Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Ahold Delhaize Data Breach Impacts 2.2 Million People

The ransomware attack against grocery giant Ahold Delhaize has resulted in the personal information of millions getting stolen.

Ahold Delhaize USA ransomware data breach

Dutch grocery giant Ahold Delhaize revealed last week that the ransomware attack targeting its systems last year resulted in a data breach impacting more than 2.2 million individuals.

The cybersecurity incident came to light in November 2024, when several US pharmacies and supermarket chains owned by Ahold Delhaize reported suffering network issues. The incident impacted Giant Food pharmacies and Hannaford supermarkets, as well as Food Lion, The Giant Company, and Stop & Shop.

The Inc Ransom ransomware group took credit for the attack on Ahold Delhaize in mid-April 2025, and the company confirmed shortly after that the hackers likely exfiltrated data from some of its internal business systems.

Ahold Delhaize has since determined that personal information has been compromised and impacted individuals are now being notified. 

The stolen files stored internal employment records pertaining to current and former Ahold Delhaize USA companies. 

The organization told the Maine Attorney General’s Office that 2,242,521 people are affected.

Advertisement. Scroll to continue reading.

The compromised information varies from individual to individual, but can include name, contact information, date of birth, Social Security number, passport number, driver’s license number, financial account information, health information, and employment-related details.   

Affected individuals are being offered two years of free credit monitoring and identity protection services.

On their Tor-based leak website, the cybercriminals have made available roughly 800 Gb of data allegedly stolen from Ahold Delhaize, which indicates that the company has not paid a ransom. Inc Ransom claimed to have stolen 6 Tb of files from the company.

The retail industry, particularly supermarkets, have been increasingly targeted in cyberattacks in recent months. 

UK retailers Co-op, Harrods, and M&S were targeted in April by cybercriminals believed to be associated with the Scattered Spider group.  

Earlier this month, United Natural Foods (UNFI), the main distributor for Amazon’s Whole Foods and many other grocery stores in North America, was hit by a cyberattack that caused disruptions to business operations and led to grocery shortages.

UNFI said there is no indication that personal or health information has been stolen, and no ransomware group has taken credit for the attack.

Related: Aflac Finds Suspicious Activity on US Network That May Impact Social Security Numbers, Other Data

Related: Steelmaker Nucor Says Hackers Stole Data in Recent Attack

Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.