Skip to content

McDonalds Ecuador

vexy ransomware

Ransomware leak-site victim intelligence

Data size
42.08 GB
Posted
Sep 6, 2026
Country
Ecuador
Industry
fast-food restaurant operations (franchise)

Summary

Written by ThreatClusterfrom victim profile, leak post

Vexy ransomware group claims to have exfiltrated 42.08 GB of data from McDonalds Ecuador, the local franchise operation of McDonald's in Ecuador. They state the leak includes HR and recruitment records, internal documentation and source code. The leak post is published on 2026-09-03 and identifies McDonalds Ecuador as operating under Arcos Dorados with the domain mcdonalds.com.ec.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

McDonalds Ecuador is the local franchise operation of the global McDonalds brand. The company operates fast-food restaurants across Ecuador, offering products such as burgers, fries, beverages, breakfast items, and childrens meals. It operates under the McDonalds franchise model through Arcos Dorados, the largest McDonalds franchise operator in Latin America and the Caribbean.