Everest Ransomware Group Claims Breach of Al-Futtaim

The Everest ransomware group has claimed responsibility for a cyberattack targeting Al-Futtaim, one of the Middle East’s largest business groups. According to the threat actor, approximately 307 GB of data, containing more than 161,000 files, was stolen during the alleged breach. At the time of publication, these claims have not been independently verified by Al-Futtaim or other trusted sources.

The ransomware group alleges that the stolen information includes corporate and financial records, human resources files, customer information, identity documents, SAP data, email archives, engineering drawings, and operational documentation.

If these claims are confirmed, the exposed information could be used in phishing campaigns, identity fraud, business email compromise (BEC) attacks, and other scams targeting employees, customers, suppliers, and business partners.

This incident also highlights the continued evolution of ransomware attacks. Today, many ransomware groups do not rely only on encrypting systems. Instead, they first steal sensitive data and then threaten to publish it unless a ransom is paid. This double-extortion approach increases pressure on victim organizations and raises the potential impact of an attack.

Large organizations operate through extensive networks of customers, suppliers, and business partners. As a result, a cyberattack affecting one organization can have wider consequences across its entire business ecosystem.

Organizations should continue strengthening their cybersecurity programs by protecting sensitive data, monitoring their networks, implementing strong access controls, maintaining secure backups, and preparing effective incident response plans. Regular employee awareness training also remains essential to reduce the risk of phishing and social engineering attacks.

Customers and business partners should remain cautious following reports of potential data breaches. Unexpected emails, phone calls, or messages requesting personal, financial, or login information should always be verified through official communication channels before any information is shared.

Cybersecurity is not only about protecting technology. It is also about protecting people, privacy, business operations, and the trust that organizations build with their customers and partners.