Ransomware victim disclosure
← All victimsNIMR Oil
Claimed by Everest · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Energy & Utilities
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileNIMR Oil is a 100% Qatari-owned oil and gas service provider operating from Qatar with 35 years of experience. The company offers comprehensive service solutions across upstream, midstream, and downstream segments, including well intervention, pipeline services, and process projects for the oil, gas, petrochemical, and power generation industries.
- Industry
- Oil & Gas Services
- Address
- Qatar
- Founded
- 1988
Attack summary
Severity: medium — Confirmed data publication by ransomware operator against a critical infrastructure service provider in the energy sector. No specific data types (PII, financial records, etc.) are detailed, and no proof files are quantified, preventing 'high' or 'critical' classification.The Everest group claims to have compromised NIMR Oil and published exfiltrated data. No specific details about the scope of exfiltration or encryption are provided in the available post.
Data the group says was taken
AI dossier — extracted from the leak post- Business operational data
- Client information
- Technical documentation
Original description
AI-summarised, not from the leak postNIMR Oil is an Omani oil and gas company operating primarily in the Sultanate of Oman. It specializes in the production, processing, and management of crude oil and natural gas resources. The company works within Oman's energy sector, often collaborating with the national oil infrastructure. NIMR is known for operating mature oilfields and applying enhanced recovery techniques to maximize output from established reserves.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

