Rx Networks Data Breach

Alleged

Ransomware claim involving Rx Networks.

Published: Aug 17, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Rx Networks
Industry
Technology
Threat Actor
Everest
Date of Incident
Aug 17, 2026

Executive Summary

Rx Networks, a Canadian company operating in the positioning and location technology sector, was identified as a victim by the Everest ransomware group. The listing appeared on Everest’s dark web portal on August 17, 2026, which was detected by SOCRadar’s Dark Web Monitoring service. Rx Networks specializes in providing GNSS and geolocation services to manufacturers of mobile and IoT devices. The presence of rxnetworks[.]com in the Everest dataset, which was first observed on July 21, 2026, indicates a potential dwell period of approximately four weeks between the initial compromise and the public listing on the threat actor’s site. This timeline suggests a deliberate staging and exfiltration process before extortion. In the 60 days leading up to this listing, Everest claimed 21 other victims. The ransomware group primarily targets the Technology, Healthcare, and Manufacturing sectors, with a geographical concentration in the United States, India, and the United Arab Emirates. Notable recent victims in the technology sector include Keysight, Alzone Software, Allied Telesis, and TechCorr. Rx Networks aligns with Everest’s established pattern of targeting specialized engineering and infrastructure-adjacent firms, suggesting the group may perceive such companies as valuable targets for data exfiltration and extortion.

Technical Analysis

SOCRadar’s query against the stealer-log dataset for the domain rxnetworks[.]com returned no records within the sampled data slice. It is important to note that these datasets are typically paginated samples, and the absence of results does not definitively rule out the presence of compromised credentials. Such credentials could exist in adjacent data slices, under alternate corporate domains not included in the query, or might have been exfiltrated using employee personal email aliases. The observed four-week gap between the initial sighting of rxnetworks[.]com in the Everest dataset (July 21, 2026) and the public listing date (August 17, 2026) is a significant factor. This extended period suggests that data was likely staged and exfiltrated over a prolonged duration, potentially outside the specific timeframe covered by the queried stealer-log samples. Consequently, a null result from this specific query carries less definitive weight than usual in assessing the extent of compromise. Everest ransomware commonly exploits credentials obtained from infostealers as a primary method for initial access. This typically involves sourcing compromised logs from underground markets, validating corporate login credentials, and then leveraging them to gain access to systems such as Microsoft 365, VPNs, or other remote-access portals before deploying their ransomware payload. This modus operandi aligns with a scenario where initial access might have been gained via an Initial Access Broker (IAB) rather than a deep, targeted intrusion. However, the multi-week dwell period observed in this incident warrants a thorough forensic investigation. Furthermore, the potential exposure of Rx Networks’ IoT and GNSS product data could also lead to downstream customer notification obligations, adding another layer of complexity to the incident response. Next Steps: – Query stealer-log sources under alternate domains and employee personal email aliases – Review Microsoft 365 and VPN access logs from July 21 onward – Assess scope of GNSS and IoT product data exposure – Monitor Everest’s leak portal for data publication or ransom status changes

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.