Everest Ransomware Group Allegedly Claims Breach of McDonald’s India Systems

The Everest ransomware group has claimed responsibility for a significant cyberattack targeting McDonald’s India operations, allegedly exfiltrating 861 gigabytes of sensitive corporate and customer data.

The threat actors published breach details on their dark web leak site on January 20, 2026, demanding a ransom payment within a specified deadline before threatening to release public data.

According to the group’s claims posted on its leak portal, the compromised data includes customer personal information and internal company documents.

The attackers stated that “personal data of your customers and internal documents were leaked into our storage,” describing the stolen assets as a “huge variety of personal documents and information of clients.”

Data Compromise Assessment

Security analysts assess the breach as particularly severe given the nature of the exfiltrated information.

The stolen dataset reportedly contains internal records that could facilitate identity theft and enable targeted phishing campaigns against customers and employees across the Indian subcontinent.

Such breaches typically expose sensitive information, including names, contact details, transaction histories, and internal business documentation.

The volume of compromised data, 861 GB, represents one of the largest disclosed incidents targeting McDonald’s franchise operations globally, underscoring the scale of the security incident.

Everest emerged as a Russian-speaking cybercriminal operation in December 2020, initially specializing in data exfiltration before incorporating full ransomware encryption capabilities by early 2021. The group employs dual AES/DES encryption for file encryption.

The threat actor is widely recognized for “pure extortion” tactics, prioritizing data theft and extortion over traditional file encryption.

Rather than simply locking systems, Everest focuses on stealing valuable data, threatening public release to maximize pressure on victims.

Recent high-profile victims include ASUS, Nissan Motor Corporation (900 GB stolen in January 2026), and Dublin Airport (1.5 million passenger records compromised in October 2025).

This track record demonstrates the group’s consistent targeting of large organizations across multiple sectors.

McDonald’s operates in India through two distinct business entities: Connaught Plaza Restaurants Private Limited, which manages locations in North and East India, and Hardcastle Restaurants Private Limited, which oversees West and South India operations.

The company has served Indian customers since entering the market in 1996.

McDonald’s India has not yet publicly confirmed or commented on the alleged breach as of January 21, 2026.

This incident represents another cybersecurity challenge for McDonald’s India franchise operations.

The company experienced data security incidents in 2017 and 2024, indicating a pattern of security vulnerabilities within its infrastructure.

Organizations should implement robust incident response procedures and monitor threat intelligence feeds for updates regarding this incident.

Customers of McDonald’s India should monitor their accounts for suspicious activity and implement identity theft protection measures.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories