Data breach
Pepsi | Al Hayat
- Records
- 58,491
- Breach date
- 26 July 2026Estimated
- Added
- 5 September 2026
What was exposed
11 types of data · 3 put you at serious risk
- Names58,491
- Phone numbers42,483
- Email addresses17,263
- Street addresses8,204
- Dates of birth1,830
- Licence plates845
- Driving licence numbers228
- Social security numbers128
- Passport numbers98
- Vehicle VINs27
- Medical diagnoses9
About this breach
The ransomware group calling itself Global Secret Group has claimed responsibility for a cyberattack on Al Hayat, an Iraqi food and beverage company that produces and distributes Pepsi products. According to our investigation team, the incident involves roughly 47,600 rows of records, and the group listed the company on its leak site in late July 2026. The listing claims the attackers exfiltrated 138 GB of internal files, a total Ransomware.live puts at 205,992 files across 17,178 folders. As with any leak site entry, the claim reflects what the attackers assert, and it does not by itself confirm every detail of what was taken.
July 15, 2026: Ransomware.live lists this as the estimated date of the attack on Al Hayat.
July 26, 2026: Global Secret Group lists Al Hayat on its leak site, and the listing is indexed by Ransomware.live at 17:55 UTC.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: names for 47,622 individuals, phone numbers for 37,606, email addresses for 14,713, street addresses for 6,611, dates of birth for 1,830, vehicle license plates for 824, driver's license numbers for 166, passport numbers for 98, Social Security numbers for 65, and vehicle identification numbers for 27.
Not every individual is affected by every type of data listed here.
The full scope of the stolen files, which the attackers describe as internal company documents, has not been publicly cataloged beyond these indexed records.
What Are the Potential Risks for Affected Individuals?
The combination of names, phone numbers, email addresses, and home addresses is enough to support targeted phishing and phone-based scams. Attackers who know your name, employer or country, and contact details can craft messages that look far more convincing than generic spam.
Identity documents such as passport and driver's license numbers, even in small quantities, carry a higher risk because they are harder to replace than an email address and can support identity fraud. Dates of birth add to that risk when paired with the other records.
Because the attackers claim to hold large volumes of internal company files, anyone whose records appear in this dataset may also face ongoing exposure if the group publishes more material. Ransomware groups sometimes release data in stages.
What Should You Do If You Were Affected?
Be skeptical of unexpected calls, texts, or emails that reference Al Hayat, Pepsi, or any order, delivery, or payment details. Verify independently before responding or clicking links.
Use unique passwords for every account, and turn on two-factor authentication where it is offered, especially for email and banking.
Watch your financial accounts and credit activity for charges or applications you did not make. If you are outside Iraq and a US credit file applies to you, consider a fraud alert or credit freeze.
If you hold an Iraqi passport or driver's license and believe your number is in this dataset, contact the issuing authority about your options.
Keep records of any suspicious contact that references your personal details. Scammers connected to a breach often strike weeks or months after the initial news fades.
In the news
- Ransomware.live victim listing for Al Hayat | Pepsiransomware.live (opens in a new tab)
- Ransomware.live profile of Global Secret Groupransomware.live (opens in a new tab)
- Dexpose: Global Secret Group Strikes Al Hayat | Pepsi in Iraqdexpose.io (opens in a new tab)
- HookPhish: Ransomware Group Global Secret Group Hits Al Hayat | Pepsihookphish.com (opens in a new tab)
- GalaxyWarden: Al Hayat | Pepsi Listed by Global Secret Groupgalaxywarden.com
