LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › CO-VER Power Technology SpA Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

CO-VER Power Technology SpA Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 7, 2024
CO-VER Power Technology SpA Listed by everest Ransomware Group

Reported December 7, 2024.

HIGH
Severity
December 7, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

CO-VER Power Technology SpA was listed by the everest ransomware group on December 07, 2024 after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; individuals should review the group’s claims and take protective steps if they believe their data is involved.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 7 December 2024, the ransomware group known as everest listed CO-VER Power Technology SpA on its leak site, claiming to have stolen 800 GB of internal files in a ransomware attack. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the intrusion or the data volume has been released. The listing includes a demand that a company representative contact the group before a deadline expires, along with a reference to the organisation’s website.

For an Italian firm operating in power technology, any confirmed exfiltration of internal material raises practical questions about operational continuity, supply-chain trust and the possible exposure of business or employee records. What is known so far rests entirely on the group’s unverified claim.

Breaking down the breach

According to the everest listing dated 7 December 2024, CO-VER Power Technology SpA suffered a ransomware attack in which internal files were exfiltrated. The group states that the total volume of stolen data is 800 GB and instructs a company representative to make contact before time runs out. No further technical details—such as the initial access vector, the ransomware variant used, the precise date of the intrusion, or any ransom demand amount—have been disclosed in the public record. The number of individuals whose data may be involved is also unknown. At present the incident is known only through the group’s own claim; no statement from CO-VER Power Technology SpA confirming or denying the event has been incorporated into the available facts.

The group behind it: everest

Everest is a ransomware operation that follows the now-common double-extortion model: it encrypts systems and simultaneously steals data, then threatens to publish the material on a dedicated leak site if payment is not made. The group typically posts victim names, claimed data volumes and countdown timers, and it has previously targeted organisations across manufacturing, technology and industrial sectors. Its listings are public claims rather than verified forensic findings; victims sometimes negotiate, sometimes ignore the posts, and sometimes confirm breaches only after independent investigation. In this case the group claims to hold 800 GB of CO-VER Power Technology SpA’s internal files and has set a contact deadline, but no additional statements specific to this victim beyond the listing itself have been recorded.

Who is CO-VER Power Technology SpA?

CO-VER Power Technology SpA is an Italian company active in the power-technology sector. Organisations of this type design, manufacture or supply equipment and systems related to energy generation, conversion or distribution. They routinely hold engineering drawings, supplier contracts, employee records, customer project data and internal operational documents. A breach at such a firm can affect not only the company itself but also partners in the energy supply chain and any individuals whose personal or professional information appears in the stolen material. The potential consequences therefore extend beyond the organisation’s own walls to the wider industrial ecosystem it serves.

The information in question

The everest listing describes the exposed material simply as “internal files” totalling 800 GB. No further breakdown—such as whether the files include personal data, financial records, intellectual property or operational schematics—has been provided. Organisations in the power-technology sector typically maintain a mix of technical documentation, commercial correspondence, human-resources files and system configurations. Because the exact contents remain unconfirmed, it is not possible to state with certainty which categories of data, if any, have left the company’s control. The 800 GB figure and the characterisation as internal files are claims made by the group and have not been independently verified in the public record.

Why it matters

If the claimed exfiltration is accurate, the primary risks are twofold. For the organisation, loss of proprietary engineering or commercial information can undermine competitive position, disrupt operations and trigger regulatory scrutiny under European data-protection rules. For any individuals whose details appear in the files—employees, contractors or clients—the exposure could lead to phishing, identity misuse or unwanted contact. Even when the precise data types are unknown, the sheer volume cited (800 GB) suggests a substantial archive that could contain sensitive material. Until the company or independent investigators provide clarity, those potentially affected must treat the risk as real while recognising that the full picture is still incomplete.

What to do if you're exposed

Anyone who has worked with or for CO-VER Power Technology SpA, or who suspects their information may have been among the internal files, can take a few immediate, practical steps:

These measures do not confirm or deny involvement in this specific incident, but they reduce the chance that any leaked material can be used against you while further details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCO-VER Power Technology SpA security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See CO-VER Power Technology SpA’s full breach history →

More recent breaches

Key 4 Energy Srl Listed by everest Ransomware GroupSeptember 15, 2025Bio-Clima Service Srl Listed by everest Ransomware GroupNovember 15, 2024Arctrade Listed by everest Ransomware GroupNovember 1, 2024STUDIO NOTARILE BUCCI – OLMI Listed by everest Ransomware GroupJuly 17, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the CO-VER Power Technology SpA Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram