Quick Summary
AllegedExecutive Summary
Grupo DT, a company based in Spain, has been listed as a victim on the Everest ransomware group’s dark web portal, with the listing published on August 20, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. Grupo DT operates as a Spanish business group with diverse commercial sector activities. The appearance of Grupo DT on Everest’s victim list adds a Spanish entity to the group’s active portfolio during a period of heightened operational activity. In the 60 days leading up to this listing, Everest had claimed 25 other victims on its leak portal, positioning it among the more prolific ransomware groups in the monitored timeframe. The group demonstrates a broad sector focus, with a notable presence in Professional Services, Technology, and Financial Services, primarily targeting organizations in Europe and North America. Recent victims of Everest identified within the same operational window include Dharma Group, Capgemini Engineering, Experts Entreprendre, and Kingston Technology. The listing of Grupo DT aligns with a recent trend of Everest targeting European organizations in August 2026.
Technical Analysis
Initial access correlation against SOCRadar’s stealer-log telemetry yielded no exposure signals for the grupodt.es domain within the queried sample. It is important to note that the absence of stealer-log evidence does not definitively confirm that no compromise has occurred; it indicates that the specific queried sample did not surface domain-specific credentials within the monitored feed. Ransomware groups commonly employ a variety of initial access methods, which can include purchasing access from initial access brokers, exploiting vulnerabilities, conducting phishing campaigns, or utilizing supply chain vectors that may not generate stealer-log artifacts readily detectable in standard feeds. For ransomware operations such as those conducted by Everest, the diversity of initial access vectors means that a lack of stealer-log signals should not be interpreted as an assurance of network security. Organizations appearing on Everest’s victim portal should treat such listings as indicators of potential network access or data exfiltration, warranting a thorough incident response investigation irrespective of external telemetry findings. Recommended actions include a forensic review of authentication logs, endpoint detection data, and network egress patterns to identify any unauthorized activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.