SYS::ONLINE
Wasteland.
Briefs1531
Issues20
SinceFeb 2026
LIVE
█ Ransomware OMNICELL-EVEREST-R 2026-07-25

Omnicell: Everest Ransomware 1TB Data Theft Claim

"The Everest ransomware group has publicly claimed a breach of Omnicell, a U.S.-based provider of medication management and pharmacy automation systems, alleging the theft of 1 terabyte of data across more than 682,887…"

The Everest ransomware group has publicly claimed a breach of Omnicell, a U.S.-based provider of medication management and pharmacy automation systems, alleging the theft of 1 terabyte of data across more than 682,887 files. The claim was observed on July 22, 2026 and first flagged by threat-intelligence tracker Hackmanac. As of this writing, neither Omnicell nor independent security researchers have confirmed the breach, and no proof of the alleged data has been published.

What Happened

On July 22, 2026, Everest added Omnicell to its list of claimed victims, asserting it had exfiltrated roughly 1TB of data spanning 682,887-plus files. The posting frames Omnicell, a maker of automated medication management systems used by hospitals, long-term care facilities, and retail pharmacies, as the source of a large trove of technical and operational data.

The claim remains unverified. Everest has not released a public sample, and Omnicell has not issued a statement confirming or denying the incident. This is a common posture in the early hours of an extortion listing, where the threat actor's goal is to pressure the victim into negotiation before evidence is scrutinized.

What Was Taken

According to Everest's posting, the allegedly exfiltrated archive includes:

Everest further claims the data contains customer implementation records tied to partners in Saudi Arabia, Australia, the UAE, Ireland, Singapore, Qatar, South Korea, Chile, Spain, Sweden, and the Netherlands. If accurate, that spread would point to an international scope reaching well beyond Omnicell's domestic footprint. The inclusion of source code, firmware, and deployment packages is the most concerning element, given the role these components play in the medication infrastructure Omnicell ships to clinical environments.

Why It Matters

Omnicell equipment sits at a sensitive point in hospital operations: automated dispensing and medication management. A confirmed leak of source code, firmware, and deployment packages would raise supply-chain concerns, because those artifacts can reveal how the systems are built, updated, and secured across many downstream healthcare customers.

The alleged credentials and certificates compound the risk. If genuine and still valid, they could enable follow-on intrusion into partner environments or facilitate the signing of malicious updates. Omnicell is not new to this threat surface; the company previously disclosed a ransomware attack in May 2022 that affected internal systems and ultimately impacted tens of thousands of patients. Defenders in the healthcare sector should treat this listing as a prompt to review their exposure to Omnicell software and any shared credentials, even while confirmation is pending.

The Attack Technique

Everest has not disclosed an initial access vector, and no technical indicators have been released. The group has been active since at least December 2020 and is known for double-extortion tactics, in which data is stolen before or instead of encryption and then used as leverage for payment.

A note of caution is warranted. Everest is also known for high-volume claims across many sectors, and past incidents have shown that the group's stated data-theft figures do not always hold up to technical scrutiny. The group has recently claimed breaches at Nissan, and in 2025 listed Under Armour, Coca-Cola, and Mailchimp among its targets. High file counts and large data volumes are frequently cited in these postings and should be treated as unverified until corroborated.

What Organizations Should Do

Sources: Everest Claims 1TB Data Breach at Healthcare Firm Omnicell - TechNadu