Ransomware victim disclosure
← All victimsAl Hayat Pepsi
listed as Al Hayat | Pepsi · Claimed by Global Secret Group · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Global Secret Group
- Status
- Data leaked
- Country
- Iraq
- Sector
- Retail & E-Commerce
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileAl Hayat Pepsi is an Iraqi beverage distribution company based in Erbil that distributes PepsiCo brands including Pepsi, 7UP, Mirinda, Mountain Dew, Aquafina, and Rockstar. The company operates across manufacturing, distribution, and merchandising channels with approximately 500–1,000 employees and an estimated annual revenue of $100 million.
- Industry
- Food & Beverage Distribution
- Address
- Makhmoor Street, Koran, Erbil, Iraq 44001
- Employees
- 501-1,000
Attack summary
Severity: high — Confirmed exfiltration and public disclosure of a large dataset (138 GB) from a significant regional business with 500–1,000 employees. The data likely includes operational, financial, and employee records of commercial sensitivity.Global Secret Group claims to have exfiltrated 138 GB of company data comprising 205,992 files and 17,178 folders. The group has published the stolen data; no ransom demand is stated.
Data the group says was taken
AI dossier — extracted from the leak post- Business documents
- Financial records
- Employee information
- Customer data
- Distribution and merchandising records
- Operational files
What the group claims
Country: Iraq | Website: alhayatco.com | Revenue: $100 Million | Industry: Food & Beverage | Employees: 501-1,000 | Properties: 138 GB (205,992 Files, 17,178 Folders)
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

