2023 Sysco — long-dwell intrusion (Jan–Mar); ~126k individuals; payroll identifiers in Maine AG filings
Data compromised
Payroll-class PII (names, SSNs, financial-account-style identifiers per sample notices) plus unspecified company and customer data
Technical writeup
Sysco told employees and regulators it detected unauthorized activity on March 5, 2023, after an intrusion believed to have begun January 14, 2023. Letters summarized in Maine breach indexing and trade reporting cited roughly 126,243 U.S. persons notified, with combinations of names and Social Security numbers tied to payroll systems; corporate and customer operational data were also described as extracted pending further compliance review. The company did not publicly brand the event as ransomware in those primary disclosures, though it noted the actor claimed to hold data—typical of dual ransomware/extortion timelines.
Root cause
External compromise with extended dwell time and data extraction from enterprise and HR-facing systems