Ransomware victim disclosure
← All victimsEmpresas Públicas de Medellín (EPM)
listed as EPM · Claimed by Everest · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- Colombia
- Sector
- Energy & Utilities
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileEPM is a major Colombian public utility company headquartered in Medellín that provides electricity generation and distribution, water supply, sewage, and natural gas services. It operates across Colombia and has expanded into other Latin American countries, serving millions of customers.
- Industry
- Energy & Utilities (Electricity, Water, Sewage, Natural Gas)
- Address
- Medellín, Colombia
Attack summary
Severity: critical — EPM is critical infrastructure (major public utility providing electricity, water, and gas to millions). Confirmed data publication by ransomware group on a public utility of this scale and national importance constitutes a critical breach regardless of specific data inventory details.The Everest group claims to have conducted an attack on EPM resulting in data exfiltration. The group has published data from the breach, though specific details on the scope and nature of exfiltrated information are not provided in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- operational/business systems data
- customer information
- financial records
Original description
AI-summarised, not from the leak postEPM (Empresas Públicas de Medellín) is a Colombian public utility company headquartered in Medellín, Colombia. It operates in the energy, water, and telecommunications sectors, providing electricity generation and distribution, water supply, sewage, and natural gas services. It serves millions of customers across Colombia and has expanded operations into other Latin American countries, making it one of the largest public utility groups in the region.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

