Ransomware victim disclosure
← All victimsTapon Corona S.A. de C.V.
listed as Tapon Corona · Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Mexico
- Sector
- Manufacturing
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileTapon Corona S.A. de C.V. is a Mexican manufacturer based in Azcapotzalco, Mexico City, specializing in world-class crown caps (metal bottle caps) for beer and soft drink brands. The company is part of Grupo Zapata and operates alongside subsidiaries that produce aluminum cans (Jalisco) and PET packaging (CDMX). It serves major beverage brands in the Mexican and potentially international market.
- Industry
- Metal Bottle Cap & Beverage Packaging Manufacturing
- Address
- Azcapotzalco, Mexico City, Mexico
Attack summary
Severity: high — Data has been confirmed as published by the threat actor, indicating successful exfiltration of business data from a manufacturing company; while no specific regulated/PII data at scale is confirmed, the disclosed status of 'data_published' elevates this beyond medium.The group 'thegentlemen' claims to have compromised Tapon Corona S.A. de C.V. and has published data ('data_published' status), indicating exfiltration of company data. No specific ransom demand or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal data
What the group claims
taponcorona.com.mx Tapon Corona S.A. de C.V. is a Mexican manufacturer based in Azcapotzalco, Mexico City, specializing in world-class crown caps (metal bottle caps) for beer and soft drink brands. The company is part of Grupo Zapata and operates alongside subsidiaries producing aluminum cans (Jalisco) and PET packaging (CDMX).
Sources
- Victim sitetaponcorona.com.mx
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

