EPM Data Breach

Alleged

Ransomware claim involving EPM.

Published: Aug 5, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
EPM
Industry
Energy and Utilities
Threat Actor
Everest
Date of Incident
Aug 5, 2026

Executive Summary

EPM, an energy and utilities company based in Colombia, has been listed as a victim on the Everest ransomware group’s dark web portal, published on August 5, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organisation operates in the utilities sector, delivering services to a large residential and commercial customer base. It is the only Colombian entry in Everest’s recent listing population. In the 60 days prior to this listing, Everest has claimed 18 other victims across its leak portal. The group has shown a strong targeting pattern in the technology, professional services, and energy and utilities sectors. Geographically, its victims are concentrated in the United States, India, and the United Arab Emirates. Other recent Everest listings that overlap with EPM’s profile — energy and utilities organisations — include NIMR Oil, Keysight, Stadler Rail, and Mansfield Family Dentistry. The sector fit is clear; Latin America is new territory for the group in this window, which makes EPM the geographic outlier of the batch.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the epm.com.co domain. All 25 records in the returned sample authenticated against organisation-owned subdomains — regional service portals and the root domain — but every one was classified as a customer, supplier, or external user account rather than an employee credential. Log activity runs to 4 August 2026, the day before the listing appeared. For a utility with a mass-market customer base this shape is expected: the volume reflects consumer portal credentials in circulation, not corporate compromise. The profile is customer account takeover. For ransomware groups such as Everest, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. In this case the visible sample contains no employee credentials at all, so it offers no support for that route — the exposure is real but sits on the customer side of the estate. CTI teams should read this as a customer fraud and account-abuse concern in parallel with the leak-site listing, and continue monitoring for corporate-level records that a customer-portal-dominated sample would crowd out.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.