Threat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mapping

Qilin (Agenda) — leak-site claim, not confirmed by the victimhigh

Qilin claims Danone: what the source says, and what remains to be verified

The Qilin ransomware group listed Danone on its leak site, claiming it stole roughly 221 GB of data and publishing more than 90,000 files. The claim, dated 17 July 2026, is not currently confirmed by the company: as always with leak sites, the assertion should be treated as a claim until verified. The case is still a chance to look at Qilin's double-extortion model — one of 2026's most active groups — with what the sources actually say and the uncertainties in plain view.

A claim, not yet a confirmation

Let's start with the point usually skipped. What happened, verifiably, is that the Qilin group posted Danone on its leak site, claiming to have stolen roughly 221 GB of data and publishing more than 90,000 files as proof. The claim is dated 17 July 2026. Danone is the food group behind brands like Evian, Activia, Silk and International Delight, present in more than 120 countries.

What is not confirmed — and this belongs before everything else — is the company itself: there is no public confirmation from Danone about the incident, its scope, or the authenticity of the files. Ransomware leak sites are pressure tools: inflating numbers, mixing old data with new, or claiming a marginal foothold as a total compromise is part of the tactic. Until there is independent verification, "221 GB" and "90,000 files" are what the attacker says, not an established fact.

~221 GB
data claimed
per Qilin's leak site, unverified
90,000+
files published
as "proof" by the attacker
17 Jul 2026
date of the claim
posting on Qilin's site

Who Qilin is, according to the sources

Beyond this single case, Qilin — also known as Agenda — is documented by threat-intelligence sources as one of the most active ransomware groups of 2026, operating a ransomware-as-a-service model: the core develops and maintains the malware and infrastructure, while external affiliates run the intrusions for a cut of the ransom. Its stated tactic is double extortion: first data exfiltration, then system encryption, with the threat of publishing the stolen material on the Tor leak site if the ransom goes unpaid.

The Danone case, if confirmed as claimed, would fit this pattern: corporate data (per the source, financial reports, sales documents and confidentiality agreements from 2023–2025) used as leverage, with partial publication as a show of force and pressure to negotiate.

  1. 01
    Initial access
    often bought from brokers, not "found"
  2. 02
    Data exfiltration
    a copy of the material before any encryption
  3. 03
    Encryption + leak site
    double extortion: pay, or we publish

Why the food sector, and what changes for the reader

Groups like Qilin don't pick victims out of spite: they pick for likelihood of payment. A large organization with a time-sensitive supply chain and a public-facing brand has three good reasons to want to close fast — operational continuity, reputation, contractual pressure from partners. It is no accident that manufacturing and consumer goods are among the most-hit sectors in 2026 tracking.

For the reader, the useful lesson isn't the number of gigabytes claimed, but the path. Initial access, in most documented cases, doesn't come from a sophisticated exploit: it comes from bought credentials, an exposed remote access, a phishing hit that landed. That is where the chain breaks — with phishing-resistant authentication, segmentation that stops one foothold from becoming lateral movement, and verified, offline backups that strip extortion of half its leverage.

How to read this news

With caution, and without amplifying the attacker. The right thing today is to record that a claim exists, attribute it to Qilin, and wait for confirmation or denial from the party that matters — the company, or an independent analysis of the files. The relevant authorities for these situations (in Italy ACN and the Garante; at EU level Europol with the No More Ransom initiative and CISA with #StopRansomware) agree on one point worth repeating: paying guarantees nothing, neither deletion nor recovery, and it feeds the model. The news, for now, is that the model still works well enough to make a claim like this routine — and that, more than any single brand, is the fact.

More dossiers