Neighbor News
Coca-Cola Hit by Ransomware: Employee Personal Information at Risk
Global Beverage Giant Investigates After Sophisticated Cyberattack Threatens Employee Security and Business Continuity

On May 22, 2025, the global beverage giant Coca-Cola fell victim to a ransomware attack orchestrated by the Everest hacking group. The attack reportedly compromised the sensitive internal information and personal data of nearly 1,000 employees, primarily affecting Coca-Cola’s operations in the Middle East.
The Everest ransomware group, active since 2020, is known for its sophisticated cyberattacks involving double extortion tactics—encrypting victim files while simultaneously exfiltrating sensitive data to pressure victims into paying. The group has a history of targeting high-profile organizations, including NASA and the Brazilian government, and is linked to ransomware-as-a-service operations. According to dark web posts and leaked data samples, the stolen information includes employee identification details and internal company documents, such as salary information, which could be exploited for identity theft, financial fraud, or targeted phishing campaigns.
The attack also appears to have impacted Coca-Cola’s Middle East distributor, raising concerns about the security of regional operations. Coca-Cola has yet to issue an official statement regarding the breach. They are reportedly working with law enforcement and forensic teams to investigate the incident.
Find out what's happening in Princetonfor free with the latest updates from Patch.
This attack coincides with a separate breach claimed by the Gehenna hacking group targeting Coca-Cola Europacific Partners’ Salesforce database that occurred two months ago. These attacks underscore a challenging cybersecurity landscape for the beverage giant and its affiliates.
As ransomware attacks continue to escalate globally, this incident highlights the critical need for robust cybersecurity defenses and vigilance against increasingly sophisticated cyber threats.