A ransomware group is claiming it stole the blueprint for how hospitals dispense medication

not just patient records, the actual software and firmware behind it.
The Everest ransomware group says it exfiltrated 1 TB of data, more than 682,887 files, from Omnicell, the pharmacy automation and medication management vendor used by hospitals worldwide. The claim, posted July 22, 2026, remains unverified by Omnicell or independent researchers.
WHAT ACTUALLY HAPPENED
Everest posted the claim on its leak site: Omnicell's pharmacy automation software, partial source code, SQL databases and backups, credentials, certificates, firmware, deployment packages, and customer implementation records.
The named customers reportedly span Saudi Arabia, Australia, the UAE, Ireland, Singapore, Qatar, South Korea, Chile, Spain, Sweden, and the Netherlands — hospital networks running Omnicell's automated dispensing cabinets.
Omnicell has not confirmed the breach, and Everest's stated figures have not always held up to scrutiny in past incidents. Treat the 1 TB / 682,887-file claim as unverified, not fact. This is also not Omnicell's first incident: a May 2022 ransomware attack there ultimately impacted tens of thousands of patients.
WHY THIS IS DIFFERENT FROM A TYPICAL BREACH
A stolen customer list is bad. Stolen source code, firmware, and deployment packages for a medication-dispensing platform is worse — it is the engineering behind systems that control what drugs get dispensed in hospitals across a dozen countries.
That material does not just expose Omnicell. It lets attackers study the platform offline, find undisclosed flaws, and craft supply-chain attacks against every hospital running that software, whether or not Omnicell's own network is breached again.
WHAT TO DO NOW
VERIFY YOUR EXPOSURE DIRECTLY — if you run Omnicell systems, contact your vendor rep for confirmation instead of waiting on a public notice.
ROTATE CREDENTIALS TIED TO OMNICELL DEPLOYMENTS — treat any credentials or certificates shared with the vendor as compromised until proven otherwise.
WATCH FOR FIRMWARE-LEVEL ANOMALIES — stolen firmware and deployment packages could inform attacks on dispensing cabinets; flag unexpected updates now.
DO NOT DISMISS UNVERIFIED CLAIMS — Everest's numbers may be inflated, but pharmacy automation vendors sit deep inside hospital supply chains; act on the exposure risk regardless.
Medication dispensing runs on trust in a vendor's software. Right now, that trust is exactly what is in question.
If a supplier deep in your supply chain got breached tomorrow, would you find out from them — or from a leak site?