LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › EPM Listed by Everest Ransomware Group

HIGH severityUnverified claimHow we verify

EPM Listed by Everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 5, 2026

SourceLeak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

EPM Listed by Everest Ransomware Group

Reported August 5, 2026.

HIGH
Severity
August 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

EPM has been listed by the Everest ransomware group, with the incident disclosed on 5 August 2026; the exact timing of the breach itself is not established. The group claims to have obtained personal data, and anyone connected to EPM should verify whether their information was exposed and take steps to protect themselves.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where ransomware groups routinely list large public-sector and utility operators on leak sites to pressure payment, the appearance of major infrastructure providers has become a recurring signal of risk to essential services and the people who depend on them. Against that backdrop, a listing tied to EPM warrants careful attention rather than alarm.

On August 05, 2026, EPM — Empresas Públicas de Medellín, a major Colombian public utility group — was reported as listed by the Everest ransomware group. The number of people affected is unknown, and the types of data involved have not been disclosed. What is known is limited to the claim on the group’s side and to EPM’s public role as a provider of energy, water, and related services across Colombia and parts of Latin America. That combination makes the incident consequential even while many operational details remain unconfirmed.

Inside the incident

Public reporting on this matter centers on a single core fact: EPM was listed by the Everest ransomware group, with the report dated August 05, 2026. Beyond that listing, available detail is sparse. The scale of any intrusion, the method of initial access, whether encryption or data theft occurred, and whether negotiations or recovery steps followed have not been disclosed in the material at hand. The number of individuals potentially affected is unknown, and no inventory of exposed file types or systems has been published in the facts provided.

In practical terms, a leak-site listing is a claim by the threat actor. It signals that the group asserts it holds or has access to data connected to the named organisation; it does not, by itself, constitute independent confirmation of the full scope or success of an attack. Until EPM or another authoritative source provides verified particulars, the responsible reading is that the organisation has been named in this context and that the underlying technical and human impact remain unconfirmed.

Who is Everest?

Everest is a known ransomware operation that has appeared in public reporting as a group using double-extortion style pressure: encrypting systems where it can, exfiltrating data, and threatening to publish material on a dedicated leak site if demands are not met. Like other actors in this category, it has historically relied on listings and timed disclosures to increase leverage against victims, including companies and institutions whose disruption would draw public and regulatory attention.

Well-documented patterns associated with such groups include opportunistic initial access through exposed services, stolen credentials, or phishing; lateral movement inside networks; and the packaging of stolen data for leak-site publication. None of those general tactics should be read as a confirmed playbook for this specific EPM matter. For this incident, the only actor-linked assertion in the facts is the listing itself. Claims the group may make about volume, sensitivity, or exclusivity of any haul should be treated as unverified until corroborated.

EPM and its sector

EPM, or Empresas Públicas de Medellín, is a Colombian public utility company headquartered in Medellín. It operates across energy, water, and telecommunications-related activities, including electricity generation and distribution, water supply, sewage, and natural gas. It serves millions of customers in Colombia and has extended activity into other Latin American countries, placing it among the larger public utility groups in the region.

Organisations of this type sit at the intersection of critical infrastructure and large-scale customer administration. They typically manage billing and account systems, service addresses, consumption records, workforce and contractor data, and operational technology environments that keep power, water, and gas flowing. A breach claim against such an entity matters because disruption or data exposure can affect both continuity of essential services and the privacy of households and businesses that have little choice but to entrust utilities with identifying and contact information. The sector’s public-service mandate also means incidents can carry civic and regulatory weight beyond a purely commercial data loss.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to assert what, if anything, left EPM’s control. No file counts, database names, or categories such as identity documents, financial details, or operational schematics have been confirmed in the provided record.

In general, public utilities commonly hold customer names, service addresses, account and billing data, contact details, payment-related records, and internal employee or contractor information, along with technical documentation tied to networks and plants. Those categories describe what such organisations typically maintain — not what was taken or published in this case. Until official or independently verified disclosures appear, the exact contents of any alleged dataset remain unconfirmed, and speculation about specific fields or volumes would be inappropriate.

The real-world impact

For individuals, the primary risks in utility-sector incidents — when data is actually exposed — tend to involve phishing and social engineering that misuse real account or address details, account takeover attempts on billing portals, and longer-term identity misuse if government identifiers or financial data were involved. Because the exposed data types here are undisclosed and the number of people affected is unknown, those outcomes cannot be stated as facts for this event; they are the concrete harms people should keep in mind when a utility is named.

For the organisation, a credible listing can mean operational distraction, potential service and safety scrutiny, regulatory and contractual notification duties, and erosion of public trust even before technical findings are complete. Ransomware pressure can also force difficult choices about system isolation and restoration that affect customers who rely on continuous electricity, water, or gas. None of this establishes negligence; it describes why listings against critical-service providers attract sustained attention and why transparent, factual updates matter once investigations mature.

If your data was in this breach

If you are an EPM customer, employee, or partner and are concerned you may be affected, start with basics: treat unexpected messages that reference your utility account or this incident with skepticism; verify any request through official EPM channels you already trust; monitor billing accounts for unfamiliar activity; and consider placing fraud alerts or credit monitoring where that is available in your country if you later learn sensitive identity data was involved. Change passwords on related accounts if you reuse credentials, and enable multi-factor authentication where offered.

Because public detail on this listing remains limited, confirmation that your information was included may take time or may never be fully itemised. You can run a free exposure scan of your email to check whether your information has surfaced in known breach data, and you should rely on official notices from EPM or relevant authorities for definitive guidance rather than on unverified claims circulating online.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEPM security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See EPM’s full breach history →
RelatedMore incidents at EPM

More recent breaches

Rx Networks Listed by Everest Ransomware GroupAugust 17, 2026Ingersoll Rand Listed by Everest Ransomware GroupAugust 8, 2026Omnicell Listed by Everest Ransomware GroupAugust 8, 2026AKM Enterprises INC Listed by Everest Ransomware GroupAugust 5, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the EPM Listed by Everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification. Leak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram