[EVEREST] – Ransomware Victim: Mailchimp
![[EVEREST] - Ransomware Victim: Mailchimp 1 image](https://www.redpacketsecurity.com/wp-content/uploads/2024/09/image.png)
Ransomware Group: EVEREST
VICTIM NAME: Mailchimp
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the EVEREST Onion Dark Web Tor Blog page.
AI Generated Summary of the Ransomware Leak Page
The ransomware leak pertains to Mailchimp, a prominent marketing automation and email marketing service based in the United States. The attack was discovered on July 31, 2025, with an attack date recorded as July 26, 2025. Mailchimp offers a variety of functionalities, including campaign management, audience segmentation, dynamic content, analytics, and website creation tools. The leak image includes a screenshot of internal content, indicating that the attackers may have accessed significant data. Information suggests that data related to the platform’s internal operations or user data might have been compromised, although specific details are not provided. The incident highlights potential security vulnerabilities within the company’s infrastructure, which could impact clients relying on its services.
The leak webpage includes references to further data disclosures or potentially leaked files, as well as visuals such as screenshots of internal documents or dashboards. This indicates possible exposure of sensitive information or proprietary content. The attack was claimed by a group known as “everest,” which is possibly associated with other cybercriminal activities. The compromised data could pose risks to user privacy and corporate confidentiality, emphasizing the importance of cybersecurity vigilance. The page features a link to the claim URL, hosted on the dark web, where additional details or data may be accessible. The incident underscores the ongoing threat landscape faced by technology service providers in safeguarding client and company information.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.