The Everest ransomware group has claimed responsibility for a major cyberattack targeting McDonald’s India, alleging that it exfiltrated approximately 861 GB of sensitive data. The threat actors published details of the breach on their dark web leak site on January 20, 2026, warning that the stolen data would be publicly released if the company fails to engage with them before a specified deadline. As of now, McDonald’s India has not officially confirmed the incident or commented on the claims made by the attackers. According to Everest, the compromised data includes a vast collection of internal company documents along with personal information belonging to customers. The group stated that personal data of your customers and internal documents were leaked into our storage, claiming possession of a huge variety of personal documents and information of clients.If accurate, the scale and sensitivity of the data could expose affected individuals to serious risks, including identity theft, financial fraud, and highly targeted phishing campaigns across India. Everest is a Russian-speaking ransomware operation that first appeared in December 2020. Initially focused on data theft and extortion, the group later expanded into full-scale ransomware attacks using dual AES and DES encryption by early 2021. Unlike many ransomware gangs, Everest is known for pure extortion tactics, prioritizing data exfiltration and the threat of public leaks over file encryption alone. The group has recently targeted several high-profile organizations, including ASUS, Nissan Motor Corporation—where it claimed to have stolen 900 GB of data in January 2026—and Dublin Airport, which reportedly suffered the exposure of 1.5 million passenger records in October 2025. McDonald’s operates in India through two franchise entities: Connaught Plaza Restaurants, which manages North and East India, and Hardcastle Restaurants, responsible for West and South India. Serving millions of customers since 1996, the brand has faced cybersecurity challenges in the past, including reported data security incidents in 2017 and 2024. This latest claim underscores the growing cyber risk faced by large consumer-facing enterprises in the region.
A critical security issue in the Marimo Python notebook environment has raised serious alarm in the cybersecurity community due to its ability to enable unauthenticated remote comm...
A sophisticated software supply chain attack targeted the widely used Nx Console extension on the Microsoft Visual Studio Code Marketplace, potentially exposing more than two milli...
Critical security flaws have been discovered in the workflow automation platform n8n, prompting urgent warnings from cybersecurity researchers. The vulnerabilities, tracked as CVE-...