Colins Aerospace / RTX.com Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On October 17, 2025, the Everest ransomware group listed internal files from Collins Aerospace / RTX.com, indicating a data breach at RTX. An undisclosed number of people may have been affected; individuals are advised to review any communications from RTX and monitor their accounts for unusual activity.
People connected to RTX or its Collins Aerospace operations may now face uncertainty about whether internal company files that include their personal or professional details have been taken and could surface online. On October 17, 2025, the ransomware group everest listed RTX.com and Colins Aerospace on its leak site, claiming it had exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail about the precise contents is limited, yet the listing alone raises practical concerns for employees, contractors, partners, and others whose information might sit inside those files.
Because the claim has not been independently confirmed in the available record, the situation is still one of asserted rather than proven exposure. Even so, the mere appearance of a major aerospace and defense organization on a ransomware leak site is enough to warrant careful attention from anyone who has shared data with the company.
Breaking down the breach
According to the public listing, everest claims to have conducted a ransomware attack against RTX that resulted in the exfiltration of internal files. The incident was reported on October 17, 2025. No confirmed figure for the number of people affected has been released, and the method of initial access, the duration of the intrusion, and any ransom demand remain undisclosed in the available facts. The listing itself is the primary public signal; it has not been accompanied by further verified technical details or an official confirmation of the full scope from the organization.
What is stated is that internal files were taken. Beyond that single characterization, the record does not identify specific systems, business units, or file volumes. In the absence of those details, the incident must be treated as an unverified claim of data theft tied to a ransomware operation rather than a fully documented breach with known parameters.
Who is everest?
Everest is a ransomware group that has operated for several years by combining encryption of victim systems with the theft of data, then threatening to publish the stolen material if payment is not made. Like other groups in this category, it maintains a leak site where it names organizations and, in some cases, releases samples or larger archives of claimed exfiltrated files. The group has previously targeted companies across multiple sectors, using the dual pressure of operational disruption and public data exposure.
In this instance, everest has listed Colins Aerospace / RTX.com and asserted that internal files were exfiltrated. That listing constitutes a claim by the group; it does not by itself prove the accuracy or completeness of the assertion. Public reporting on everest’s broader activity shows a pattern of high-profile listings followed, at times, by partial or full data dumps, but no such dump details are provided in the facts for this specific case.
Who is RTX?
RTX is a major American aerospace and defense corporation formed from the combination of Raytheon and United Technologies. Its businesses include commercial aviation systems, defense electronics, and related technologies. Collins Aerospace, referenced in the listing as Colins Aerospace, is a well-known business unit within RTX that supplies aircraft systems, interiors, and avionics to commercial and military customers worldwide.
Organizations of this scale routinely hold large volumes of employee records, contractor information, supplier data, technical documentation, and operational files. A breach claim against such a company is consequential because the data it processes often includes sensitive personal identifiers, security-related information, and proprietary material whose exposure could affect both individuals and national-security-adjacent supply chains. The listing therefore carries weight beyond a typical commercial incident simply by virtue of the sector and the organization’s size.
The information in question
The available facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, contact details, financial records, health information, or technical drawings—has been disclosed. Because the exact contents remain unconfirmed, it is not possible to state with certainty what categories of personal or corporate information may be involved.
Companies in the aerospace and defense sector typically maintain employee and contractor personnel files, access credentials, project documentation, supplier contracts, and systems data. Any of those categories could theoretically appear among “internal files,” yet that remains speculation. Readers should treat the exposure as potential rather than proven until more specific inventories are released by the organization or verified independently.
Why it matters
For individuals, the practical risk is that personal details contained in internal files could later appear in criminal marketplaces or be used for targeted phishing, identity fraud, or social-engineering attempts. Even limited data—names, email addresses, job titles, or internal identifiers—can be combined with other sources to create convincing scams. For contractors and partners, exposure of commercial or technical information could create competitive or contractual complications.
For RTX itself, a claimed ransomware incident involving data theft can disrupt operations, trigger regulatory notification duties, and damage trust with customers and government clients. Because the number of people affected is unknown and the precise data types unconfirmed, the full scale of those risks cannot yet be measured. The listing alone, however, places the organization under public scrutiny and requires affected parties to treat the possibility of exposure seriously.
If your data was in this claimed breach
If you have worked for, contracted with, or otherwise shared information with RTX or Collins Aerospace, begin by monitoring financial and email accounts for unusual activity and treat unexpected messages that reference the company with caution. Change passwords on any accounts that may have reused credentials linked to work systems, and enable multi-factor authentication wherever it is available. Consider placing a fraud alert with credit bureaus if you believe sensitive personal identifiers could be involved.
Because the exact contents of the claimed files remain unconfirmed, there is no definitive list of affected individuals. Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets; such a scan provides an additional, independent signal while official details continue to develop.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Chrysler Listed by everest Ransomware GroupCollins Aerospace / RTX.com Listed by everest Ransomware GroupPetra Listed by everest Ransomware GroupVikor Scientific, LLC / Korgene Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.