Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog

Coca-Cola: Two Ransomware Claims, Three Years Apart

AUGUST 23, 20265 MIN READ
Marshall BennettMarshall Bennett
Chat with a real personno Slack required
Coca-Cola: Two Ransomware Claims, Three Years Apart

Key takeaways

  • In April 2022, Stormous claimed on Telegram it had breached Coca-Cola on April 24 and stolen 161 GB of data, then offered the files for about 1.65 bitcoin, roughly $64,000 at the time.
  • Researchers could not verify Stormous’s screenshots as coming from Coca-Cola’s network, and analysts noted the unusually low $64,000 demand plus Stormous’s history of exaggerated claims and possible “scavenger operations,” where groups take credit for someone else’s stolen data.
  • On May 22, 2025, Everest listed Coca-Cola on its leak site, gave the company five days to pay, and claimed to hold personal records on 959 employees in Coca-Cola’s UAE, Oman, and Bahrain operations.
  • After the deadline expired, Everest published the data on May 27, 2025; Cybernews reviewed the leak directly and confirmed 1,104 documents containing passport scans, visa copies, government ID numbers, names, birth dates, nationalities, home addresses, and job titles.
  • The article cites Dr. Max Smeets of Stanford’s Center for International Security and Cooperation and co-author Janina Inauen, who wrote that ransomware groups “may fake listings, post old data, or post other groups’ victims” to inflate their reputation.
  • Everest’s history mattered because the group has been active since December 2020 and is known for recruiting insiders by offering cash or a share of the ransom in exchange for VPN access or IT credentials.

How an unverified 2022 extortion attempt and a confirmed 2025 data leak reveal two different faces of the same threat.

An Adaptive Security series on the ransomware attacks that shaped modern cyber defense. Hub: A History of Notable Ransomware Attacks. Previously: GandCrab.

In late April 2022, a group calling itself Stormous announced on Telegram that it had broken into Coca-Cola's servers on April 24 and stolen 161 gigabytes of data. Three years later, on May 22, 2025, a different group named Everest listed Coca-Cola on its own leak site and gave the company five days to pay. Both claims targeted the same company. Only one of them held up under scrutiny.

A Claim Built for a Poll

Stormous introduced itself to the public in early 2022 as a pro-Russian hacking group. In March, weeks before it approached Coca-Cola, the group posted on Telegram that it would work against any cyberattack on Russian infrastructure, planting its flag on one side of the war in Ukraine. Choosing its next target became a crowdsourcing activity. Stormous ran a Telegram poll asking followers to vote on who to hit next, and Coca-Cola appears to have won.

The group claimed it had exfiltrated 161 gigabytes of financial records, credentials, and other sensitive files, and it listed the data for sale for roughly 1.65 bitcoin, about 64,000 dollars at the time. Coca-Cola’s response gave nothing away. “We are aware of this matter and are investigating to determine the validity of the claim,” a spokesperson said, adding that the company was coordinating with law enforcement.

Security researchers who looked at the screenshots Stormous posted could not independently verify they came from Coca-Cola’s network. A ransom of 64,000 dollars was also unusually small for a company Coca-Cola’s size, the kind of number that fits a bluff better than a serious extortion attempt. Analysts flagged two reasons for doubt: a pattern known as scavenger operations, in which a group claims credit for data stolen by someone else, and Stormous’s own track record of exaggerated or invented claims. No independently verified leak of that data ever followed. Coca-Cola never issued a follow-up confirming or denying that anything had happened.

A Claim That Held Up

Everest is a different kind of operation than Stormous. The group has been active since December 2020, and researchers have linked it to a run of high-profile claimed breaches, including NASA, the Brazilian government, and the aerospace supplier Collins Aerospace, whose 2025 incident disrupted check-in systems at several European airports. Not every one of those claims has been independently confirmed, but the pattern itself is a track record Stormous never built. When Everest listed Coca-Cola on its dark web leak site on May 22, 2025, it claimed to have stolen personal records on 959 employees across the company's Middle East operations in the UAE, Oman, and Bahrain, and set a five-day countdown for the company to negotiate. Security teams had reason to take the threat seriously before a single file leaked.

The countdown ran out with no public response from Coca-Cola. Everest published the dataset on May 27, and this time researchers did not have to take the claim on faith. Cybernews examined the leaked files directly and confirmed the count: 1,104 documents, including passport scans, visa copies, government identification numbers, full names, birth dates, nationalities, home addresses, and job titles, the kind of personal records that follow an employee well past the news cycle of any single breach.

Coca-Cola did not confirm the breach publicly, the same posture it took in 2022. The difference was that this time, independent researchers could examine the underlying documents themselves, and they checked out.

Why the Difference Matters

Why does one claim collapse under scrutiny while another holds up? Dr. Max Smeets, a researcher at Stanford University’s Center for International Security and Cooperation who studies ransomware extortion tactics, has pointed to how leak sites are built to blur that line on purpose. Ransomware groups, he and co-author Janina Inauen have written, “may fake listings, post old data, or post other groups’ victims,” a tactic built to make a group look more capable than it is, regardless of what happened underneath the claim. Stormous’s Telegram poll and political branding fit that pattern well: a claim built for attention first, verification second.

The two Coca-Cola incidents point to the same practical problem from opposite directions. A company cannot tell which kind of claim it is facing on day one, and the ransom clock does not wait for that answer. Closing that gap starts with understanding what a specific group does, and Everest’s own history offers one clear example. The group is known for a tactic aimed at people instead of firewalls: recruiting employees directly, offering cash or a cut of the ransom to anyone willing to hand over VPN access or IT credentials. Adaptive Security studies this history because the newest version of that pitch arrives as a message to an employee, asking them to become the way in.

Next in this series: Fairlife, the Coca-Cola-owned brand whose own ransomware incident left no doubt about what happened.

Get started with Adaptive Security

Get started

Human security for the AI era.