Cascade Coffee Data Breach Exposes Employee Passports and Driver’s License Numbers

Published: 20 August 2026
Manufacturing data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

The Akira ransomware group claims to have stolen detailed employee records from Cascade Coffee, a Washington-based coffee manufacturer, including passports, driver’s licenses, addresses, vehicle information, and financial documents. The number of affected individuals has not been publicly disclosed. Anyone connected to Cascade Coffee should monitor credit reports and consider a credit freeze immediately.

CompanyCascade Coffee
IndustryManufacturing
Data Types ExposedPassport Information, Driver’s License Numbers, Home Addresses, Phone Numbers, Vehicle Information, Financial Records, Contracts and Business Agreements, Non-Disclosure Agreements
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Cascade Coffee Data Breach?

Cascade Coffee, a gourmet coffee contract manufacturer based near Seattle, Washington, has confirmed a cybersecurity incident tied to the Akira ransomware group. The Cascade Coffee data breach involves claims that attackers accessed and copied sensitive company and employee files before threatening to release them publicly.

According to the threat actor’s own postings, the group behind the attack calls itself Akira. Akira is a known ransomware operation that typically infiltrates corporate networks, extracts data, and then pressures victims to pay by threatening to leak stolen files. As a result, this incident follows a pattern seen across many other ransomware cases in recent years.

The exact breach discovery date has not been publicly disclosed. However, the notification connected to this incident became public in August 2026. Because forensic investigations into ransomware attacks often take weeks or months, the timeline between initial intrusion and public disclosure frequently stretches longer than victims initially expect.

Cascade Coffee has not released full details about how the attackers first gained access to its systems. In addition, the company has not confirmed whether it engaged outside cybersecurity investigators. Nevertheless, incidents involving groups like Akira typically prompt a forensic review to determine the scope of the intrusion and the specific files accessed.

Who was affected?

The Cascade Coffee data breach appears to primarily affect current and former employees of the company. The threat actor specifically referenced detailed personal employee information, which suggests that workers, rather than retail customers, form the core group of people impacted.

At this time, the exact number of affected individuals has not been publicly disclosed. Therefore, anyone who has worked for Cascade Coffee, or who has an ongoing business relationship with the company, should consider themselves potentially affected until official notifications clarify the scope further.

Because Cascade Coffee supplies products to well-known coffee brands, business partners and contract counterparties could also face indirect exposure. This is especially true if contracts, agreements, or non-disclosure agreements shared with partner companies were among the files accessed.

It also remains unclear whether the affected population includes individuals located outside the United States. Still, given the company’s Washington state base, the breach carries a clear U.S. connection that affects American workers and their families.

What Information Was Potentially Exposed?

The threat actor claims to have obtained a wide range of sensitive personal and corporate records. This mix of personal identifiers and business documents raises serious concerns for anyone whose information was included.

  • Passport information
  • Driver’s license numbers
  • Home addresses
  • Phone numbers
  • Vehicle information
  • Financial records
  • Contracts and business agreements
  • Non-disclosure agreements (NDAs)

Exposure of passports and driver’s license numbers is particularly concerning because these documents serve as primary identity verification for banks, government agencies, and other institutions. Consequently, criminals could use this data to open new accounts, apply for loans, or impersonate victims in other official transactions.

Additionally, the combination of home addresses, phone numbers, and vehicle details creates opportunities for targeted phishing attempts and even physical safety risks. When financial records are layered on top of these identifiers, affected individuals face an elevated risk of both identity theft and direct financial fraud.

What is the company doing?

Cascade Coffee has not publicly detailed every step of its response. However, the presence of a ransomware claim from Akira strongly suggests the company is working through an active incident response process, which typically includes containment, investigation, and notification steps.

Organizations facing similar Akira-linked incidents generally isolate affected systems, reset credentials, and bring in specialized cybersecurity firms to assess the damage. In response to threats like this, companies also typically prepare notification letters for affected individuals as required by state breach notification laws.

Going forward, affected individuals should watch for official written notification from Cascade Coffee. This notice would typically outline the specific data involved, any protective services offered, and instructions for enrolling in monitoring programs if such services are made available.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to Cascade Coffee should begin checking their credit reports regularly. Because financial records were reportedly among the stolen files, unauthorized account activity is a genuine risk.

You can request free credit reports from each of the three major credit bureaus. Reviewing these reports carefully allows you to catch unfamiliar accounts or inquiries early, which makes resolving fraud far easier.

Consider a Fraud Alert or Credit Freeze

Given that driver’s license numbers, passport details, and financial information may have been exposed, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name.

A credit freeze goes even further by restricting access to your credit file entirely. Although a freeze requires a bit more effort to lift when you need credit, it offers stronger protection against identity thieves attempting to open new accounts.

Stay Alert for Phishing Attempts

Because contact information such as phone numbers and addresses may have been exposed, affected individuals should watch for suspicious calls, texts, or emails. Scammers often use stolen personal details to make phishing attempts appear more convincing.

For example, a scammer might reference your real address or vehicle information to build false trust. As a result, always verify unexpected requests for personal information by contacting the organization directly through a known phone number or website.

Safeguard Your Identity Documents

If your passport or driver’s license number was exposed, contact the relevant issuing agency to ask about replacement or additional verification steps. This is especially important because these documents are difficult to change and widely used for identity verification.

In the meantime, keep a close eye on any correspondence referencing your identity documents. Reporting suspicious activity quickly can limit the damage and help authorities track fraudulent use of your information.

Keep Records and Consider Legal Options

Affected individuals should save any notification letters, correspondence, or evidence related to this breach. This documentation can prove valuable if fraud occurs later or if you decide to pursue legal action.

Because this breach involves highly sensitive documents like passports and driver’s licenses, consulting a data breach attorney may help you understand your rights. Many attorneys offer free case evaluations to help affected individuals determine whether they qualify for compensation.



Related Data Breaches

See the latest data breaches we're tracking →