← Iron Mountain Inc

2026 Iron Mountain — Everest extortion claims vs vendor: single folder on public file-share; marketing materials

2026 Unknown records affected Share on X

Data compromised

Marketing-oriented vendor-share content per Iron Mountain; Everest claims of broader internal/client documentation cited in security press as unverified against the vendor statement

Technical writeup

Early February 2026 reporting described the Everest cybercrime group marketing roughly 1.4 TB of alleged Iron Mountain internal material while Iron Mountain told outlets that a lone compromised credential accessed one folder on a public-facing third-party file-sharing site consisting primarily of marketing assets shared with vendors, with no ransomware deployment and no broader Iron Mountain system breach in the vendor’s public framing. Press treated the gap between criminal marketing and corporate down-scope language as the central narrative.

Root cause

Stolen or phished login usable against a third-party file-sharing folder (per company statement summarized in BleepingComputer)

References