Qilin (Agenda) — leak-site claim, not confirmed by the victimhigh
Qilin claims Danone: what the source says, and what remains to be verified
The Qilin ransomware group listed Danone on its leak site, claiming it stole roughly 221 GB of data and publishing more than 90,000 files. The claim, dated 17 July 2026, is not currently confirmed by the company: as always with leak sites, the assertion should be treated as a claim until verified. The case is still a chance to look at Qilin's double-extortion model — one of 2026's most active groups — with what the sources actually say and the uncertainties in plain view.
A claim, not yet a confirmation
Let's start with the point usually skipped. What happened, verifiably, is that the Qilin group posted Danone on its leak site, claiming to have stolen roughly 221 GB of data and publishing more than 90,000 files as proof. The claim is dated 17 July 2026. Danone is the food group behind brands like Evian, Activia, Silk and International Delight, present in more than 120 countries.
What is not confirmed — and this belongs before everything else — is the company itself: there is no public confirmation from Danone about the incident, its scope, or the authenticity of the files. Ransomware leak sites are pressure tools: inflating numbers, mixing old data with new, or claiming a marginal foothold as a total compromise is part of the tactic. Until there is independent verification, "221 GB" and "90,000 files" are what the attacker says, not an established fact.
Who Qilin is, according to the sources
Beyond this single case, Qilin — also known as Agenda — is documented by threat-intelligence sources as one of the most active ransomware groups of 2026, operating a ransomware-as-a-service model: the core develops and maintains the malware and infrastructure, while external affiliates run the intrusions for a cut of the ransom. Its stated tactic is double extortion: first data exfiltration, then system encryption, with the threat of publishing the stolen material on the Tor leak site if the ransom goes unpaid.
The Danone case, if confirmed as claimed, would fit this pattern: corporate data (per the source, financial reports, sales documents and confidentiality agreements from 2023–2025) used as leverage, with partial publication as a show of force and pressure to negotiate.
- 01Initial accessoften bought from brokers, not "found"
- 02Data exfiltrationa copy of the material before any encryption
- 03Encryption + leak sitedouble extortion: pay, or we publish
Why the food sector, and what changes for the reader
Groups like Qilin don't pick victims out of spite: they pick for likelihood of payment. A large organization with a time-sensitive supply chain and a public-facing brand has three good reasons to want to close fast — operational continuity, reputation, contractual pressure from partners. It is no accident that manufacturing and consumer goods are among the most-hit sectors in 2026 tracking.
For the reader, the useful lesson isn't the number of gigabytes claimed, but the path. Initial access, in most documented cases, doesn't come from a sophisticated exploit: it comes from bought credentials, an exposed remote access, a phishing hit that landed. That is where the chain breaks — with phishing-resistant authentication, segmentation that stops one foothold from becoming lateral movement, and verified, offline backups that strip extortion of half its leverage.
How to read this news
With caution, and without amplifying the attacker. The right thing today is to record that a claim exists, attribute it to Qilin, and wait for confirmation or denial from the party that matters — the company, or an independent analysis of the files. The relevant authorities for these situations (in Italy ACN and the Garante; at EU level Europol with the No More Ransom initiative and CISA with #StopRansomware) agree on one point worth repeating: paying guarantees nothing, neither deletion nor recovery, and it feeds the model. The news, for now, is that the model still works well enough to make a claim like this routine — and that, more than any single brand, is the fact.