Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Hackers Claim Coca-Cola Data Breach, 23 Million Records Allegedly Exfiltrated
Data Breach Attacks Data Protection Latest News News & Analysis Ransomware

Hackers Claim Coca-Cola Data Breach, 23 Million Records Allegedly Exfiltrated

Kirsten DoyleBy Kirsten DoyleMay 23, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Hackers Claim Coca-Cola Data Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Two hacking groups have claimed responsibility for cyberattacks targeting Coca-Cola, with one alleging the theft of over 23 million records. 

Cyber Security News reported that in posts on dark web forums, the Everest ransomware group claims to have breached Coca-Cola’s internal systems, focusing on data linked to its Middle East operations.  

Known for previous attacks on NASA and the Brazilian government, Everest reportedly exfiltrated sensitive and confidential company information. However, the credibility of the claim is uncertain, especially after the group’s own leak site was defaced in April. 

In a separate incident, the Gehenna hacking group alleges it compromised Coca-Cola Europacific Partners’ Salesforce dashboard in early May. The group says it stole 23 million records spanning from 2016 to 2025, including account details, contact information, product data, and customer case files, potentially exposing vast amounts of sensitive CRM data. 

Coca-Cola Europacific Partners, the beverage giant’s largest bottler across Europe and the Asia Pacific, has not confirmed the breach. The company has been heavily investing in digital transformation, a strategy that could be jeopardized by such a significant security incident. 

These are not isolated events. In 2023, a Coca-Cola bottler reportedly paid $1.5 million to bad actors to prevent a data leak. In 2018, the company disclosed a breach involving data from 8,000 employees. 

While neither Coca-Cola nor Coca-Cola Europacific Partners has released an official statement, security analysts caution that ransomware groups often exaggerate claims to pressure victims. 

Customers and partners are urged to stay alert and monitor Coca-Cola’s official channels for updates and security guidance. 

Lucrative Targets 

Jamie Akhtar, CEO and Co-founder at CyberSmart, says it goes to show that no brand, no matter how global or well-resourced, is immune to today’s sophisticated cyber threats.  

High-profile companies like Coca-Cola alucrative targets for financial extortion, and the reputational impact a breach can have. “Attackers understand that these organisations are under intense pressure to keep operations running and reputations intact, making them prime candidates for ransomware demands and public data exposure. 

“What’s particularly concerning is Everest’s strategy of not only encrypting systems but stealing and publishing sensitive data to pressure victims into paying,” adds Akhtar. “This double-extortion method has become the norm, turning cyber attacks into long-term reputational crises rather than one-off incidents. For a consumer-facing brand, the fallout isn’t just about internal disruption but also about about broken trust. In industries where brand loyalty is key, data leaks that involve personal or operational information can have a lingering effect on customer confidence.” 

 Agnidipta Sarkar, Vice President CISO Advisory at ColorTokens, says: “These hackers are known to use double extortion, which means that there could be ransomware at play while they are peddling stolen information. But today’s hackers are in it for the money and not for activism, and they are not known to be consistent. What they got may be of little importance, or they could have hit pay dirt.” 

Insufficient Cybersecurity Investments? 

Sarkar says what is interesting to note is that their darknet site was defaced in April this year and had to go offline. “Initial research suggests that they use harvested credentials and exfiltrate Active Directory, too. However, this could be a bogus claim, too. If this is a genuine attack, I assume that existing cybersecurity investments of Coca-Cola into state-of-the-art technology were insufficient to stop this attack, and hence, the perpetrators succeeded. I am not sure we will ever know, but it would be nice to know if they had controls to anticipate, contain, and evolve their breach readiness.” 

As companies adopt more SaaS solutions, it creates opportunities for ransomware actors to get their hands on sensitive data, adds John Bambenek, President at Bambenek Consulting. “Many SaaS tools don’t offer the same kinds of robust logs and security detections as IaaS vendors which means organizations can often be blind to attacks on their own data. Organizations should start thinking about how they can get logs from their SaaS applications into their SIEM and develop detections that indicate data exfiltration.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}