In early 2026, the Everest ransomware group claimed to have breached Iron Mountain, a global leader in information management services. The group alleged the exfiltration of 1.4 TB of internal company documents, personal documents, and client information. Iron Mountain, however, stated that the incident did not reach its core systems and did not involve customer confidential or sensitive data. The alleged data theft primarily involved a public-facing file-sharing site used for vendor marketing materials.
The specific types of customer data compromised and the number of individuals affected have not been publicly confirmed. There is no confirmed information regarding the exposure of SSN, medical, or financial data. Similarly, the specific US states affected have not been disclosed. The incident was reported by a dark web news source, and there are no confirmed public disclosures concerning affected individual counts, state AG filings, or official breach notification letters.
Details about the incident, especially concerning any confirmed personal data exposure, may emerge later as investigations progress, and official notices may be delayed.