Data breach
Evaluate
- Records
- 248,458
- Breach date
- 15 March 2026Estimated
- Added
- 3 August 2026
What was exposed
4 types of data
- Names248,458
- Email addresses145,564
- Phone numbers93,925
- Street addresses62,623
About this breach
The Everest ransomware group publicly claimed responsibility for a cyberattack against Evaluate, a pharmaceutical market intelligence firm owned by Norstella, according to our investigation team and reporting from threat-tracking services. The claim appeared on March 15, 2026, when the group said it had stolen data from the company and threatened to publish it unless negotiations began. Evaluate, based in the UK, sells commercial data, consensus sales forecasts, and analytics to pharmaceutical and medical device companies. The investigation team added the listing on August 3, 2026, after indexing roughly 248,000 rows of exposed data.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
March 15, 2026: The Everest ransomware group publicly claimed responsibility for attacking Evaluate, a Norstella company, and threatened to release the stolen data unless the company made contact, as reported by dExpose.
March 16, 2026: Reporting by Daily Dark Web and Breachsense described the group's claim that it exfiltrated a large database, which the actors said was taken from an insufficiently secured SFTP server.
What Information Was Compromised?
Our analysis found the following data types in this breach: names for all 248,458 indexed records, 145,564 email addresses, 93,925 phone numbers, and 62,623 street addresses.
Not every individual is affected by every type of data listed here.
The group behind the attack also made broader claims about what it stole. According to Daily Dark Web, the actors said the haul included pharmaceutical forecast data, client models, internal HR records, and what they described as patient-level treatment data. These claims have not been independently verified, and no confirmed company notice listing additional fields was available as of September 25, 2026.
What Are the Potential Risks for Affected Individuals?
The confirmed data types in this breach, particularly the combination of names with email addresses, phone numbers, and home addresses, are well suited to targeted phishing. Someone holding this information can send convincing messages that reference real details about a person's life, making scams harder to spot.
Phone numbers open the door to smishing, which is phishing by text message, and to unwanted calls. Street addresses can support fraudulent mail and add credibility to impersonation attempts. Because the actors' unverified claims include internal company data, people whose information was exposed through their employer's relationship with Evaluate could face additional targeting. If the more sensitive claims about patient-level data prove accurate, that would raise the risk of exposure of medical information, which cannot be changed the way a password can.
What Should You Do If You Were Affected?
Be cautious with unexpected emails, texts, or calls, especially any that mention your name, address, or a company you do business with. Do not click links or share codes from unsolicited messages.
Use strong, unique passwords for each account and turn on multi-factor authentication wherever it is offered.
Watch your financial accounts and credit reports for activity you do not recognize, and consider a fraud alert or credit freeze if your address was involved.
If you receive messages claiming to come from Evaluate or Norstella, verify them through the companies' official websites rather than links or numbers provided in the message.
