Ransomware victim disclosure
← All victimsKÖRBER
Claimed by Everest · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profileKörber is a German technology conglomerate headquartered in Hamburg that operates across supply chain automation, pharmaceuticals, tissue, tobacco, and digital solutions. The company develops software, machinery, and integrated systems for logistics, healthcare, and manufacturing sectors globally.
- Industry
- Supply Chain Automation, Pharma, Tobacco & Digital Solutions
- Address
- Hamburg, Germany
Attack summary
Severity: medium — Data published status confirmed but no proof files advertised, no specific data types disclosed, and no operational impact stated. Critical infrastructure potential given Körber's role in supply chain and pharma, but insufficient evidence of actual exfiltration.The Everest group claims to have accessed Körber's systems. No specific details about exfiltration, encryption, or data types are provided in the available leak post.
Original description
AI-summarised, not from the leak postKörber is a German technology conglomerate headquartered in Hamburg, Germany. The company operates across multiple industries including supply chain automation, pharma, tissue, tobacco, and digital solutions. Körber develops and delivers software, machinery, and integrated systems to help businesses optimize their operations. With a global presence spanning numerous countries, it serves clients in logistics, healthcare, and manufacturing sectors worldwide.
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

