Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Ahold Delhaize Data Breach Impacts 2.2 Million People

The ransomware attack against grocery giant Ahold Delhaize has resulted in the personal information of millions getting stolen.

Ahold Delhaize USA ransomware data breach

Dutch grocery giant Ahold Delhaize revealed last week that the ransomware attack targeting its systems last year resulted in a data breach impacting more than 2.2 million individuals.

The cybersecurity incident came to light in November 2024, when several US pharmacies and supermarket chains owned by Ahold Delhaize reported suffering network issues. The incident impacted Giant Food pharmacies and Hannaford supermarkets, as well as Food Lion, The Giant Company, and Stop & Shop.

The Inc Ransom ransomware group took credit for the attack on Ahold Delhaize in mid-April 2025, and the company confirmed shortly after that the hackers likely exfiltrated data from some of its internal business systems.

Ahold Delhaize has since determined that personal information has been compromised and impacted individuals are now being notified. 

The stolen files stored internal employment records pertaining to current and former Ahold Delhaize USA companies. 

The organization told the Maine Attorney General’s Office that 2,242,521 people are affected.

Advertisement. Scroll to continue reading.

The compromised information varies from individual to individual, but can include name, contact information, date of birth, Social Security number, passport number, driver’s license number, financial account information, health information, and employment-related details.   

Affected individuals are being offered two years of free credit monitoring and identity protection services.

On their Tor-based leak website, the cybercriminals have made available roughly 800 Gb of data allegedly stolen from Ahold Delhaize, which indicates that the company has not paid a ransom. Inc Ransom claimed to have stolen 6 Tb of files from the company.

The retail industry, particularly supermarkets, have been increasingly targeted in cyberattacks in recent months. 

UK retailers Co-op, Harrods, and M&S were targeted in April by cybercriminals believed to be associated with the Scattered Spider group.  

Earlier this month, United Natural Foods (UNFI), the main distributor for Amazon’s Whole Foods and many other grocery stores in North America, was hit by a cyberattack that caused disruptions to business operations and led to grocery shortages.

UNFI said there is no indication that personal or health information has been stolen, and no ransomware group has taken credit for the attack.

Related: Aflac Finds Suspicious Activity on US Network That May Impact Social Security Numbers, Other Data

Related: Steelmaker Nucor Says Hackers Stole Data in Recent Attack

Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.