30 million sensitive records leaked, numerous PepsiCo locations exposed
Companies in at least 8 countries are impacted by the data leak.

EDX Solutions leaked sensitive data. Image by Cybernews / Shutterstock by PaleStudio.
- EDX Solutions exposed 292GB of data in a publicly accessible MongoDB instance found by researchers.
- Researchers estimate at least 30 million sensitive records were exposed, with PepsiCo’s Latin America operations most affected.
- The leaked data included invoices, tax documents, employee accounts, plaintext credentials, API tokens, and supplier details.
- Attackers could use the data for fraud, account takeovers, and impersonation across supply chains.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
E-documents manager EDX Solutions has leaked hundreds of gigabytes of data, exposing tens of millions of records. Our researchers, who discovered the leak, found employee accounts, plaintext credentials, and tax data among the numerous leaked records.
No matter how secure your systems are, if your data is managed by a lax third party, your information can end up unsecured on the internet, accessible to anyone. EDX Solutions, a Mexican electronic document management service provider, is a perfect example of this.
In early July, our team discovered a publicly accessible MongoDB instance owned by EDX. Within the instance, researchers discovered 48 databases containing a whopping 292GB of EDX and the company’s client data.
We estimate that at least 30 million sensitive records were exposed, with several PepsiCo locations across Latin America bearing the brunt of the data leak. PepsiCo is an American food and beverage behemoth, best recognizable by Pepsi, Lay’s, Doritos, Cheetos, and other brands.
Several other companies had their data exposed, albeit in far less volume.
Our researchers reached out to EDX Solutions, receiving an initial reply after which the company stopped responding. We have also contacted Mexico's CERT.
We have reached out to EDX Solutions for comment and will update this article once we receive a reply. We have also reached out to PepsiCo.
“This leak should act as a cautionary tale for all the companies that provide B2B services, no matter the industry, because if they’re the weak link in the supply chain, the potential damage extends beyond the company in question but also to their clientele,” our researchers explained.
The EDX Solutions data leak: Who was exposed?
Three-quarters of the exposed data, 218GB, was discovered in a single database. According to our team, the data belongs to PepsiCo’s branch in Colombia. Information in the database revealed numerous sensitive details.
For example, a collection in the Colombia-api database contained over 11 million records, including invoice transactions with full invoice documents, their identifiers, and timestamps. Additionally, our team discovered one record with plaintext credentials to an internal application programming interface (API) and several configuration records.
While Colombia was the nation with the most exposed details, over 221GB in total, several other Latin American countries also suffered from the EDX data leak.
Peru appears to be the second-most exposed nation, with over 42GB of data attributed to entities operating there. According to the team, the exposed Peru data is mostly tied to PepsiCo Peru and Peru’s division of the Swiss building materials company Holcim.
The records included invoice and document data, supplier and subsidiary information, emails, employee account details, and authentication-related data.
With nearly 18GB of data exposed, the Dominican Republic also appears to have been heavily affected. Leaked data can be linked to PepsiCo’s local operations and to another company in the wholesale distribution sector. The leaked records included e-invoices, company details, internal files, tax-related validation data, and sensitive credentials.
El Salvador (7GB) appears to have been among the more heavily affected countries as well, with exposed data tied to PepsiCo’s operations there. The records included invoice-related data, company and supplier information, emails, employee account details, and access credentials.
Costa Rica (2GB) appears to have been affected primarily through data tied to CSU supermarkets, with a smaller amount of exposed portal data also linked to PepsiCo’s local branch. The leaked records included invoice-related information, internal files, and some employee and company account details.
Ecuador (41MB) appears to have been affected the least, with exposed data tied to PepsiCo’s local operations. The leaked records included emails, supplier and company information, and employee account details.
Some of the exposed databases contained information about EDX employees working with country-specific companies.
Why is the EDX Solutions data leak so dangerous?
The leaked information is a treasure trove of opportunities for cybercriminals. There’s enough data to devise attacks involving financial fraud, employee account takeovers, and social engineering.
Because the exposed records include invoice files, tax-related documents, digital certificates, API credentials, tokens, and supplier contact data, cybercrooks could potentially impersonate trusted businesses, tamper with invoicing workflows, or submit fraudulent documents that appear legitimate.
Moreover, it creates a direct path to financial fraud, including fake payment requests, supplier payment diversion, and invoice manipulation.
Less obvious risks include using leaked tax IDs, validation results, certificate details, and internal workflow records to study how a company’s billing and compliance processes work, making scams more convincing and harder to detect.
Meanwhile, access to employee account data, recovery codes, and internal endpoints could also help attackers move beyond simple email fraud to attempt account takeovers, business process abuse, or long-term supply chain impersonation across multiple countries.
Disclosure timeline:
- Leak discovered: July 2nd, 2026
- Initial disclosure: July 7th, 2026
- Mexico’s CERT contacted: August 8th, 2026
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.