RANSOMWARE VICTIMTRANSPORTATION/LOGISTICSDUPLICATE CLAIM

Atlas Air

everest📍 United States (US)📅 February 6, 2026
1
linked CVEs
8
same group

Attack Intelligence

Atlas Air was compromised in a ransomware attack attributed to everest in February 2026. The organization, operating in the Transportation/Logistics sector in United States, was added to the group's data leak site as part of an extortion campaign.

everest operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

[AI generated] Atlas Air Worldwide Holdings Inc. is a cargo and passenger charter airline based in Purchase, NY. Founded in 1992, Atlas Air operates globally with a large and efficient fleet of Boeing 747 aircraft. The company offers a variety of services like outsourced aircraft, crew maintenance, and insurance (ACMI), charter businesses, and dry leasing.

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-3300, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — everest (8)

Quick Facts

CountryUnited States (US)
SectorTransportation/Logistics
Attack DateFeb 6, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

everest
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.