Data breach
Sysco Corporation
- Records
- 4,540,682
- Breach date
- 15 June 2026Estimated
- Added
- 23 June 2026
What was exposed
8 types of data · 3 more reported · 1 puts you at serious risk
- Names4,540,682
- Email addresses2,699,773
- Phone numbers2,284,350
- Street addresses2,267,032
- Vehicle VINs15,454
- Licence plates9,522
- Driving licence numbers4,668
- Dates of birth3,242
- Social security numbersReported, not counted
- Government IDsReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Sysco Corporation, the Houston-based food distribution giant, was hit by a "pay or leak" extortion campaign from the hacking group ShinyHunters in June 2026. According to reporting by Cybernews, the group posted Sysco on its leak site on the Tor network on June 14, 2026, claiming it had compromised more than 61 million Salesforce records containing customer data, employee data, and internal corporate material. When the company did not meet the group's demands, the actors published a dataset they said came from Sysco. Our investigation team has indexed roughly 4.5 million records from that dump, spanning information tied to both staff and customers. The incident came on top of a separate ransomware attack claimed by the Qilin gang earlier in the spring, making 2026 a difficult year for the world's largest foodservice distributor.
Breach Timeline
The dates below come from Sysco's notification letter and from independent reporting on the extortion campaign.
April 14, 2026: The date of breach listed in Sysco's notification letter, filed with state attorneys general.
April 23, 2026: Sysco became aware of unauthorized activity in parts of its computer environment, according to the notification letter.
May 5, 2026: The company learned that an unauthorized third party may have obtained certain files from its systems.
June 14, 2026: ShinyHunters posted Sysco on its Tor leak site, claiming more than 61 million stolen Salesforce records and threatening publication within days.
June 25, 2026: Sysco determined that the affected files did include personal information belonging to certain individuals.
July 22, 2026: The company mailed notification letters to affected individuals.
What Information Was Compromised?
Our analysis found the following data types in this breach: 4,540,682 names, 2,699,773 email addresses, 2,284,350 phone numbers, 2,267,032 street addresses, 4,668 driver's license numbers, 3,242 dates of birth, 15,454 vehicle identification numbers, and 9,522 vehicle license plates. TechNadu reported that the published dataset contained approximately 2.7 million unique email addresses and consisted largely of corporate contact information, including job titles and customer feedback records, tied to staff and business customers.
Sysco's notification letter, as reviewed by ClaimDepot, confirmed that names and Social Security numbers were exposed. The letter's summary also lists dates of birth, addresses, government IDs, and medical and financial information among the categories of information affected.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The presence of Social Security numbers raises the risk of identity theft and fraudulent account openings, since these identifiers can be used with dates of birth and addresses to impersonate someone convincingly. The large volume of email addresses and phone numbers creates a pool for phishing and smishing: attackers can send messages that reference real Sysco orders, account details, or job titles to appear legitimate. Business customers should be alert to invoice fraud and payment diversion scams, because the leaked contact records make it easier for criminals to pose as Sysco staff or vendors. Vehicle identification numbers, license plates, and driver's license numbers can support targeted scams or fraudulent title and insurance activity.
What Is Sysco Corporation Doing in Response?
According to ClaimDepot's review of the notification letter, Sysco is offering affected individuals 24 months of complimentary identity theft protection and credit monitoring through Experian IdentityWorks. Enrollment must be completed by October 31, 2026. The company has set up a helpline at 833-918-8818, available Monday through Friday, 8 a.m. to 8 p.m. Central Time. Sysco also disclosed the incident to multiple state attorneys general, including those of Massachusetts, Nebraska, and Vermont, and the total number of affected individuals has not been publicly disclosed.
What Should You Do If You Were Affected?
If you received a notification letter, enroll in the offered Experian IdentityWorks protection before the October 31 deadline. Review your credit reports for accounts you did not open, and consider placing a fraud alert or credit freeze with the major credit bureaus. Watch for emails, calls, or texts claiming to be from Sysco, especially messages that reference an order, account number, or support ticket, and verify any payment or banking change request through a known contact before acting. Anyone who provided a driver's license or vehicle information should monitor for related fraud as well.
