Everest leak-site listing names KÖRBER

Published September 7, 2026

A ransomware monitoring site recorded an Everest leak-site listing that names KÖRBER. The listing is an attacker claim, not confirmation that KÖRBER was breached or that data was stolen.

Report priority
High
Involves
Körber
Group
Everest

What is known

The listing doesn't explain how Everest might have accessed KÖRBER, which systems were involved, or whether data was taken or encrypted.

What to do

If you work for or do business with KÖRBER, ask your organization's IT or privacy contact whether KÖRBER has confirmed an incident and whether your systems or data are involved. Send them the listing URL and explain your relationship to KÖRBER. The listing alone, and the absence of a notice, can't determine whether you're affected.

Follow a notice from KÖRBER or your organization after verifying it through a known contact. Don't treat the leak-site listing as confirmation of compromise or data theft.

Reported details

Ransomware.live recorded the KÖRBER listing under the Everest group on September 7, 2026. The service says it indexes publicly visible ransomware-operator posts without obtaining the underlying stolen content. The page doesn't provide an intrusion method, ransom demand or evidence confirming theft or encryption. Tracking ID: RANSOM-everest-k-rber.