Pepsi Bottling Ventures breach hit more than 28,000 employees and contractors
- Organization
- Pepsi Bottling Ventures LLC
- Exploit
- Hacking
- Industry
- Food and Beverage
Pepsi Bottling Ventures, a large independent bottler of Pepsi-Cola products in the United States, was breached over roughly four weeks around the turn of 2023. An intruder reached the company's internal IT systems on December 23, 2022, installed information stealing malware and downloaded data. The activity was discovered on January 10, 2023, and the last unauthorized access was recorded on January 19.
The company began notifying individuals on February 10, 2023 and published a further notice of security incident on July 1. Reporting in July put the number of people affected at more than 28,000. Those affected were current and former employees and contractors rather than customers.
The exposed information was wide ranging. It included names, home addresses, email addresses, financial account details together with passwords, PINs and other access numbers, government identification and driver's license numbers, Social Security numbers, passport data, digital signatures, and employment and benefits records containing limited medical history and health insurance claim information.
Pepsi Bottling Ventures said it strengthened network security, forced a company-wide password reset, suspended the affected systems and notified law enforcement. It told those affected to change their usernames, passwords and security question answers, and arranged at least a year of identity monitoring through Kroll, including credit monitoring, up to $1 million in fraud reimbursement and identity restoration support. The company said it had no awareness of the compromised information being misused.