Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Over 2 million affected by US supermarket breach | Computer Weekly

By Computer Weekly by By Computer Weekly
June 27, 2025
Home Uncategorized
Share on FacebookShare on Twitter


Belgian-Dutch supermarket operator Ahold Delhaize has revealed that the personal data of over two million individuals was compromised in a November 2024 ransomware attack on the systems of its US operations.

In a filing made this week at the office of the attorney general for the US state of Maine, the organisation said that 2,242,521 people in total had been affected.

In a letter to impacted individuals signed by Ahold Delhaize’s US legal affairs vice president, Dyana Tull, the organisation said that the stolen data included names, contact details, dates of birth, Social Security, passport and driving licence details, financial account information, and employee data related to compensation and occupational health.

“Upon detection last November, we began taking steps to assess and contain the issue, including working with external cyber security experts to investigate and secure the affected systems,” wrote Tull.

“We take this issue extremely seriously and will continue to take actions to further protect our systems…. We regret any inconvenience this issue may cause for you.”

As has become customary following such breaches, Ahold Delhaize is offering those affected a year’s worth of free identity protection and credit monitoring via Experian, which can be taken up until the end of September.

Following the incident last year saw the INC Ransom crew claimed to have stolen six terabytes of data from Ahold Delhaize, which besides the Food Lion and Giant supermarket chains in the US, operates the eponymous Albert Heijn and Delhaize chains in the Benelux region, as well as stores in Indonesia, Romania and Serbia.

In April 2025, it also emerged that data on Dutch employees who were on the company payroll in April 2021 had also been compromised.

The cyber attack also caused disruption for customers at some of Ahold Delhaize’s US operations, notably its Food Lion and Hannaford chains, when the company was forced to shut down key online commerce systems.

“Affected users should be vigilant for signs of identity theft and phishing attempts. The stolen information can be used for social engineering attacks, as attackers can pose as legitimate representatives of financial institutions, healthcare providers, or government agencies,” said Boris Cipot, senior security engineer at Black Duck, an application security specialist.

“To mitigate potential harm, users should notify relevant institutions about the breach, such as their bank, healthcare provider, employer, or government agencies. These institutions can provide guidance on next steps to protect against further exposure, monitor credit status, and prevent identity theft,” he said.

Who are INC Ransom?

INC Ransom, the cyber criminal gang that claims this particular attack, has been active for approximately two years.

It targets organisations primarily in Europe and the US, and has had a particular focus on the education, healthcare and industrial sectors.

In the UK specifically, it appears to have been behind attacks on Alder Hey Childrens NHS Foundation Trust and Liverpool Heart and Chest Hospital NHS Foundation Trust, and NHS Dumfries and Galloway.

According to analysts at SentinelOne, the gang works to a fairly typical playbook where it tries to present itself not as a criminal operation but as a service provider offering victims the chance to both ‘save their reputation’ and make their IT systems ‘more secure’.

It uses a variety of initial access methods such as targeted spear phishing emails, and has also been known to exploit vulnerabilities in Citrix products.

Its locker malware uses AES-256 encryption in cipher block chaining (CBC) mode and will terminate open processes in order to encrypt open files, as well as targeting backups for deletion.



Source link

By Computer Weekly

By Computer Weekly

Next Post
PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack

PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack

Recommended.

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

February 5, 2025
Verve Cloud, Inc. Announces NPS Score of 36

Verve Cloud, Inc. Announces NPS Score of 36

November 8, 2025

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
How Ceros Gives Security Teams Visibility and Control in Claude Code

How Ceros Gives Security Teams Visibility and Control in Claude Code

March 19, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio