Unverified claim. Extortion group Everest listed healthcare automation vendor Omnicell on its leak site around July 22–23, 2026, alleging theft of about 1TB of data—more than 682,000 files.
Omnicell had not confirmed the listing in sources reviewed. TechNadu and ransomware trackers reported the claim; no public proof archive was available at initial write-ups.
What Everest allegedly took
Monitors describe healthcare and pharmacy automation software, partial source code, SQL databases and backups, credentials and certificates, firmware, deployment packages, and customer implementation records. That mix—if authentic—matters less as a classic patient-list breach and more as a hospital medication-cabinet supply-chain risk.
What this is not
This is not a company-attested patient count. It is also not Omnicell’s separate May 2022 ransomware incident, which the company previously disclosed and which affected tens of thousands of patients. Keep the two events distinct.
Who should care
Hospital and pharmacy IT teams that run Omnicell automated dispensing and related systems; partners named in any future notice. Watch for phishing that pretends to be an Omnicell “incident response” portal.
Action items
- Wait for an Omnicell or regulator notice before treating patient PHI as confirmed stolen.
- If you integrate with Omnicell, inventory shared credentials, VPN tunnels, and deployment packages—and rotate on confirmation.
- Ignore cold calls demanding ransom “on Omnicell’s behalf.”
Canonical record
Omnicell Everest claim (unverified). Sources: TechNadu, FalconFeeds.