Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ransomware-group-operationunderground-data-leakmass-credential-exposurethird-party-vendor-breach

Everest Ransomware Extortion Claims Target McDonald’s India and Under Armour

Updated 3mo agoFirst seen Jan 21, 20262 sources

The Everest ransomware group publicly claimed two separate victim intrusions, alleging large-scale data theft and using leak-site pressure tactics. Everest posted that it breached McDonald’s India, claiming exfiltration of 861 GB of customer data and internal documents and sharing screenshots purportedly showing financial reports, audit trails, pricing data, internal communications, and month-by-month directories suggestive of access to accounting/ERP systems. The leak claim also referenced a “Contact Database” spreadsheet with personal and business details of investors/partners across multiple countries and store-level operational data (e.g., manager names and contact numbers), alongside a short deadline for the company to respond.

Separately, Have I Been Pwned (HIBP) reported ingesting files allegedly leaked by an Everest member that impacted 72.7 million Under Armour accounts, with exposed fields including names, email addresses, dates of birth, gender, location, and purchase-related details; Everest additionally claimed other data types (e.g., phone numbers, addresses, loyalty details) and had previously threatened publication unless a ransom was paid. Under Armour had not publicly acknowledged the alleged incident at the time of reporting, and a proposed class action lawsuit was filed following Everest’s initial leak-site posting. A third report about RansomHub claiming an intrusion at Apple partner Luxshare describes a different ransomware operation and does not appear connected to the Everest claims.

Share:
Everest Ransomware Extortion Claims Target McDonald’s India and Under Armour
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 21, 20265mo ago

HIBP ingests alleged Under Armour leak affecting 72.7 million accounts

By January 21, 2026, Have I Been Pwned had ingested the files leaked on January 18 and reported that 72.7 million Under Armour accounts were affected. HIBP said the exposed records contained personal and purchase-related information from the alleged ransomware-linked leak.

Jan 20, 20265mo ago

Everest claims breach of McDonald's India on leak site

On January 20, 2026, Everest posted McDonald's India on its dark web leak site, alleging it had exfiltrated 861 GB of customer data and internal company documents. The group shared screenshots and set a two-day deadline for the company to respond, while McDonald's India had not publicly commented at the time of reporting.

Jan 18, 20265mo ago

Everest member leaks alleged Under Armour data on a cybercrime forum

On January 18, 2026, files allegedly tied to the Under Armour incident were leaked by an Everest member via a cybercrime forum. The leaked data was later described as including names, email addresses, dates of birth, genders, geographic locations, and previous purchase details.

Nov 21, 20257mo ago

Everest posts Under Armour on its leak site and threatens data release

About two months before January 21, 2026, the Everest ransomware group added Under Armour to its leak site, claiming to have stolen data and threatening to publish it unless an undisclosed ransom was paid within seven days. The posting prompted a proposed class action lawsuit by a law firm on behalf of an Under Armour customer.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
1 linked
Organizations
9 linked
HackReadMcDonald's IndiaHave I Been PwnedIngram MicroHalcyonASUSCollins AerospaceChimicles Schwartz Kriner & Donaldson-SmithUnder Armour
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.