Solaris Pharma Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Solaris Pharma was listed today by the everest ransomware group, which claims to have exfiltrated internal files from the company. Anyone who has shared personal or medical information with Solaris Pharma should check the company’s notices and consider protective steps such as monitoring accounts and changing passwords.
On 14 January 2025, the ransomware group known as everest publicly listed Solaris Pharma on its leak site, claiming responsibility for an attack on the company’s internal network. According to the group’s statement, more than 400 GB of internal data were taken. The number of people whose information may be involved remains unknown, and the precise contents of the files have not been independently confirmed. For anyone connected to Solaris Pharma—employees, contractors, partners or patients—the listing raises practical questions about what may have left the organisation’s systems and what steps are sensible now.
Public detail is limited to the group’s own claims. No independent verification of the intrusion, the volume of data or any subsequent publication has been reported in the available record. That uncertainty itself is part of the risk: people cannot yet know whether their personal or professional information is among the material described.
Breaking down the breach
The incident is known solely through everest’s leak-site listing dated 14 January 2025. The group states that it attacked Solaris Pharma’s internal network and exfiltrated more than 400 GB of “internal important data” to its own servers. The listing specifically mentions internal and confidential information as well as contract information. everest further claims that a company representative should contact the group to restore access to files and to prevent publication of the documents.
No technical details of the initial access method, the duration of the intrusion, or any encryption of systems have been disclosed in the public record. The number of individuals affected is listed as unknown. Whether any data has actually been released, sold or otherwise distributed remains unconfirmed. The listing itself is an unverified claim by the threat actor.
Who is everest?
everest is a ransomware group that has operated for several years using a double-extortion model. In this approach, operators first steal data and then encrypt systems, threatening to publish the stolen material if a ransom is not paid. The group maintains a dedicated leak site where it names victims and, in some cases, posts samples or full archives of claimed data. Public reporting has linked everest to attacks across multiple sectors, including manufacturing, professional services and healthcare-related organisations. Its typical tactics include initial access through compromised credentials or vulnerabilities, followed by lateral movement, data staging and exfiltration before ransomware deployment. Claims made on the leak site are statements by the group and are not independently verified unless confirmed by the victim or by forensic investigators.
About Solaris Pharma
Solaris Pharma operates in the pharmaceutical sector. Organisations of this type typically manage research data, manufacturing records, regulatory filings, supplier and distributor contracts, and employee information. Depending on their activities they may also hold clinical-trial related material or commercial agreements with healthcare providers. A breach of an internal network at such a company can therefore touch both commercial confidentiality and, potentially, information linked to individuals. The exact nature of Solaris Pharma’s operations and the systems involved in this incident have not been detailed in the public facts available.
What data was at risk
The only description of the data comes from everest’s own statement: more than 400 GB of internal files that the group characterises as “internal important data,” including internal and confidential information and contract information. No further breakdown—such as whether employee records, customer lists, research files or personal identifiers were present—has been provided or confirmed. Public detail on the precise contents remains limited.
Pharmaceutical companies commonly hold a range of sensitive material. In the absence of confirmation, it is not possible to state what was actually taken. The following points summarise what is known and what is not:
- Claimed volume: more than 400 GB of internal files.
- Claimed categories: internal and confidential information, contract information.
- People affected: unknown.
- Exact file types, personal data elements, or any publication status: undisclosed and unconfirmed.
Why it matters
For individuals, the primary concern is the possible exposure of personal or professional details that could be used for fraud, phishing or other misuse. Contract information may reveal commercial relationships that competitors or other parties could exploit. For the organisation, the loss of internal documents can affect ongoing negotiations, regulatory compliance and intellectual-property protection. Even when the full contents remain unconfirmed, the mere claim of a large-scale exfiltration creates operational and reputational pressure. Because the number of people affected is unknown, the circle of potentially impacted parties cannot yet be defined with precision.
If your data was in this claimed breach
If you have a past or present relationship with Solaris Pharma—as an employee, contractor, partner or in any other capacity—treat the listing as a prompt for caution rather than as proof that your specific information is involved. Practical first steps include monitoring financial and email accounts for unusual activity, enabling multi-factor authentication wherever available, and being alert to unexpected messages that reference the company or request sensitive details. You may also wish to request information from Solaris Pharma about any notifications it has issued. Readers can run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets. Official confirmation of what, if anything, was published from this incident has not yet been reported.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Vikor Scientific, LLC / Korgene Listed by everest Ransomware GroupLa Perouse Listed by everest Ransomware GroupPacific HealthWorks Listed by everest Ransomware GroupArlington Occupational Health and Wellness - Full leak published Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Solaris Pharma Listed by everest Ransomware Group →
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.