The Everest extortion group claimed breaches affecting two organizations: Poly (an HP subsidiary, formerly Polycom) and Iron Mountain. Reporting on Poly indicates Everest alleged theft of roughly 90 GB of data, with shared samples suggesting potential exposure of C/C++ source code (possibly firmware/driver-related), screenshots referencing RMX video conferencing management systems, and hardware imagery; researchers cautioned the material may originate from an older database and that the presence of credentials is unconfirmed.
Iron Mountain disputed Everest’s broader claims of stealing 1.4 TB of sensitive internal and client data, stating the incident was limited to one folder on a public-facing file-sharing server accessed via a single compromised credential. Iron Mountain said the exposed content was primarily marketing materials shared with third-party vendors, the credential has been deactivated, no ransomware was deployed, and there was no evidence of broader system compromise or customer sensitive data exposure.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting on February 4, 2026 said Everest claimed to have stolen 90 GB of data from Poly, an HP subsidiary. Reviewed samples allegedly included C/C++ code, possible firmware or source code references, RMX system screenshots, and a photo of a Polycom-manufactured chip.
Iron Mountain stated that attackers used a single compromised credential to access only one folder on a public-facing or third-party file-sharing server. The company said the exposed content was primarily marketing materials shared with vendors, with no ransomware, malware, or broader system compromise detected.
On February 2, 2026, Everest alleged on its leak site that it had stolen 1.4 TB of Iron Mountain internal documents and sensitive client data, posting screenshots as purported proof and setting a February 11 negotiation deadline.
In background reporting, Everest's leak site was taken down in April 2025 after being defaced with a message referencing Prague.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceupguard.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.