Skip to content
Cyber Security Firms
ConfirmedOther

Sysco Data Breach (June 2026)

ShinyHunters claimed 61 million Salesforce records from the food distributor and published data that Have I Been Pwned verified as 2.7 million email addresses with names, phone numbers, job titles and customer feedback.

Disclosed Updated
Organization
Sysco
Sector
Other
Country
United States, TX
Incident date
June 15, 2026
Disclosed
June 16, 2026
Records affected
2.7 million
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses
  • Job titles
  • Employers
  • Usernames
  • Customer feedback
Timeline
  1. The intrusion, per the breach date Have I Been Pwned records
  2. ShinyHunters lists Sysco on its leak site, claiming more than 61 million Salesforce records
  3. Have I Been Pwned loads 2.7 million verified email addresses from the published data

What Happened

Sysco, the Houston-based food distributor that supplies restaurants, hospitals and schools across the country, appeared on the ShinyHunters leak site on June 16, 2026. The group claimed it had taken more than 61 million Salesforce records "across several tables," according to Cybernews, which noted this was the second extortion claim against the company in a matter of weeks. Salesforce environments have been the group's route into hundreds of companies over the past year, usually by talking staff into authorizing a malicious connected application, though Sysco has not said how its data was reached.

The data was subsequently published. Have I Been Pwned verified it on June 28 and loaded 2,691,852 unique email addresses belonging to staff and customers, alongside largely corporate contact information: names, phone numbers, physical addresses, internal job titles and customer feedback. Sysco has published a substitute data breach notification stating that the breach involved some personal information.

The 61 million figure is the group's claim about rows in a database. The 2.7 million figure is the count of distinct email addresses a third party verified in what was published. Both are on this page for that reason, and only the second one is on the fact grid.

What was Exposed

Business contact data, mostly: who works where, in what role, with which phone number and address, plus the feedback customers gave the company. Passwords and payment data are not among the verified classes.

The risk is to businesses rather than individuals. A restaurant owner's name, role and phone number together with their Sysco account history is precisely what a fake "your Sysco invoice is overdue" call or email needs, and business email compromise is the second most costly category of internet crime by loss, per the FBI's Internet Crime Complaint Center.

What to do if you are Affected

The mechanics of the messages that will follow are in what phishing looks like, and the general sequence is in what to do after a data breach.

What is not Known Yet

How the data was reached, what Sysco's individual notices say, and whether the 61 million figure reflects duplicate rows across tables, which is common in exports of this kind. The report will be updated as the record grows.

Sources

  1. Have I Been Pwned: Sysco
  2. Cybernews, Sysco hit by second extortion claim over 61M records, June 16, 2026
  3. Sysco data breach notification
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →