Ransomware victim disclosure
← All victimsThe Coca-Cola Company
listed as FRESCA · Claimed by Snatch · listed 3 years ago
Status timeline
- ListedMay 22, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Food & Agriculture
- Listed on leak site
- May 22, 2023
About the victim
AI dossier — public-source company profileThe Coca-Cola Company is a multinational beverage corporation headquartered in Atlanta, Georgia, with over 139 years of history and more than 200 brands sold worldwide, including Coca-Cola, Sprite, Fanta, Dasani, and Fresca. The company operates globally across sparkling beverages, hydration, coffee, tea, juices, and dairy categories. It is one of the largest beverage companies in the world by revenue and market capitalization.
- Industry
- Beverages & Non-Alcoholic Drinks
- Address
- One Coca-Cola Plaza, Atlanta, Georgia 30313, United States
- Employees
- 70000
- Founded
- 1886
Attack summary
Severity: medium — Data is listed as published but the leak post provides no evidence of specific exfiltrated files, data types, or volume; the target appears to be a brand/product of a major corporation rather than a confirmed full-company breach, and no regulated data types are confirmed.The Snatch ransomware group claims to have attacked Fresca, a Coca-Cola brand, with disclosed status indicating data has been published; however, the leak post contains only a brief product description of Fresca with no explicit detail on encrypted or exfiltrated data volumes or specific data types.
What the group claims
Fresca is a grapefruit-flavored citrus soft drink created by The Coca-Cola Company.Borrowing the word Fresca (meaning "fresh") from Italian, Spanish and Portuguese, it was introduced in the United States in 1966. Originally a bottled sugar-free diet soda, sugar sweetened versions were introduced in some markets.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

