Cyber Security News

Everest Ransomware Group Allegedly Claims to Have Breached McDonald’s India

The Everest ransomware group has claimed responsibility for a major cyberattack targeting McDonald’s India, allegedly exfiltrating 861 GB of sensitive data.

The threat actors posted details of the breach on their dark web leak site on January 20, 2026, threatening to publicly release the stolen information if the company fails to respond within a specified deadline.

According to the ransomware group’s claims, the breach compromised a massive volume of internal company documents and customer personal data.

The attackers stated that “personal data of your customers and internal documents were leaked into our storage,” including a “huge variety of personal documents and information of clients”.

The stolen data reportedly contains internal records that could pose significant risks for identity theft and targeted phishing campaigns across the region.

Everest is a Russian-speaking ransomware operation that emerged in December 2020, initially focusing on data exfiltration before evolving to full ransomware capabilities with dual AES/DES encryption by early 2021.

The group is well-known for “pure extortion” tactics, specializing in stealing and selling sensitive corporate data rather than just encrypting files. Recent high-profile victims include ASUS, Nissan Motor Corporation (900 GB stolen in January 2026), and Dublin Airport (1.5 million passenger records compromised in October 2025).

McDonald’s India has not yet confirmed the breach. The company operates in India through two business entities: Connaught Plaza Restaurants for North and East India, and Hardcastle Restaurants for West and South India, serving millions of customers since 1996.

This incident marks another cybersecurity challenge for the fast-food giant’s Indian operations, which previously experienced data security issues in 2017 and 2024.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago