Ransomware

Subway Sandwich Chain Investigating Ransomware Group’s Claims

The LockBit ransomware group claims to have stolen hundreds of gigabytes of data from US sandwich chain Subway.

The LockBit ransomware group claims to have stolen hundreds of gigabytes of data from US sandwich chain Subway.

Sandwich chain Subway has launched an investigation after the notorious LockBit ransomware group claimed over the weekend that it hacked into the company’s systems and stole vast amounts of information. 

“The biggest sandwich chain is pretending that nothing happened,” the LockBit gang said in a message posted on its website. “We exfiltrated their SUBS internal system which includes hundreds of gigabytes of data and all financial expects of the franchise, including employee salaries, franchise royalty payments, master franchise commission payments, restaurant turnovers etc.” 

The hackers added, “We are giving some time for them to come and protect this data, if no we are open to sell to competitors.”

The cybercriminals posted the message on January 21 and are apparently giving Subway until February 2 to pay a ransom. 

“We are exploring the validity of the claim,” a Subway spokesperson told SecurityWeek via email.

Subway has roughly 20,000 locations worldwide and over 400,000 employees, according to the company’s Wikipedia page. 

LockBit has been the most active ransomware group, targeting thousands of organizations. The US government reported in June 2023 that the group had targeted 1,700 entities in the US alone, receiving over $90 million in ransom payments since early 2020. 

Advertisement. Scroll to continue reading.

Related: MGM Resorts Says Ransomware Hack Cost $110 Million

Related: Ransomware Shuts Hundreds of Yum Brands Restaurants in UK

Related: Cyberattack Disrupts Ace Hardware’s Operations

Related: 500k Impacted by Data Breach at Fashion Retailer Forever 21 

Related Content

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version