February 2026 security reporting placed records-management giant Iron Mountain in the Everest extortion ecosystem: the group claimed a large internal document haul while Iron Mountain emphasized a single deactivated credential, no ransomware on its own systems, and a one-folder exposure on a public-facing third-party file-sharing path consisting primarily of marketing materials—explicitly denying involvement of customer confidential data in its statements relayed by mainstream outlets.
Canonical record: Iron Mountain February 2026 cyber incident on BreachHistory.
Sources: Iron Mountain, BleepingComputer, Cybernews