Cyber & AI intelligence
Wasteland.
Briefs indexed2894
Issues29
Published Mondays07:30 CT
█ Ransomware SECURITAS-EVEREST- 2026-09-27

Securitas Group: Everest Ransomware Leak Site Claim, Not Yet Verified

"On September 25, 2026, the Everest ransomware group listed Stockholm-based Securitas Group as a victim on its Tor leak site. This brief treats the listing as a threat-actor claim, not a confirmed breach. All eight…"

On September 25, 2026, the Everest ransomware group listed Stockholm-based Securitas Group as a victim on its Tor leak site. This brief treats the listing as a threat-actor claim, not a confirmed breach. All eight sources are OTHER-tier: aggregators, leak-site trackers and automated feeds. None is a statement from Securitas, a regulator filing, a CERT advisory or a report from established security press. Some aggregators say the attack is "disrupting operations," but nothing we reviewed supports that. The sources name no ransom demand, no stolen-data volume and no attack vector. As of September 26, the company had not disclosed anything publicly.

What Happened

The trackers agree on the basic timeline. Everest published a post at /news/securitas-group on its onion leak site at about 16:28 UTC on September 25. Ransomware.live picked it up at 16:29 UTC (per Hendry Adrian, QPulse, Pulse and Undercode). QPulse and HackerFeeds give the estimated attack date as September 25, but that is almost certainly the listing date, not a forensically established intrusion date.

Breach House captured the post as of September 26. The post carries a countdown timer and the message: "The files will be published after the timer counts down. The company still has time to get in touch with us." That is Everest's standard pressure tactic. Breach House lists the leak status as "pending" and disclosure as "not disclosed yet."

Accounts differ on impact. Undercode's first write-up (Sept 25) and Hendry Adrian's feed (Sept 26) say the attack "impacted operations in Sweden." Neither cites evidence beyond the leak-site entry, and the wording looks like boilerplate from automated tracker text. Undercode's own follow-up (Sept 27) walks this back. It states that the available information "does not establish that Everest successfully breached Securitas, encrypted its systems, disrupted operations, or stole sensitive information." We give the more cautious account more weight. The listing is real. A breach, encryption and operational disruption are all unconfirmed.

The feeds also disagree on severity. QPulse scores it "High" (85/100) and HackerFeeds rates it "Medium." Both are automated scores built on the same thin data.

For context, Ransomware.live's Sweden page shows a running count of Swedish leak-site victims, and even that figure is inconsistent (151 in the page body, 162 in the page title). Recent Swedish listings are attributed to Qilin, Deadlock, DragonForce, The Gentlemen and others. Securitas would be one of the most prominent Swedish names on that list this year.

What Was Taken

Nothing has been established. Pulse records the ransom amount and exfiltrated-data size as "not disclosed," and notes that the post includes no leak screenshots and no press mention. Undercode's follow-up and QPulse confirm that no data volume, record count or data categories have been published. The victim description on the Everest post, as reproduced by HackerFeeds, Pulse and Hendry Adrian, is a generic AI-generated company profile ("founded in 1934... guarding services, electronic security, fire and safety solutions..."). It is not a sample of stolen material.

If the claim is genuine, the likely exposure matters. Securitas serves corporate, government and critical-infrastructure clients, so the data at risk could include employee HR and payroll records, client site details, alarm and monitoring configurations, and guarding schedules. This is analyst assessment, not reporting.

Why It Matters

The Attack Technique

Unknown. None of the sources report the initial access vector, affected systems, malware or indicators of compromise. Everest has historically used compromised valid credentials, exposed remote-access services (RDP and VPN), and commodity tooling such as Cobalt Strike and remote-management software for lateral movement and data staging. Nothing links those techniques to this incident specifically.

What Organizations Should Do

  1. Securitas clients: ask for a statement. Contact your account and security contacts for a formal position on the claim, and ask whether any client data or integrations were in scope. Don't rely on aggregator headlines.
  2. Review integrations with the vendor. Audit VPN tunnels, monitoring-platform accounts, API keys and shared credentials used by Securitas or its subsidiaries. Rotate anything high-privilege as a precaution.
  3. Harden physical-security data. Assume building layouts, alarm codes and guard rotations could be exposed. Change alarm and access codes where feasible and brief on-site staff.
  4. Watch for follow-on phishing. Warn finance and facilities teams about emails that impersonate Securitas, such as invoice changes or "incident update" lures. These typically follow a public extortion claim.
  5. Track the leak post. Monitor Ransomware.live and similar trackers for a data dump when the timer expires, and check any published file trees for your organization's name or domain.
  6. Hunt for Everest's usual tradecraft. Look for unusual RDP or VPN logins, new remote-management tools, and large outbound transfers to cloud storage in your own environment, especially on accounts shared with third parties.

Sources: Securitas Group Hit by Ransomware in Sweden: Everest Attack Disrupt... | Everest Claims Securitas Group: Swedish Security Giant Named on Ran... | 162 victims for Sweden | Everest Ransomware Group Claims Securitas Group as Victim QPulse | Securitas Group — EVEREST Ransomware Attack Breach House | Ransomware group everest hits Securitas Group HackerFeeds | Ransom! Securitas Group (SEP-2026) | Securitas Group ransomware — filtración de everest Pulse Pulse