Data breach
Koninklijke Ahold Delhaize N.V.
- Records
- 417,907
- Breach date
- 16 April 2025Estimated
- Added
- 15 May 2026
What was exposed
10 types of data · 3 put you at serious risk
- Phone numbers417,907
- Email addresses333,196
- Social security numbers98,471
- Names59,103
- Dates of birth27,624
- Street addresses26,055
- Bank account numbers1,324
- Licence plates1,295
- Driving licence numbers532
- Vehicle VINs280
About this breach
Data belonging to hundreds of thousands of people connected to Koninklijke Ahold Delhaize N.V., the Dutch parent company of grocery chains including Albert Heijn, has surfaced in connection with a cyberattack on the company's U.S. operations. Our investigation team estimates the breach covers 417,907 rows of data, with an estimated attack date of April 16, 2025. The listing has no claimed actor in our records, but independent reporting ties the underlying intrusion to the Inc Ransom ransomware group.
The incident traces back to November 2024, when Ahold Delhaize USA detected a cybersecurity issue in its U.S. network. The company later confirmed that files were taken from internal U.S. business systems. In April 2025, the company disclosed that some of those stolen files contained Dutch employment data, affecting staff of Ahold Delhaize Group, Ahold Delhaize Europe & Indonesia, Albert Heijn, Etos, Gall & Gall, and the Ahold Delhaize Coffee Company. The Dutch Data Protection Authority was notified.
November 5-6, 2024: An unauthorized third party accessed and obtained files from an internal Ahold Delhaize USA file repository, according to the company's breach notification filed with the Maine Attorney General.
Mid-April 2025: The Inc Ransom group claimed responsibility for the attack and published roughly 800 GB of allegedly stolen data on its leak site, out of a claimed 6 TB, according to SecurityWeek and Security.nl.
April 22, 2025: Ahold Delhaize announced that certain Dutch employment data was found in the affected files and said it had notified the Dutch Data Protection Authority, in a statement on its newsroom.
June 26, 2025: The company disclosed that more than 2.2 million people were affected in the U.S. portion of the breach and began mailing notifications, as reported by The Register.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers (98,471 records), birthdays (27,624), email addresses (333,196), phone numbers (417,907), names (59,103), street addresses (26,055), bank account details (1,324), driver's license numbers (532), vehicle license plates (1,295), and vehicle VINs (280).
Not every individual is affected by every type of data listed here.
The company's own notice states that people on the April 2021 payroll of its Dutch entities may be affected, though it did not say in that notice which specific fields were taken.
What Are the Potential Risks for Affected Individuals?
The combination of names, addresses, phone numbers, email addresses, and identification numbers is useful for identity fraud and targeted phishing. Criminals can use real employer names and employment details to build convincing scams. Bank account details, where present, raise the risk of fraudulent payment attempts. Social Security numbers are particularly sensitive for people with ties to the U.S. entities, since they can support fraudulent loan or tax filings. People whose data appears in this listing should also expect follow-up scam attempts that reference Ahold Delhaize or its brands, since attackers often reuse leaked details to seem legitimate.
What Is Koninklijke Ahold Delhaize N.V. Doing in Response?
The company says it began investigating with external cybersecurity experts as soon as it detected the issue in November 2024 and notified law enforcement. It reported the Dutch data to the Autoriteit Persoonsgegevens, the Dutch data protection authority, and said it would notify affected individuals according to its legal obligations. In the U.S., affected current and former staff were offered two years of free credit monitoring and identity protection services. The company has not confirmed the nature of the attack publicly, though reporting has widely linked it to ransomware.
What Should You Do If You Were Affected?
If you worked for Ahold Delhaize, Albert Heijn, Etos, Gall & Gall, the Ahold Delhaize Coffee Company, or any of the company's U.S. brands, take these steps:
Watch for official notification letters or emails and read them carefully.
Place a fraud alert or credit freeze with credit bureaus if you have U.S. credit history.
Review bank and payment statements for unfamiliar activity.
Be cautious with unexpected calls, texts, or emails referencing your employer or payroll, and never share codes or passwords in response.
Change passwords on accounts tied to your work email, and avoid reusing passwords across sites.
If you receive a credit monitoring offer from the company, enroll promptly.
In the news
- Ahold Delhaize newsroom statement on Dutch employment data, April 22, 2025newsroom.aholddelhaize.com (opens in a new tab)
- Ahold Delhaize cybersecurity issue pageaholddelhaize.com (opens in a new tab)
- The Register, June 27, 2025theregister.com (opens in a new tab)
- SecurityWeeksecurityweek.com (opens in a new tab)
- Security.nlsecurity.nl
