The Qilin ransomware group listed Danone on its leak site and claimed it had taken 221 gigabytes comprising 91,558 files, BreachNews reported, which is evidence of a public adversary claim rather than confirmation that Qilin entered Danone's network or removed authentic files. [1]
BreachNews said Qilin displayed a small set of purported samples and described financial, customer, sales and contractual material, while also saying the claim had not been independently verified and Danone had issued no public statement at publication; corporate silence proves neither a hidden breach nor a false accusation. [1]
The missing stages matter because a leak-site listing comes before sample authentication, forensic confirmation of access, verified exfiltration, evidence of encryption, operational disruption and notification of affected people, and the recovered record established none of those later events or identified an access method, affected Danone entity or country, regulator filing, plant interruption or confirmed customer population.
Treating the quoted volume as a completed incident would let the extortionist define both the fact and scale of the story, while treating Danone's silence as exoneration would be equally careless; the defensible record is narrower, as Qilin made a precise allegation, a specialist outlet reported it with explicit caveats, and independent evidence remained absent.
The next report should begin with authenticated samples, a Danone or regulator notice, or a forensic account, and until one appears 221 gigabytes is the size of Qilin's claim rather than the measure of a confirmed Danone breach.
-- HENDRIK VAN DER BERG, Brussels