Food seller Ahold Delhaize notifies 2.2 million people of data breach that compromised SSNs, financial and health info

The US arm of Dutch-Belgian food retailer Ahold Delhaize yesterday confirmed it notified 2,242,521 people of a November 2024 data breach that compromised the following info:

  • Names
  • Social Security numbers
  • Financial account info including bank account numbers
  • Health info including worker’s compensation info
  • Employment-related info
  • Government-issued ID numbers (passports, driver’s licenses, etc)
  • Postal addresses
  • Email addresses
  • Phone numbers
  • Dates of birth

This was the eighth-largest breach on a US company via ransomware in 2024, and the 11th-largest worldwide, according to Comparitech’s research.

Ransomware gang Inc took credit for the attack, saying it stole 6 TB of data from Ahold Delhaize.

Inc lists Ahold Delhaize on its data leak site.

Ahold Delhaize has not verified Inc’s claim. We do not know if Ahold Delhaize paid a ransom, how much Inc demanded, or how attackers breached the company’s network. Comparitech contacted Ahold Delhaize for comment and will update this article if it replies.

“We detected a cybersecurity issue involving unauthorized access to some of our internal U.S. business systems on November 6, 2024,” says the company’s notice to victims. “Based on our investigation, we identified that an unauthorized third party obtained certain files from one of our internal U.S. file repositories between November 5 and 6, 2024.”

In a FAQ section on Ahold Delhaize’s website, the company states, “The issue affected certain internal U.S. business systems, including one of our internal file repositories. We have no indication that customer payment or pharmacy systems were compromised in connection with the issue.”

Ahold Delhaize is offering eligible victims two years of free credit monitoring and identity theft protection through Experian. The deadline to enroll is September 30, 2025.

Who is Inc?

Inc Ransomware emerged in July 2023 and targets a wide range of victims in healthcare, education, and government. Its methods involve spear phishing and exploiting known vulnerabilities in software. Once infected, Inc’s malware both steals data and locks down computer systems until a ransom is paid to unlock them.

Since it began listing targets on its leak site, Inc has claimed responsibility for 98 confirmed ransomware attacks: 60 in 2024 and 17 in 2025 to date. The group made hundreds of other unconfirmed claims that haven’t been acknowledged by the targeted organizations.

This attack on Ahold Delhaize is Inc’s largest to date by number of records compromised. It’s followed by an attack on OnePoint Patient Care, which notified 1.7 million people of the resulting date breach.

Last night, Inc demanded a $1 million ransom from Tonga’s Ministry of Health after its ransomware crippled the country’s national health information system.

In 2024, Inc hit another company in the food and beverage industry. The Coffee Bean and Tea Leaf, a café franchise, notified 53,901 people of a June 2024 data breach.

Ransomware attacks on US food and beverages

In 2024, Comparitech researchers logged 36 confirmed ransomware attacks on food and beverage companies, compromising more than 2.9 million records. Inc’s attack on Ahold Delhaize accounts for the majority of these.

Other such attacks include:

  • Bojangles notified 165,106 people of a February 2024 data breach claimed by Hunters International
  • Krispy Kreme notified 161,676 people of a November 2024 data breach claimed by Play

The attack on Krispy Kreme cost $11 million in revenue and another $3 million in remediation, according to the company.

In 2025 to date, we’ve recorded four confirmed ransomware attacks on the US food and beverage industry, and we’re monitoring 82 unconfirmed attack claims.

About Ahold Delhaize USA

Ahold Delhaize USA, or ADUSA, is the American arm a Dutch-Belgian company of the same name. It is one of the biggest food retail and wholesale companies in the United States. ADUSA supplies and operates a number of US grocery store chains, including Food Lion, Giant Food, Stop & Shop, Hannaford.

Ahold Delhaize employs 402,000 people at 7,716 stores across nine countries. In the USA, it operates more than 2,000 stores in 23 states.


Source link
Exit mobile version