Desk live·
ForensicPost
Breaches/Manufacturing/File 25-1111

A Hundred and Fifty-Nine Gigabytes, Claimed

The Everest group claimed on 11 November 2025 to have taken 159GB from SIAD, an Italian industrial gas company. The number is the attacker’s and the corpus records it as such.

Constructed geometry · not a chart of case data
JurisdictionItalyBergamothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSIAD Group
ActorEverest
S. Rosler10 min readConfidence: low2 sources reviewed

The ransomware group operating as Everest claimed on 11 November 2025 to have stolen 159GB of data from SIAD Group, an Italian chemical and industrial gas company.

A Volume In Gigabytes Tells You Almost Nothing

This desk filed the argument at 26-0425 and 25-1230: leak-site figures are advertisements written by the seller, published to establish credibility and apply pressure.

Gigabytes are a particularly poor unit. A single CAD assembly or a video archive can be tens of gigabytes and concern nobody. A 200-megabyte database can hold every customer a company has. The number is chosen because it sounds large.

Industrial Gas Is A More Interesting Target Than It Sounds

A company supplying industrial and medical gases sits upstream of manufacturing, food processing and hospitals. Its customer records describe what other companies consume, in what volumes, at which sites — which is a usable picture of industrial activity across a country.

And medical gas supply is a hospital dependency of the kind filed at 25-0415 and 25-0801: a supplier whose disruption reaches patients through a route nobody counts.

This desk is describing what such a company holds, not what was taken. Nothing has been verified.

Graded Low, And That Is The File

A group claim, a volume figure, and a date. No confirmation from the company, no verified sample, no established impact.

It is recorded because the corpus’s European coverage is thin — the bias documented at 25-1225 — and because an unverified claim, clearly labelled, is more useful than a gap that implies nothing happened.

How we reported this

Compiled from published incident briefings, listed below. The 159GB figure originates with the attacking group and is recorded as a claim. No company confirmation was available in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber Brief 25-12 — November 2025CERT-EU
  2. Significant cyber incidentsCSIS
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary