com
  • ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion.ws
  • ransomoefralti2zh5nrv7iqybp3d5b4a2eeecz5yjosp7ggbepj7iyd.onion
  • file.kiwi
  • example.com
  • anonfiles.com
  • rransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion
  • bifpwatchoxp7tsb2kpes37b23ogjrb2kj4wgr7yncf4hhgsfahu7jad.onion
  • 2vqamwfdpis5rkjtpkutigykp56n6hkxfurm6qukdxp6uz5uff5kkaid.onion

Everest questions

Is Everest still active?

Yes. Everest posted its most recent victim on September 28, 2026. That's 12 victims in the last 30 days.

How many victims has Everest claimed?

Everest has named 367 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 127 of them were posted in the last 12 months.

When did Everest first appear?

The first victim we recorded for Everest was posted on October 7, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Everest target?

Healthcare accounts for the most victims we can classify, with 40. Financial Services follows at 35. We could identify a sector for 183 of 367 victims, so treat this as the shape of the targeting rather than a full census.

Has Everest already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.