Sysco data breach (Qilin and ShinyHunters extortion claims)
Foodservice distributor Sysco notified individuals that an unauthorized party obtained files containing personal information after an April 2026 intrusion, following separate extortion claims by the Qilin ransomware gang and by ShinyHunters, which said it stole more than 61 million Salesforce records.
- Victim
- Sysco Corporation
- records
- 2.7M
On 22 July 2026, Sysco Corporation, the largest foodservice distributor in the United States, began mailing breach notification letters to individuals whose personal information was in files taken from its systems. According to the notice, Sysco became aware of unauthorized activity in parts of its environment on 23 April 2026, learned on 5 May that the intruder may have obtained files, and confirmed on 25 June that those files included personal information such as names and Social Security numbers. The company reported the breach to state regulators including the Massachusetts and Vermont attorneys general and offered affected people 24 months of identity protection through Experian IdentityWorks.
Two extortion claims
The breach drew two separate public extortion claims before Sysco's notification. On 6 May 2026, the Qilin ransomware gang listed Sysco on its leak site and threatened to publish stolen data unless the company made contact. In mid-June, the extortion group ShinyHunters claimed to have stolen more than 61 million Salesforce records from Sysco, covering customer data, employee data and other internal corporate information, and gave the company until 18 June to pay.
When the deadline passed, ShinyHunters published data that breach index Have I Been Pwned catalogued as 2,691,852 unique email addresses belonging to staff and customers, alongside names, phone numbers, physical addresses, job titles, employer details and customer feedback. Sysco has not publicly attributed the intrusion to either group, and it is not established whether the Qilin listing and the Salesforce data come from the same compromise.
Why it matters
Sysco supplies restaurants, hospitals, schools and hotels across North America, so its CRM holds contact and account details for a very large commercial customer base. The incident fits the 2026 ShinyHunters campaign against Salesforce environments, where the headline record counts reflect database rows rather than unique people, and it shows how a single victim can face overlapping extortion attempts from unrelated criminal groups.
Timeline
Sysco becomes aware of unauthorized activity in parts of its environment and begins an investigation.
Sysco learns that the unauthorized third party may have obtained certain files from its environment.
The Qilin ransomware gang lists Sysco on its data-leak site and threatens to publish stolen data.
ShinyHunters claims to have stolen more than 61 million Salesforce records from Sysco and sets a payment deadline of 18 June.
Sysco's review determines that the affected files contained personal information.
Have I Been Pwned adds 2,691,852 email addresses from the data ShinyHunters published.
Sysco mails notification letters to affected individuals and offers 24 months of credit monitoring.
Sources
- mass.govhttps://www.mass.gov/doc/2026-1239-sysco-corporation/download
- claimdepot.comhttps://www.claimdepot.com/data-breach/sysco-2026
- cybernews.comhttps://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Sysco
- dexpose.iohttps://www.dexpose.io/qilin-ransomware-group-targets-sysco/