[EVEREST] – Ransomware Victim: Watchfinder & Co

image

Ransomware Group: EVEREST

VICTIM NAME: Watchfinder & Co

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the EVEREST Onion Dark Web Tor Blog page.


AI Generated Summary of the Ransomware Leak Page

The leak page pertains to Watchfinder & Co, a prominent retailer specializing in pre-owned luxury watches, founded in 2002 in the United Kingdom. The company is known for offering high-end brands such as Rolex, Cartier, and Omega, and combines online sales with physical stores to provide authentic and thoroughly inspected timepieces. The breach was discovered on July 23, 2025, and involved a ransomware attack. The incident has resulted in the public leak of certain data related to the company’s operations. The page includes a screenshot depicting internal information, which suggests that sensitive operational data may have been compromised. Download links or data exfiltration details appear to be available, indicating potential exposure of proprietary information. The attacker group responsible is identified as “everest,” and the attacker has published a link to their claim page on the dark web. Despite the leak, no specific PII of customers or employees has been disclosed publicly. The incident underscores the importance of cybersecurity measures for businesses operating in the consumer retail sector. The breach date is set for July 21, 2025, indicating a recent compromise, and the threat actors may continue to exploit or leak additional data. Overall, the attack poses a serious threat to the company’s reputation and operational integrity, emphasizing the need for prompt response and mitigation strategies.


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.