Quick Summary
AllegedExecutive Summary
Everest ransomware listed Italtel Peru as a victim on September 1, 2026. Italtel Peru is the Peruvian subsidiary of Italtel S.p.A., a company that provides networking infrastructure, digital transformation, and managed services to telecommunications operators in the Andean market. Their services include Cisco-based infrastructure and managed network environments. As a managed telecommunications vendor, a breach involving Italtel Peru presents a potential supply-chain risk, offering a pivot point into the networks of its clients. In the 60 days preceding the listing, Everest claimed approximately 30 victims, with a strong concentration in the Technology, Professional Services, and Other sectors. Geographically, the United States, India, and the UAE were the most frequently targeted countries. Notable technology sector victims from this period include VIVOTEK, Rise UP, Kingston Technology, and Rx Networks. This consistent targeting of the technology sector suggests that Everest affiliates have developed playbooks specifically designed to exploit vulnerabilities within enterprise IT infrastructure.
Technical Analysis
A stealer-log query for italtel[.]com.pe revealed 24 records spanning June 2026 through August 2026, indicating significant credential exposure. These records included 16 employee credentials, as well as customer and third-party records, suggesting a mixed profile of compromised accounts. The exposed endpoints included Cisco SSO, which provides access to network management portals, the internal Italtel Peru web portal at italtelperu[.]com/web/login, an internal IP-addressed service at 10.56.1.114:7777, and a beta/development environment for password resets at beta.italtel[.]com.pe/reset_password. Additionally, Telefónica network management infrastructure was implicated. The exposure of credentials, particularly those related to Cisco SSO and Telefónica’s network management, indicates a potential pathway for attackers to gain unauthorized access. As a managed service provider for telecommunications companies, Italtel Peru’s compromise could allow threat actors to move from Italtel Peru’s environment into the networks of the clients it manages. The credential data spans up to August 2026, just five weeks before the Everest listing, suggesting these credentials could have been active and potentially used at the time of the ransomware deployment. Organizations utilizing Italtel Peru’s managed services should consider this incident a critical supply-chain indicator. It is recommended to audit vendor access tokens and network management credentials thoroughly. Given the recency of the exposed data, these credentials should be treated as potentially active and compromised. Proactive measures such as continuous dark web monitoring for further credential leaks, reviewing and rotating passwords, and ensuring multi-factor authentication is enabled and enforced across all critical systems, especially for remote access points and internal portals, are advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.