Everest Claims 682,887 Files From a Hospital Medication Vendor — Including Firmware, Certificates and Deployment Packages. The Patient Data Is the Least of It.
- Patrick Duggan
- 8 minutes ago
- 5 min read
On 22 July the Everest extortion group listed Omnicell on its leak site and claimed roughly 1 TB of stolen data across 682,887 files. Omnicell has not confirmed the claim and no independent researcher has verified it, so everything that follows is an unverified attacker assertion and should be read that way. But the contents of the claimed archive are worth taking seriously even at that discount, because of what is on the list.
Alongside the expected material — SQL databases and backups, credentials, customer implementation records — the claim includes healthcare and pharmacy automation software, partial source code, certificates, firmware, and deployment packages. Omnicell builds automated medication management and dispensing systems used by hospitals, long-term care facilities and retail pharmacies. The customer implementation records are said to span partners in Saudi Arabia, Australia, the UAE, Ireland, Singapore, Qatar, South Korea, Chile, Spain, Sweden and the Netherlands.
Why this is not a data breach story
Most healthcare incidents are counted in patients. This one should be counted in installations. Firmware, signing certificates and deployment packages are not records about people; they are the material you use to build and ship an update to a device sitting in a hospital medication room. Customer implementation records are the map of where those devices are and how they were configured.
If that combination is genuinely in someone else's hands, the exposure is not primarily to Omnicell's customers' privacy. It is to the integrity of the update path into medication dispensing infrastructure, across at least eleven countries. That is a materially different risk with a materially different response — and it is a supply-chain question, not a notification-letter question.
We want to be precise about the conditional. The claim is unverified. Attacker leak-site inventories are marketing copy and routinely inflated. Certificates may be expired, revoked, or unusable for signing. Firmware images may be old, or for discontinued lines. Any of those would collapse most of the risk described above. What we can say is that the claimed inventory describes a supply-chain scenario rather than a privacy one, and that the correct question for a hospital is not "were my patients in it" but "what would I do if the update path to these cabinets could not be trusted."
For clarity, because it will come up: Omnicell had a separate ransomware incident in 2022 affecting patient data. This is not that. Different year, different claim, different shape.
What we had, and what we did not
We have carried an Everest adversary profile in our corpus since 29 June, three and a half weeks before this listing appeared. That profile describes Everest as a Russian-speaking group active since roughly December 2020 that began as conventional double extortion — exfiltrate then encrypt — and has increasingly pivoted to pure data-theft extortion while operating as an initial access broker, selling network access to corporate and government victims from its Tor leak site. We characterised it as one of the brands typifying the 2026 shift toward extortion that skips the encryptor entirely.
That characterisation held up. An encryptor-less, exfiltration-only operation is exactly what this claim looks like. Having the actor profiled before the event is a real thing, and it is also a limited thing, so here is the limit stated plainly: we hold no indicators for this campaign. No infrastructure, no hashes, nothing a defender can block today that is specific to this intrusion. Owning a profile of the actor is not the same as having detected the operation, and we are not going to let the first imply the second. What the profile buys you is context on how this crew behaves and what typically comes next, which is worth having and is not a receipt.
The sector call, and the honest tally
On 15 March we published a post arguing that medical device makers invisible to AI were the ones getting breached. On 16 July we published the follow-up and graded ourselves in public: Medtronic, Stryker, Intuitive Surgical and UFP had all proven the thesis, and on two of those four we were early with receipts while on the other two we went quiet exactly when we should have been loudest.
This is the fifth. And unlike the previous four, it is a supply-chain exposure rather than a data loss, which extends the original thesis rather than merely repeating it. The March argument was that this sector is under-covered and therefore under-defended. The version we would write today is narrower and more uncomfortable: the sector's suppliers hold firmware and signing material for devices that dispense medication, and that material is a higher-value target than the patient records everyone counts.
We were late to this one. The claim went up on 22 July and we are writing on 6 August. That is a fifteen-day gap on a story sitting squarely inside a vertical we publicly claimed as our beat. Counting it as a miss is the only honest option, and the reason we are counting it out loud is that a sector map with only the catches on it is a brochure.
What a hospital should actually do this week
Ask Omnicell directly whether the claimed archive includes signing certificates or firmware for systems in your estate, and ask for the answer in writing. Vendors answer that question more precisely when the request is specific and documented.
Independent of the answer, treat this as the prompt to verify how you would even know. Confirm that firmware updates for medication dispensing equipment arrive through a channel you can authenticate independently of the vendor's own signing material, and that you have a record of currently installed firmware versions to compare against. If a hospital cannot answer "how would I detect an unauthorised firmware update on these cabinets," that gap exists regardless of whether this particular claim is true, and this is a cheap moment to close it.
Finally, if you are one of the implementation partners in the named countries, assume your configuration details and credentials are in scope and rotate accordingly. Implementation records are the least glamorous item on that inventory list and the most immediately actionable.
The bit we cannot tell you
Whether any of this is real. The claim is unverified, Omnicell has not confirmed it, and extortion crews lie for leverage. We have written this because the shape of the claim — firmware and certificates for medication infrastructure across eleven countries — describes a risk worth preparing for at a cost low enough that being wrong is survivable, and because a fifteen-day silence in a vertical we said we cover was already long enough.
We guarantee five percent of what we publish is wrong. On this one the honest disclosure is larger than usual: the underlying claim itself is unverified, we hold no indicators, and we came to it late.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.
