LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › SH Pension Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

SH Pension Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 22, 2024
SH Pension Listed by everest Ransomware Group

Reported July 22, 2024.

HIGH
Severity
July 22, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The SH Pension Listed by everest Ransomware Group (reported July 22, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who hold pensions or related accounts with SH Pension may now face uncertainty about whether their personal and financial details have been taken by criminals. On 22 July 2024 the organisation appeared on a ransomware leak site, with the operators claiming they had already removed a large volume of internal files and would publish everything unless contact was made within 24 hours. The number of individuals affected remains unknown, and public detail about exactly what was taken is limited, yet the mere listing raises practical risks of identity misuse, targeted fraud and long-term privacy exposure for anyone whose information sat inside those systems.

This article sets out only what has been reported, places the claim in context, and explains the concrete steps ordinary people can take while fuller confirmation is still pending.

Breaking down the breach

According to the listing published by the everest ransomware group on or around 22 July 2024, SH Pension was the victim of a ransomware attack in which internal files were exfiltrated. The group stated that the total volume of stolen data amounted to 100 GB and gave the company a final 24-hour window to make contact using instructions left during the intrusion. Failure to do so, the listing said, would result in the full publication of the data. The organisation’s website address was included in the post. No independent confirmation of the intrusion, the precise date of the attack, or the method of initial access has been released by SH Pension or by any official authority. The number of people whose records may be involved is listed as unknown. Beyond the claim of “internal files,” no further inventory of the material has been made public.

Who is everest?

Everest is a ransomware operation that has been active for several years and is known for double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to leak it on a dedicated site if a ransom is not paid. The group typically posts victim names, claimed data volumes and short deadlines, then gradually releases samples or full archives when negotiations stall. Public reporting has linked everest to attacks across multiple sectors, including finance, manufacturing and professional services, often using common initial-access methods such as compromised credentials or unpatched remote-access software. In this instance the group claims to have taken 100 GB from SH Pension and to have left contact instructions; those assertions remain unverified claims rather than What's Publicly Reported. No statement from everest beyond the leak-site listing itself has been reported in connection with this particular organisation.

About SH Pension

SH Pension is a Swedish pension provider whose website is registered at shpension.se. Organisations of this type administer occupational and private pension schemes, manage long-term savings, and process contributions, benefits and beneficiary information on behalf of individuals and employers. As a result they routinely hold large volumes of sensitive personal data—names, addresses, national identification numbers, employment histories, contribution records and banking details—together with internal corporate documents. A successful intrusion into such an environment is consequential because the data are both long-lived and highly valuable for identity fraud, social-engineering attacks and financial crime. Even if encryption of production systems is later reversed, the exfiltration of copies creates an enduring risk that cannot be undone by simply restoring backups.

What was likely exposed

The only data type named in the public listing is “internal files” said to have been exfiltrated during a ransomware attack, with a claimed total volume of 100 GB. Exact contents have not been disclosed or independently verified. Pension providers typically store customer identity documents, contact details, pension-account balances, contribution histories, beneficiary designations, tax identifiers and correspondence with employers and regulators, as well as internal administrative records, contracts and employee information. Whether any or all of those categories were among the 100 GB remains unconfirmed. Until SH Pension or a competent authority releases a verified inventory, it is not possible to state with certainty what specific records were taken.

The real-world impact

For individuals, the primary risks are identity theft, phishing campaigns that reference real account details, and fraudulent attempts to redirect pension payments or open new credit facilities. Because pension data often include lifelong identifiers and financial histories, the material can remain useful to criminals for years. Affected people may also face secondary harms such as increased scrutiny when applying for loans or insurance, or the emotional burden of monitoring accounts indefinitely. For SH Pension itself the consequences include potential regulatory investigation under data-protection rules, reputational damage, the cost of forensic investigation and customer notification, and possible civil claims. Even if the group never publishes the full archive, the mere existence of an unauthorised copy creates ongoing exposure that the organisation must manage.

Were you affected?

If you hold or have held a pension or related product with SH Pension, treat the listing as a credible warning until official confirmation arrives. Monitor bank and pension statements for unexpected activity, enable multi-factor authentication on all financial accounts, and be alert to unsolicited emails or calls that reference your pension details. Consider placing fraud alerts with credit-reference agencies if you are in a jurisdiction that offers them. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Keep records of any suspicious contact and report confirmed fraud to the relevant authorities. Further official statements from SH Pension or Swedish regulators should be watched for concrete guidance on next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySH Pension security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See SH Pension’s full breach history →

More recent breaches

Zuber Gardner CPAs pt.2 Listed by everest Ransomware GroupJune 12, 2024Voorhees Family Office Services Listed by everest Ransomware GroupJune 4, 2024Wealth Depot LLC Listed by everest Ransomware GroupMay 15, 2024Zuber Gardner CPAs Listed by everest Ransomware GroupMay 9, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the SH Pension Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram