PepsiCo, Inc.
ent_019e5e54f97263d1bda67921169bb257
Disclosures
7
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
949
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PepsiCo, Inc.
- Normalized
- pepsico— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- FJSUNZKFNQ5YPJ5OT455
- SEC EDGAR CIK
- 0000077476
- Domain
- None on record
Disclosure history (7)newest first
- Indiana State AGas victim2024-09-06
PepsiCo Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-15 and was reported on 2024-09-06. 2 Indiana residents were affected. 18 individuals affected in total.
- Indiana State AGas victim2022-10-07
PepsiCo, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-02-24 and was reported on 2022-10-07. 24 Indiana residents were affected. 949 individuals affected in total.
- Montana State AGas victim2022-10-07
Donlen Corporation (Sellerco), a fleet management provider for PepsiCo, notified Montana residents of a data breach occurring Feb 24–Mar 4, 2021. An unknown actor accessed Donlen's network. Donlen reset passwords, engaged forensic specialists, and offered 24 months of credit monitoring. The investigation could not confirm if specific individuals' data was accessed, but names and other data elements were accessible.
- New Hampshire State AGas reporting2022-10-07
PepsiCo notified NH AG of a breach at third-party vendor Donlen (now Sellerco). Unknown actor accessed Donlen's network Feb-Mar 2021. Donlen confirmed in Sept 2022 that PepsiCo employee names and driver's license numbers may have been accessed. 4 NH residents affected. Notifications sent Oct 7, 2022, including 24 months credit monitoring.
- Maine State AGas victim2022-10-06
PepsiCo, Inc. reported a data breach impacting 949 individuals, which occurred between February 24, 2021, and March 4, 2021. The breach was discovered on March 4, 2021, and was described as an external system breach or hacking incident. The compromised information included names and driver's license numbers. Affected individuals were notified on October 7, 2022, and were offered 24 months of credit monitoring and identity protection services.
- Massachusetts State AGas victim2022-10-06
PepsiCo, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-10-06. 31 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2022-01-01
PEPSI CO filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-443). The register records the breach as discovered on May 20, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of PepsiCo, Inc. — not by PepsiCo, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia PEPSI BOTTLING VENTURES LLC2023-06-28
Pepsi Bottling Ventures LLC reported a supplemental data security incident to New Hampshire. Unauthorized access occurred between Dec 23, 2022, and Jan 19, 2023, via malware. Personal information of 7 NH residents was compromised. PBV contained the incident, reset passwords, engaged Kroll for credit monitoring, and cooperated with law enforcement.
- Vermont State AGvia PEPSI BOTTLING VENTURES LLC2023-06-28
Pepsi Bottling Ventures LLC disclosed a cybersecurity incident where unauthorized parties accessed internal IT systems between Dec 23, 2022, and Jan 19, 2023. The attackers installed malware and exfiltrated personal data including names, addresses, SSNs, driver's licenses, financial account info, and health insurance details. The company reported the incident to law enforcement, suspended affected systems, reset passwords, and engaged Kroll to provide one year of free identity monitoring services to affected individuals.
- Maine State AGvia PEPSI BOTTLING VENTURES LLC2023-06-28
Pepsi Bottling Ventures LLC was the victim of an external system breach, described as hacking. The incident, which occurred between December 23, 2022, and January 19, 2023, was discovered on January 10, 2023. The breach resulted in the compromise of financial account numbers or credit/debit card numbers, along with their corresponding security codes, access codes, passwords, or PINs. The company notified the affected individuals and offered 12 months of identity theft protection services through Kroll.
- Maine State AGvia PEPSI BOTTLING VENTURES LLC2023-02-20
Pepsi Bottling Ventures LLC experienced an external system breach between December 23, 2022, and January 19, 2023. The incident, discovered on January 10, 2023, affected 17,612 individuals. Compromised information included names and financial account or credit/debit card numbers with their corresponding security codes, access codes, or PINs. The company began notifying affected individuals on February 10, 2023, and offered 12 months of credit monitoring services through Kroll.
- Montana State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC notified Montana residents of a security incident where an unknown party accessed internal IT systems, installed malware, and downloaded personal information including names, addresses, SSNs, driver's licenses, financial account info, and health data. The incident occurred around Dec 23, 2023, was discovered Jan 10, 2023, and last unauthorized access was Jan 19, 2023. Law enforcement was notified, systems were suspended, and Kroll identity monitoring was offered.
- Montana State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC notified Montana residents of a security incident where unauthorized parties accessed internal IT systems, installed malware, and downloaded personal information including names, addresses, SSNs, driver's licenses, financial account info, and health data. The incident occurred around Dec 23, 2022, and was discovered on Jan 10, 2023. The company suspended systems, engaged law enforcement, and provided one year of Kroll identity monitoring services.
- South Carolina State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC notified South Carolina residents of a cybersecurity incident where unauthorized parties accessed internal IT systems between December 23, 2022, and January 19, 2023. The attackers installed malware and downloaded personal information including names, addresses, SSNs, driver's licenses, financial account info, and PHI. The company contained the incident, reported to law enforcement, and provided one year of Kroll identity monitoring services.
- Delaware State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC disclosed a security incident where an unknown party accessed internal IT systems on or around December 23, 2022, installed malware, and downloaded information. The company discovered the activity on January 10, 2023, and contained the breach by January 19, 2023. Affected data included names, addresses, government IDs (SSN, driver's license), financial account info, and limited medical history. The company reported to law enforcement, suspended systems, reset passwords, and engaged Kroll for one year of identity monitoring.
- Massachusetts State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-02-10. 28 Massachusetts residents were affected. The report records the breach type as electronic.
- Vermont State AGvia PEPSI BOTTLING VENTURES LLC2023-02-10
Pepsi Bottling Ventures LLC notified consumers of a security incident where an unknown party accessed internal IT systems, installed malware, and downloaded personal information. The incident occurred between December 23, 2022, and January 19, 2023. Affected data included names, addresses, government IDs (SSN, driver's license), financial account info, and limited medical/employment data. Pepsi Bottling Ventures reported the incident to law enforcement, suspended systems, and engaged Kroll to provide one year of free identity monitoring services.