Cyber Security News

Everest Ransomware Group Allegedly Claims to Have Breached McDonald’s India

The Everest ransomware group has claimed responsibility for a major cyberattack targeting McDonald’s India, allegedly exfiltrating 861 GB of sensitive data.

The threat actors posted details of the breach on their dark web leak site on January 20, 2026, threatening to publicly release the stolen information if the company fails to respond within a specified deadline.

According to the ransomware group’s claims, the breach compromised a massive volume of internal company documents and customer personal data.

The attackers stated that “personal data of your customers and internal documents were leaked into our storage,” including a “huge variety of personal documents and information of clients”.

The stolen data reportedly contains internal records that could pose significant risks for identity theft and targeted phishing campaigns across the region.

Everest is a Russian-speaking ransomware operation that emerged in December 2020, initially focusing on data exfiltration before evolving to full ransomware capabilities with dual AES/DES encryption by early 2021.

The group is well-known for “pure extortion” tactics, specializing in stealing and selling sensitive corporate data rather than just encrypting files. Recent high-profile victims include ASUS, Nissan Motor Corporation (900 GB stolen in January 2026), and Dublin Airport (1.5 million passenger records compromised in October 2025).

McDonald’s India has not yet confirmed the breach. The company operates in India through two business entities: Connaught Plaza Restaurants for North and East India, and Hardcastle Restaurants for West and South India, serving millions of customers since 1996.

This incident marks another cybersecurity challenge for the fast-food giant’s Indian operations, which previously experienced data security issues in 2017 and 2024.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…

23 minutes ago

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

35 minutes ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

37 minutes ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

40 minutes ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

1 hour ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

1 hour ago