A Danone ransomware attack may have exposed financial reports, customer information, and thousands of internal company files.
The Qilin ransomware group claims it stole 221GB of data from the global food and beverage company. Danone owns major brands such as Evian, Activia, Silk, International Delight, Volvic, AQUA, and Actimel.
However, Danone had not publicly confirmed the breach when the claim emerged. Therefore, the full scale and impact of the alleged attack remain unclear.
Qilin Claims Responsibility for the Attack
Qilin added Danone to its dark web leak site earlier this week. The cybercriminal group claimed it had accessed the company’s internal servers and stolen 91,558 files.
The hackers also published a small collection of documents as evidence. These samples reportedly date from 2023 to 2025.
The documents appear to include annual and quarterly financial summaries. In addition, the sample contains customer account information, customer complaint reports, sales records, and confidentiality agreements.
Qilin did not provide a detailed breakdown of the entire stolen archive. As a result, it remains unknown how much personal or commercially sensitive information the files contain.
Customer and Financial Records May Be Exposed
The alleged Danone ransomware attack could affect several categories of company data.
Customer databases may contain contact details, account records, or other identifying information. Meanwhile, sales reports could reveal commercial relationships, revenue figures, and internal business strategies.
Non-disclosure agreements may also contain names, signatures, and confidential details about Danone’s partners or projects.
However, the available evidence represents only a small part of the claimed 221GB archive. It does not prove that every listed data category appears throughout the full collection.
There is also no confirmation that the attack disrupted production or affected Danone products. Moreover, Qilin has not disclosed whether it encrypted the company’s systems.
Danone Operates Across More Than 120 Countries
Danone is one of the world’s largest food and beverage producers. The company was founded in 1919 and has its headquarters in Paris.
Its products are available in more than 120 countries. Furthermore, Danone operates over 180 production sites across 55 countries and employs more than 90,000 people.
The company also has a significant presence in the United States. Its American operations include 13 manufacturing sites, a research and development center, and two headquarters.
Danone reported group sales of €27.3 billion in 2025. Consequently, a data breach involving its internal systems could affect a large international network of employees, customers, suppliers, and commercial partners.
Qilin Remains a Major Ransomware Threat
Security researchers first identified Qilin in 2022. Since then, the Russian-linked ransomware operation has become one of the most active cybercrime groups in the world.
Qilin usually targets organizations in manufacturing, healthcare, finance, retail, transportation, and government. The group follows a double-extortion model in many of its attacks.
First, the hackers steal sensitive files from a victim’s network. They may also encrypt systems to disrupt normal operations. Finally, the group threatens to publish the stolen information unless the victim pays a ransom.
Qilin reportedly listed more than 1,000 victims during 2025. By mid-July 2026, it had claimed over 700 additional attacks.
Its recent targets have included companies in food distribution, commercial property, transportation, healthcare, and other major industries.
Investigation Into the Claim Continues
Danone had not issued a detailed public statement about the incident at the time of reporting. Therefore, it is not yet clear when the attackers gained access or which systems they may have compromised.
The company has also not confirmed whether customer or employee information appears in the stolen files.
Until Danone releases further details, Qilin’s statements should remain treated as unverified claims. Nevertheless, the alleged Danone ransomware attack highlights the growing threat facing large manufacturers with complex global networks.


0 responses to “Danone Ransomware Attack Exposes 221GB of Data”