Ransomware victim disclosure
← All victimsEquatorial Coca-Cola Bottling
Claimed by worldleaks · listed 29 days ago
Status timeline
- Listed
Apr 22, 2026
- Data leaked
At a glance
- Group
- worldleaks
- Status
- Data leaked
- Country
- ES
- Listed on leak site
- Apr 22, 2026
About the victim
AI dossier — public-source company profileEquatorial Coca-Cola Bottling Company (ECCBC) is a licensed bottling partner of The Coca-Cola Company operating across 13 countries in North and West Africa. The company produces, commercializes, and distributes Coca-Cola's beverage portfolio, achieving over 2 billion transactions per year through more than 250,000 points of sale. ECCBC employs more than 5,000 people and has been active since 1989.
- Industry
- Non-Alcoholic Beverage Bottling & Distribution
- Employees
- 5000+
- Founded
- 1989
Attack summary
Severity: high — Data has been confirmed as published by the threat actor, indicating successful exfiltration from a large multinational company with over 5,000 employees and operations across 13 African countries. The scale of the organisation and confirmed data publication elevate this beyond medium severity, though the absence of detail on data type (e.g. PII, financial, medical) and volume prevents a critical classification.The worldleaks group has published data allegedly belonging to ECCBC, indicating exfiltration of company data with the disclosure status listed as data_published. No specific ransom demand or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal data
Original description
AI-summarised, not from the leak postEquatorial Coca-Cola Bottling Company is a beverage manufacturer and distributor operating primarily in West and Central Africa, including countries such as Cameroon and Equatorial Guinea. It produces and distributes Coca-Cola branded soft drinks and related beverages under license from The Coca-Cola Company. The company operates within the non-alcoholic beverage industry, managing bottling plants and regional distribution networks across its operating territories.
Sources
Source
Indexed 29 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
