Polycom Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Polycom has been named by the everest Ransomware Group as a victim of a ransomware attack in which internal files were exfiltrated. The incident was publicly disclosed on February 2, 2026, and the number of people affected is undisclosed.
Ransomware groups continue to target technology and communications firms, often publicising claims of access on dedicated leak sites when negotiations fail. In this case, the Polycom listing by the Everest group adds one more entry to a pattern of incidents affecting organisations that handle collaboration and conferencing infrastructure.
The facts currently available are limited. Polycom was listed by the group on or around 2 February 2026. The number of individuals affected remains unknown, and the only detail released about the data is that internal files were allegedly exfiltrated during a ransomware attack.
What happened
The incident came to light when the Everest ransomware group listed Polycom on its leak site. No independent confirmation of the claimed access or exfiltration has been made public. The scale of any data removal, the precise timing of the intrusion, and whether encryption was also deployed are not disclosed in available reporting.
Inside everest
Everest is a ransomware operation that follows the double-extortion model common among current groups: data is taken before encryption, and the threat of publication is used to pressure payment. The group maintains a public leak site where it lists organisations it claims to have compromised. Such listings constitute the group’s own assertions and are not automatically verified by third parties.
Polycom and its sector
Polycom develops video-conferencing systems, communication devices and related collaboration software. Headquartered in San Jose, California, the company was acquired by Plantronics in 2018 and maintains a global customer base that includes enterprises and public-sector clients. Organisations in this sector routinely process meeting records, directory information and integration data that connect to wider corporate networks.
What was likely exposed
The only information released states that internal files were exfiltrated. No inventory of file types, no record counts and no confirmation of personal data have been published. The exact contents therefore remain unconfirmed.
The real-world impact
Where internal business files are involved, the primary risks are competitive exposure, follow-on social-engineering opportunities and possible regulatory scrutiny for the organisation. Individuals named in any documents would face the usual downstream concerns of targeted phishing or identity misuse, though the absence of confirmed personal-data categories limits the precision of any assessment.
What to do if you're exposed
- Monitor official statements from Polycom or Plantronics for further details on the scope of the incident.
- Review account activity on any services that integrate with Polycom systems and change passwords if unusual access is detected.
- Run a free exposure scan of your email address against known breach data to check for prior appearances of your information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Morae Listed by everest Ransomware GroupTsunami Tsolutions Listed by everest Ransomware GroupReeves Information Technology Listed by everest Ransomware GroupMorgan Records Management Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Polycom Listed by everest Ransomware Group →
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.