Omnicell Data Breach: Everest Ransomware Group Claims 1TB Stolen from the Healthcare Automation Firm 

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Claim reported: Everest hacking group claims to have breached Omnicell and stolen 1 TB of data across more than 682,887 files.
  • Data stolen: The archive reportedly includes healthcare and pharmacy automation software, source code, SQL databases, credentials, and firmware.
  • Verification pending: The claim, observed July 22, 2026, has not been confirmed by Omnicell or independent researchers.

The Everest ransomware group has announced an Omnicell data breach, alleging the theft of 1 terabyte of data spanning more than 682,887 files. Omnicell and independent security researchers have not confirmed the claim, which is momentarily pending verification.

What Everest Claims Was Stolen

According to the posting, which was first flagged by threat-intelligence tracker Hackmanac, the allegedly exfiltrated archive belonging to the U.S.-based provider of medication management and pharmacy automation systems includes:

Everest claims Omnicell data breach | Source: HackManac on X
Everest claims Omnicell data breach | Source: HackManac on X

The claim also alleges the data includes customer implementation records tied to partners in Saudi Arabia, Australia, the UAE, Ireland, Singapore, Qatar, South Korea, Chile, Spain, Sweden, and the Netherlands, pointing to a potential international scope if proven real. 

A Claim Still Awaiting Confirmation

Neither Omnicell nor independent cybersecurity outlets have confirmed the breach at this time, and no proof of the alleged data has been made public. Everest is an extortion group active since at least December 2020, known for double-extortion tactics and a pattern of high-volume claims against many sectors. 

The group has made several large claims in recent months, and past incidents have shown that Everest's stated data-theft figures do not always hold up to technical scrutiny.

Why a Confirmed Breach Would Matter

Omnicell manufactures automated medication management systems used by hospitals, long-term care facilities, and retail pharmacies. The company previously disclosed a ransomware attack in May 2022, which affected internal systems and ultimately impacted tens of thousands of patients. 

The alleged inclusion of source code, firmware, and deployment packages would raise supply-chain concerns given the company's role in hospital medication infrastructure.

Earlier this year, Everest Group claimed a massive Nissan data breach, with sportswear giant Under Armour, Coca-Cola, and Mailchimp also claimed in 2025.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: