1. Executive summary
On 7 September 2026, the ransomware group "everest" publicly listed the German technology conglomerate Körber (headquartered in Hamburg) as a victim on its leak site. The listing is a claim of compromise only: no technical detail on initial access, malware, or data volume is present in the source material, and no independent corroboration of the intrusion exists at time of writing. Attribution to "everest" is unconfirmed — the actor has no MITRE ATT&CK profile in our verified reference data, and the claim rests entirely on the group's own leak-site post. Körber supplies software, machinery and integrated systems to logistics, healthcare and manufacturing clients globally, so EMEA financial services exposure is indirect — via supply chain — rather than direct, unless a client runs Körber-supplied operational technology or depends on Körber as an ICT service provider.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | Körber is a technology supplier of software and integrated systems to logistics, healthcare and manufacturing sectors; a claimed ransomware compromise of that supplier engages clients' third-party risk obligations where Körber is in their ICT or OT supply chain. | Clients with Körber in their supplier register should trigger third-party risk assessment: confirm whether any contracted Körber product or service touches production ICT/OT estate, and open a supplier incident query. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A named ransomware group has publicly claimed compromise of a specific supplier; this is a cyber threat requiring classification under clients' incident processes even absent confirmed impact. | Classify the claim, record the decision rationale, and escalate to Art. 19 reporting only if major-incident thresholds are met (i.e. if the supplier relationship is confirmed and impact materialises). |
No NIS2 or UK NIS article is directly engaged by this item on the facts available; the trigger would only arise for an entity with a confirmed, impactful dependency on Körber.
3. Technical analysis & attack chain
No confirmed attack chain can be reconstructed from the source material. The ransomware.live entry contains only: group (everest), victim (Körber), country (DE), and a leak-site screenshot reference. There is no description of initial access, exploited vulnerability, malware family, persistence mechanism, C2 infrastructure, exfiltration volume, or ransom demand.
What is established:
- The claim itself. The group "everest" posted Körber to its leak site, dated 7 September 2026. Ransomware.live indexes this public post; the platform explicitly does not access or verify the underlying stolen data.
- The victim profile. Körber is a German technology conglomerate headquartered in Hamburg, operating in supply chain automation, pharma, tissue, tobacco and digital solutions, serving logistics, healthcare and manufacturing clients worldwide. This is a broad industrial footprint, not a financial-services-specific one.
- Actor context. The same actor listed Capgemini Engineering (FR) in a separate claim, indicating ongoing targeting of large European technology and engineering services firms. This is context only — it does not corroborate the Körber intrusion.
Confidence caveat: Every material claim here is single-sourced — the ransomware.live index of the everest leak-site post. There is no victim statement, law-enforcement action, or second vendor report corroborating the compromise. The "everest" attribution is unconfirmed: the actor has no MITRE ATT&CK profile in our verified reference data. Treat the listing as an unverified extortion claim until Körber or a credible third party confirms. Note also that a leak-site listing does not establish that ransomware was deployed — some listings reflect data-theft extortion only; the source does not distinguish.
4. Mitigation & containment
P1 — within 24h
- Query your supplier/asset registers for Körber and any subsidiaries or branded product lines (supply chain automation, pharma software, digital solutions). If a dependency exists, contact the Körber relationship owner for a status statement.
- If Körber-supplied software is present in production ICT or OT estates, inventory the versions and any integrations (APIs, data feeds, remote-access tunnels) that could serve as a pivot path.
- Block nothing yet — there are no IOCs and no confirmed intrusion. Do not take network action against a supplier on the basis of an unverified claim.
P2 — within 72h
- Where a Körber dependency is confirmed, review the integration points identified at P1 for excessive trust: shared credentials, unmonitored file transfer paths, site-to-site VPNs with broad subnet access. Tighten to least privilege as a precautionary measure.
- Log and retain any inbound/outbound traffic to Körber-managed systems or Körber update/delivery infrastructure for retrospective review.
- Record the classification decision and rationale under your incident process (DORA Art. 18).
P3 — within 7 days
- If Körber issues a public statement or advisory, incorporate it and re-assess.
- For clients with Körber in the ICT supply chain, fold this event into the third-party risk assessment cycle (DORA Art. 28) — verify contractual incident-notification provisions are operative and tested.
- Monitor for follow-on claims: everest's pattern of listing large European engineering/technology firms (Capgemini Engineering, FR) suggests continued targeting of this sector; watch for additional supply chain victims.
5. Indicators of compromise
No indicators of compromise available in the source material.
No behavioural indicators are described in the sources either — the listing contains no detail on access patterns, exfiltration behaviour, or malware activity.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live — Victim: KÖRBER – everest — https://www.ransomware.live/id/S8OWUkJFUkBldmVyZXN0 — 2026-09-07
- Ransomware.live — Victim: Capgemini Engineering – everest (context on actor targeting pattern) — https://www.ransomware.live/id/Q2FwZ2VtaW5pIEVuZ2luZWVyaW5nQGV2ZXJlc3Q= — undated in source
8. Adverse Trace position
This is an unverified, single-sourced extortion claim against a German industrial technology conglomerate with no financial-services-specific footprint; severity for direct EMEA FS impact is low pending corroboration, with the residual risk sitting in supply chain dependencies. Attribution to "everest" is unconfirmed — no MITRE ATT&CK profile exists for the actor in our verified reference data — and the listing does not establish ransomware deployment as distinct from data-theft extortion. We are not changing any client-facing threat level on this item. We will monitor for a Körber statement, second-source corroboration, or IOCs emerging from the leak-site post, and will reissue this advisory at version 2.0 if the claim is confirmed or technical detail surfaces. Clients with Körber in their ICT/OT supply chain should action the P1 register query now; others need take no action beyond awareness.
Published via PulseTrace — Adverse Trace threat intelligence.