Sysco discloses breach affecting customer, supplier and employee data

Organization
Sysco Corporation
Exploit
Hacking
Industry
Food Distribution

Sysco, the Houston-based foodservice distributor, disclosed a data breach in a quarterly filing with the US Securities and Exchange Commission on May 2, 2023, and followed up with an internal memo to employees the next day. The company said it detected the intrusion on March 5 but that its investigation indicated the attacker had access to its network from January 14.

According to Sysco, the stolen material included data relating to the operation of the business, customers and employees. Customer and supplier information from the United States and Canada was affected, along with personal data belonging to US employees that had been provided for payroll purposes, including names and Social Security numbers.

Breach notification filings reported by BleepingComputer put the number of affected individuals at roughly 126,000. Sysco said the incident did not disrupt customer service or business operations.

The company engaged outside cybersecurity and forensics specialists, notified federal law enforcement, isolated the attacker from its network and put additional safeguards in place. Sysco said there was no ongoing threat as of the May disclosure, and that its review of the extracted data and the resulting individual notifications were still underway. No threat group publicly claimed the attack.

Sources