Data breach
Sysco
- Records
- 1,709,807
- Breach date
- 5 May 2026Estimated
- Added
- 5 June 2026
What was exposed
4 types of data
- Street addresses1,709,807
- Names1,026,594
- Phone numbers956,783
- Email addresses481
About this breach
Qilin, a ransomware group, has listed Sysco, the world's largest food distributor, on its dark web leak site, and the investigation team has indexed a dataset connected to the claim containing roughly 1.7 million rows of records. The group posted samples of alleged internal Sysco documents as proof of access and set a deadline of May 12, 2026, for ransom negotiations. According to our investigation team, the indexed data includes more than one million names and roughly 956,000 phone numbers. Sysco, a Houston-based company that supplies restaurants, hospitals, schools, hotels, and airlines, had not publicly confirmed a breach when the claim was first reported.
Breach Timeline
May 5, 2026: Qilin listed Sysco on its dark web leak blog. Researchers at Cybernews observed a countdown clock of roughly six days, pointing to a May 12 deadline.
May 2026: Qilin published three sample documents as proof of access: a formula-based customer pricing list dated 2021 to 2022 and marked confidential, a February 2026 invoice billed to a restaurant in St. Paul, Minnesota, and a June 2025 Certificate of Resale tax document.
By the May 12 deadline: Qilin followed through on its threat to publish the stolen cache, according to Cybernews.
June 2026: Weeks after the Qilin claim, the group ShinyHunters posted its own extortion claim against Sysco, alleging it had stolen more than 61 million Salesforce records containing customer and employee data. No proof samples accompanied that post.
What Information Was Compromised?
Our analysis found the following data types in this breach: 1,709,807 street addresses, 1,026,594 names, 956,783 phone numbers, and 481 email addresses, drawn from a dataset of 1,709,807 rows indexed by our investigation team.
The samples Qilin posted with its leak site entry, which Cybernews reporters reviewed, included customer pricing documents, invoices, and tax records. The group did not state how much data it claimed to have taken.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, home addresses, and phone numbers is the raw material for targeted phishing and impersonation scams. Someone holding this data can pose as a Sysco vendor, a delivery service, or a billing department and sound convincing because they know your name and address.
Business customers face an added risk. If invoices, pricing terms, or tax documents tied to their accounts are in circulation, scammers can reference real transactions to pressure accounts payable staff into fraudulent payments. There is no evidence in the indexed data that passwords or payment card numbers were exposed, but the email count in the dataset is low, so most affected people should not expect a direct breach notification email tied to this listing.
What Is Sysco Doing in Response?
Sysco had not publicly confirmed a breach or disclosed any operational impact when the Qilin claim was first reported, according to BlackFog's May 2026 ransomware report. The company faces two separate extortion claims, from Qilin and ShinyHunters, and has not verified either.
What Should You Do If You Were Affected?
Be skeptical of unsolicited calls, texts, or emails that reference Sysco, a food order, an invoice, or a delivery, especially if the sender knows your name or address. Do not pay or share account details before verifying the request through a number you look up yourself.
If you run a business that orders from Sysco, brief your accounts payable team about invoice fraud and confirm any change to payment details by phone using a known contact.
Monitor your financial statements and consider a credit monitoring service if your address and phone number were exposed.
In the news
- Ransomware.live victim entry for Syscoransomware.live (opens in a new tab)
- Cybernews: Sysco targeted by Qilin ransomware gangcybernews.com (opens in a new tab)
- Cybernews: ShinyHunters claims 61M Sysco recordscybernews.com (opens in a new tab)
- BlackFog: The State of Ransomware, May 2026blackfog.com (opens in a new tab)
