Ransomware victim disclosure
← All victimsCCL Products (India) Limited
listed as CCL Products India · Claimed by Skira · listed 1 year ago
Status timeline
- ListedMar 6, 2025
- Data leakeddate unknown
At a glance
- Group
- Skira
- Status
- Data leaked
- Country
- India
- Sector
- Manufacturing
- Listed on leak site
- Mar 6, 2025
About the victim
AI dossier — public-source company profileCCL Products (India) Limited is a public limited company established in 1994 and headquartered in Guntur, Andhra Pradesh. The company is the world's largest exporter of instant coffee and a leading private label coffee manufacturer, operating in over 110 countries with diverse coffee product lines including freeze-dried, spray-dried, roast & ground, and premix coffees.
- Industry
- Coffee Manufacturing & Export
- Address
- Duggirala, Guntur 522330, Andhra Pradesh, India
- Founded
- 1994
Attack summary
Severity: low — The leak post provides only an announcement/listing with no proof files, screenshots, or data samples. No specific data types or operational impact are disclosed. The post appears to be AI-generated promotional content rather than substantive breach evidence.The ransomware group Skira claims to have conducted an attack on CCL Products India. The specific nature of the compromise (encryption, exfiltration, or both) and data types targeted are not detailed in the available leak post excerpt.
Original description
AI-summarised, not from the leak postCCL Products India is a leading manufacturer and exporter of instant coffee. It was established in 1994 and is headquartered in Hyderabad, India. The company has coffee processing units in multiple regions offering a wide range of coffee products including freeze-dried, spray-dried, and agglomerated coffees. CCL distributes its products globally in bulk packaging, as well as private labeled direct consumer packaging. They are widely respected for their sustainable and socially responsible business practices.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

