Ransomware victim disclosure
← All victimsCascade Coffee
Claimed by Akira · listed 4 hours ago
Status timeline
- ListedAug 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Retail & E-Commerce
- Listed on leak site
- Aug 20, 2026
About the victim
AI dossier — public-source company profileCascade Coffee is a gourmet coffee contract manufacturer based near Seattle, Washington, specializing in roasting, grinding, flavoring, and packaging coffee for premium brands. The company produces whole bean, ground, flavored, and specialty blend coffees.
- Industry
- Coffee Manufacturing & Contract Roasting
- Address
- Seattle, Washington area
Attack summary
Severity: high — Confirmed exfiltration of PII at scale (employee passports, licenses, addresses, phones, vehicle data) combined with business-sensitive data (financials, contracts, NDAs). Personal identification documents represent regulated sensitive data.The akira group claims to have exfiltrated corporate data including detailed personal employee information (passports, driver's licenses, addresses, phone numbers, vehicle information), financial records, contracts, agreements, and NDAs. The group states they will upload this data.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal information (passports, driver's licenses)
- employee addresses and phone numbers
- employee vehicle information
- corporate financial records
- contracts and agreements
- NDAs
What the group claims
Cascade Coffee is a premier gourmet coffee contract manufacturer based near Seattle, Washington , specializing in roasting, grinding, flavoring, and packaging coffee. The company caters to so me of the world's finest coffee brands, providing a wide range of products including whole bean , ground, flavored coffees, and specialty blends. We will upload corporate data soon. Detailed personal employee information (passports, DLs, add resses, phones, car information), details, financials, contracts and agreements, NDAs and so on .
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

