Ahold Delhaize, a global food retail giant operating over 9,400 stores worldwide, has disclosed that a November ransomware attack compromised the personal data of more than 2.2 million individuals.
## Company Overview
The multinational retailer serves approximately 60 million customers weekly across Europe, the United States, and Indonesia, employing over 393,000 people. With annual net sales exceeding $104 billion, the company operates well-known brands including Food Lion, Stop & Shop, Giant Food, and Hannaford in the U.S., plus Delhaize and other European chains.
## The Breach Details
On November 6, 2024, cybercriminals infiltrated Ahold Delhaize’s internal U.S. business systems, stealing sensitive information from 2,242,521 individuals. The attack primarily affected the company’s U.S. operations, including pharmacies and e-commerce platforms.
### Compromised Information
The stolen data varied by individual but potentially included:
– Personal details (names, addresses, phone numbers, birth dates)
– Government identification numbers (Social Security, passport, driver’s license)
– Financial account information
– Health records from employment files
– Employment-related documents
While the company hasn’t confirmed customer data exposure, the breach primarily involved internal employment records of current and former employees.
## The Attackers
Although Ahold Delhaize hasn’t officially named the perpetrators, cybersecurity experts link the attack to INC Ransom, a ransomware-as-a-service group that emerged in July 2023. The group added Ahold Delhaize to its dark web extortion site in April, releasing sample stolen documents.
### INC Ransom’s Track Record
This ransomware operation has targeted over 250 organizations across various sectors, including:
– Scotland’s National Health Service
– Yamaha Motor Philippines
– Xerox Business Solutions U.S. division
– State Bar of Texas (affecting 100,000+ members)
The group has recently focused on U.S. organizations, particularly healthcare providers, with one member known as “Vanilla Tempest” specifically targeting American medical facilities.
## Impact and Response
The breach affected multiple Ahold Delhaize USA brands and services, disrupting pharmacy operations and e-commerce activities. The company filed disclosure documents with Maine’s Attorney General, meeting legal notification requirements for data breaches.
This incident highlights the ongoing cybersecurity challenges facing major retailers and the sophisticated nature of modern ransomware operations targeting critical infrastructure and large-scale consumer data.
