Unverified claim. On July 23, 2026, the Play ransomware group listed U.S. foodservice warehouse Restaurant Depot on its leak site, according to Ransomware.live and ThreatAtlas.
Restaurant Depot had not confirmed the listing in sources reviewed. Treat any “pay to stop a leak” message as hostile until the company posts on restaurantdepot.com.
What is known
Only the leak-site naming is public so far—no attested member count or data-element list in the monitors cited. This is not the company’s older 2011–2012 card-skimming era incidents.
Action items
- Members: watch for fake “account lock / re-verify membership” phishing.
- Use unique passwords on the Restaurant Depot portal.
- Wait for a company or AG notice before assuming your purchase history is confirmed stolen.