ELC Electroconsult SpA Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ELC Electroconsult SpA was listed by the everest ransomware group on December 16, 2025, with internal files reported as exfiltrated. Individuals with any connection to the company should verify whether their data has been exposed and take protective steps.
ELC Electroconsult SpA, an Italy-based engineering firm, was listed by the Everest ransomware group on December 16, 2025. The listing states that internal files were exfiltrated during a ransomware attack. The number of individuals affected remains unknown, and no additional details on the volume or contents of the data have been made public.
The incident is significant because the company works on large-scale infrastructure projects that often involve sensitive technical, contractual and operational information. Public records confirm only the group’s claim of a listing and the reported date.
Inside the incident
The available information is limited to the December 16, 2025 listing. It indicates that files were removed from ELC Electroconsult SpA systems in the course of a ransomware operation. No confirmed figures for the quantity of data, the timeline of the intrusion, or the methods used have been released. The organisation has not issued a public statement detailing its response or the scope of the event.
Who is everest?
Everest is a ransomware group that conducts operations involving encryption of victim systems and the removal of data for later publication. The group maintains a public leak site where it lists organisations it claims to have targeted. Such listings serve as the primary public signal of claimed activity; independent verification of each entry is not always available. The group has appeared in multiple prior incidents across different industries, following a pattern of data exfiltration combined with ransom demands.
Who is ELC Electroconsult SpA?
ELC Electroconsult SpA is an Italian engineering company that provides design and consultancy services for large infrastructure projects worldwide. Its work focuses on hydroelectric power, renewable energy installations and dam construction. Organisations in this sector routinely handle detailed technical specifications, project schedules, supplier contracts and regulatory submissions that are not intended for public release.
What was likely exposed
The listing refers only to “internal files” removed during the attack. No inventory of specific document types or data categories has been published. Companies of this kind commonly store engineering drawings, client correspondence, financial records related to projects and employee or contractor information. The precise contents of the exfiltrated material remain unconfirmed.
What's at stake
Exposure of internal project files could affect ongoing or future contracts if competitors or other parties obtain proprietary designs or cost data. If personal information of employees, partners or clients is present in the files, those individuals face the standard risks associated with leaked contact details or credentials. For the company, the incident adds operational disruption and potential reputational consequences while the full extent of the data remains unclear.
What to do if you're exposed
Individuals who have worked with ELC Electroconsult SpA or similar organisations should monitor their email accounts and any associated services for unusual activity. Enabling multi-factor authentication on important accounts and changing passwords remain basic protective steps. Readers can run a free exposure scan of their email address against known breach data to check for prior appearances in published records.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Accela Listed by everest Ransomware GroupBenchmark Electronics Inc Listed by everest Ransomware GroupSarmap Listed by everest Ransomware GroupExegy Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ELC Electroconsult SpA Listed by everest Ransomware Group →
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.