Everest gang claims 1 TB theft from Omnicell medication systems

The Everest ransomware group claims it stole roughly 1 TB from medication dispensing vendor Omnicell, whose cabinets run in thousands of hospitals.

MedRisk Staff
By
1 Min Read

The Everest extortion gang says it walked off with roughly 1 TB of data, more than 682,000 files, from Omnicell, the company behind automated medication dispensing cabinets used in hospitals worldwide. Threat trackers logged the dark web listing on August 8, with the intrusion itself estimated to have started around July 22.

The group’s post reportedly describes stolen customer records that could include names, contact details, account information, and in some cases login credentials, though no samples have been released to verify the claim. Omnicell has not publicly confirmed a breach, and the alleged data is described as customer and internal files rather than clinical records.

Everest, an extortion-focused group with ties to other ransomware families, has claimed victims across multiple sectors. The supply chain angle matters for healthcare: credentials tied to a medication dispensing vendor could give attackers a foothold into hospital pharmacy environments, and exposed customer records create phishing and credential-stuffing risk for health system staff.

Ransomware claims remain unconfirmed until victims or regulators verify them, but organizations using Omnicell products should watch for follow-on attacks and reset any credentials that overlap with vendor portals.

Share This Article