← Sysco

2026 Sysco — ShinyHunters extortion; HIBP 2,691,852 accounts (Jun)

2026 2.7M records affected Share on X

Data compromised

HIBP-indexed 2.7M unique email addresses for staff and customers with names, phone numbers, physical addresses, internal job titles, usernames, employers, and customer feedback

Technical writeup

HIBP- and company-attested corpus — June 2026. Sysco Corporation was targeted in a ShinyHunters “pay or leak” campaign; published data was loaded by Have I Been Pwned with 2,691,852 breached accounts (staff/customer emails plus corporate contact fields: names, phones, addresses, job titles, customer feedback). Sysco posted a public data-breach notification page and has communicated with individuals. Earlier Cybernews coverage cited much larger Salesforce-scale marketing figures; BreachHistory indexes the HIBP unique-account count 2,691,852. Distinct from Sysco’s 2023 long-dwell incident (~126k).

Root cause

ShinyHunters pay-or-leak extortion campaign against Sysco food distributor; published corpus indexed by Have I Been Pwned June 28, 2026—formal Sysco customer notice not published at catalog time

References