// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
Breach Record

Sysco

DISCLOSED 2026-06-15 · STOLEN CREDS · 2,691,852 RECORDS EXPOSED

In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.

The record

What we know

Disclosed
2026-06-15
Attack vector
Stolen Creds
Records exposed
2,691,852
Domain
sysco.com
Data classes exposed
Customer feedbackEmail addressesEmployersJob titlesNamesPhone numbersPhysical addressesUsernames
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Sysco disclosure. It updates if new public reporting emerges. All tracked breaches →

Sysco just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →