June 2026: Food-distribution giant Sysco appeared in the ShinyHunters extortion wave tied to Salesforce-scale theft marketing. Published data reached Have I Been Pwned on June 28, 2026 with 2.7 million unique email addresses belonging to employees and customers.
What the HIBP load contains
- 2.7M unique emails (staff and customer accounts)
- Names, phone numbers, and physical addresses
- Internal job titles, employers, and usernames
- Customer feedback text tied to corporate contacts
For restaurants, hospitals, and schools that buy through Sysco, this is enough to craft convincing fake invoice or delivery-exception messages—even without passwords in the indexed set.
Separate from Sysco's 2023 breach
Sysco previously disclosed a 2023 payroll intrusion affecting roughly 126,000 people. The 2026 ShinyHunters corpus is a different published dump indexed at a much larger email scale; Sysco had not posted a matching 2026 consumer FAQ at HIBP load time.
Action items
- Check HIBP for emails used with Sysco ordering portals.
- Verify payment and ACH change requests through known Sysco rep phone numbers—not reply links.
- Alert accounts-payable staff to vendor-impersonation attempts citing real job titles from the leak.
Canonical record: Sysco 2026 on BreachHistory.