Rise UP Data Breach

Alleged

Ransomware claim involving Rise UP

Published: Sep 1, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Rise UP
Industry
Business Services
Threat Actor
Everest
Date of Incident
Sep 1, 2026

Executive Summary

Everest ransomware has claimed Rise UP as a victim, with the listing appearing on their dark web portal on September 1, 2026. SOCRadar’s Dark Web Monitoring service flagged this incident. Rise UP is identified as an AI-powered B2B learning and corporate training platform that serves enterprise clients, with its primary domain being riseup[.]ai. While its country of incorporation is not confirmed by available data, the nature of its services positions it as a valuable target for ransomware actors seeking to disrupt operations or exfiltrate sensitive data. The simultaneous listing of multiple companies, including VIVOTEK in Taiwan and Italtel Peru in Peru, on the same date as Rise UP suggests a coordinated campaign by the Everest threat group. This pattern could indicate shared initial access broker infrastructure or a targeted credential harvesting operation rather than a series of isolated intrusions. In the preceding 60 days, Everest has claimed approximately 30 other victims, primarily within the Technology, Professional Services, and Other industries. Their geographic focus has been the United States, India, and the United Arab Emirates. Previous B2B SaaS victims with similar profiles include Alzone Software and TechCorr.

Technical Analysis

A query of stealer-log data for the domain riseup[.]ai yielded a severe result, with 25 records identified. These records span from June 2024 through September 1, 2026, coinciding directly with the ransomware group’s listing of the victim. The compromised credentials were a mix of employee, customer, and third-party accounts. Specifically, 21 of the 25 records were customer credentials, indicating that stealers were active on devices belonging to Rise UP’s enterprise clients while they accessed hosted learning environments. The exposed customer-facing endpoints include cdf-bytel-production.riseup[.]ai (an enterprise client production environment), oppbtp-preprod.riseup[.]ai (a pre-production client environment), e-citylearn.riseup[.]ai (a password-reset endpoint), and ise.riseup[.]ai. If Everest gained access to Rise UP’s production environment, they may have had the capability to access customer data, proprietary content, or session tokens across multiple client organizations. The presence of these credentials across a significant timeframe and their concentration on customer accounts suggests a potential avenue for deeper network access and data exfiltration. The substantial number of customer credentials exposed suggests that organizations utilizing Rise UP’s platform should conduct thorough audits of their authentication logs. This auditing process should cover the period from June 2024 to September 2026 to identify any anomalous session activity. Furthermore, organizations should evaluate the client-side data they host on Rise UP’s production environments for any signs of unauthorized access or compromise. Continuous dark web monitoring and proactive credential hygiene checks are recommended for all connected parties.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.