← Blog

Sysco Breach: 2.7M Emails in ShinyHunters Dump

Share on X

June 2026: Food-distribution giant Sysco appeared in the ShinyHunters extortion wave tied to Salesforce-scale theft marketing. Published data reached Have I Been Pwned on June 28, 2026 with 2.7 million unique email addresses belonging to employees and customers.

What the HIBP load contains

  • 2.7M unique emails (staff and customer accounts)
  • Names, phone numbers, and physical addresses
  • Internal job titles, employers, and usernames
  • Customer feedback text tied to corporate contacts

For restaurants, hospitals, and schools that buy through Sysco, this is enough to craft convincing fake invoice or delivery-exception messages—even without passwords in the indexed set.

Separate from Sysco's 2023 breach

Sysco previously disclosed a 2023 payroll intrusion affecting roughly 126,000 people. The 2026 ShinyHunters corpus is a different published dump indexed at a much larger email scale; Sysco had not posted a matching 2026 consumer FAQ at HIBP load time.

Action items

  1. Check HIBP for emails used with Sysco ordering portals.
  2. Verify payment and ACH change requests through known Sysco rep phone numbers—not reply links.
  3. Alert accounts-payable staff to vendor-impersonation attempts citing real job titles from the leak.

Canonical record: Sysco 2026 on BreachHistory.