Sysco A.I CyberSecurity Scoring
Sysco
Company Information
Website:http://www.sysco.com
Employees number:35,617
Number of followers:440,589
NAICS:722
Industry Type:Food and Beverage Services
Homepage:sysco.com
Sysco Risk Score (AI oriented)
Between 550 and 599
SyscoFood and Beverage Services
Updated:
07/08/2026
07/08/2026
575/1000
Very Poor
Ca
Sysco Global Score (TPRM)
xxxx
SyscoFood and Beverage Services
Score locked

SyscoVery Poor
Current Score
575Ca (VERY POOR)
01000
6 incidents
-59 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
575
JULY 2026
628
Breach
13 Jul 2026 • Sysco
Brinks Home: ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Brinks Home Suffers Data Breach Following Vishing Attack by ShinyHunters
570
CRITICAL-58
BRI1785435859
Brinks Home Suffers Data Breach Following Vishing Attack by ShinyHunters
Brinks Home, a leading residential security provider serving over 1 million customers across the U.S., Canada, and Puerto Rico, disclosed a data breach after hackers infiltrated its systems. The company detected the attack on July 20 and immediately launched an incident response, enlisting forensic experts to contain the breach. While alarm monitoring and system functionality remained unaffected, the threat actor identified as the ShinyHunters extortion gang claimed to have stolen sensitive data.
According to ShinyHunters, the breach occurred on July 13 via a Microsoft Entra voice phishing (vishing) attack, in which an employee was tricked into completing an authentication process, granting the hackers access. The group alleges it exfiltrated:
- 1.1 million+ rows of customer data from Salesforce’s "Contacts" object,
- 4,000+ rows of employee PII, including names, emails, job titles, and phone numbers,
- 3.8 million+ customer support chat logs from Brinks’ Care Cresta instance.
Brinks Home confirmed the attacker’s threat to leak the data but has not verified the full scope of the stolen information. The company stated it is still investigating and will notify affected individuals if their data is confirmed compromised. In the meantime, Brinks warned customers about potential fraudulent messages exploiting the incident.
With $830 million in annual revenue and 1,500 employees, Brinks Home offers security systems, smart home devices, and monitoring services. The breach highlights the growing risk of vishing attacks targeting enterprise authentication systems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
681
Breach
01 Jun 2026 • Sysco
Sysco: Have I Been Pwned’s Post
Sysco Hit by ShinyHunters Extortion Campaign
624
CRITICAL-57
SYS1782671069
Sysco Hit by ShinyHunters Extortion Campaign, Exposing 2.7M Email Addresses
Earlier this month, global foodservice distributor Sysco fell victim to an extortion campaign by the cybercriminal group ShinyHunters. The breach resulted in the exposure of 2.7 million unique email addresses, along with a significant volume of corporate contact details.
Analysis of the leaked data revealed that 44% of the compromised email addresses were already linked to LinkedIn profiles, suggesting a high concentration of professional and business-related accounts. The incident highlights the ongoing threat posed by extortion-focused cyberattacks, where stolen data is often leveraged for financial gain or further malicious activity.
Sysco, a major player in the food distribution industry, has not publicly detailed the full scope of the breach or its response measures. The exposure of corporate contact information raises concerns about potential follow-on attacks, including phishing and social engineering campaigns targeting affected organizations. The incident underscores the persistent risks faced by enterprises handling large volumes of sensitive data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
679
APRIL 2026
739
Breach
23 Apr 2026 • Sysco
Sysco Corp.: Sysco Corp Data Breach Exposes Social Security Numbers
Sysco Corp. Data Breach Exposing Personal Information
677
CRITICAL-62
SYS1785508066
Sysco Corp. Confirms Data Breach Exposing Personal Information in Second Major Cyberattack of 2026
Sysco Corp., the world’s largest foodservice distributor, has notified individuals of a cyberattack that compromised personal data, marking the company’s second major breach in 2026. The incident was first detected on April 23, 2026, when unauthorized activity was identified in parts of Sysco’s computer systems. After containing the threat, the company launched an investigation and discovered on May 5, 2026, that an unauthorized third party had accessed certain files. A subsequent review concluded on June 25, 2026, that these files contained personal information.
The breach was publicly linked to the threat actor group ShinyHunters, which claimed responsibility on June 14, 2026, via a post on the Tor network. The group alleged it had exfiltrated over 61 million Salesforce records, including customer and employee data, personally identifiable information (PII), and internal corporate documents. ShinyHunters threatened to publish the data within three days, though it remains unclear whether the full dataset was released.
The exposed information included names and Social Security numbers, though the total number of affected individuals has not been disclosed. Sysco reported the breach to the Massachusetts Office of Consumer Affairs and Business Regulation and the Vermont Attorney General, and began mailing notification letters to impacted individuals on July 22, 2026.
This incident follows a prior attack on May 6, 2026, when Sysco was targeted by the Qilin ransomware group, just weeks before the current breach was detected. In response to the latest compromise, Sysco is offering 24 months of complimentary identity theft protection and credit monitoring through Experian IdentityWorks, with enrollment required by October 31, 2026. Affected individuals may contact Sysco’s dedicated support line for assistance.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
734
FEBRUARY 2026
733
JANUARY 2026
731
DECEMBER 2025
730
NOVEMBER 2025
728
OCTOBER 2025
727
SEPTEMBER 2025
725
MAY 2023
725
Breach
01 May 2023 • Sysco
Sysco
Sysco Data Breach (2023)
663
CRITICAL-62
SYS5792657090725
Sysco, the world’s leading food service company, experienced a data breach in 2023 that exposed customer and employee data, leading to a class action lawsuit. The breach resulted in victims spending significant time and money on identity theft and fraud protection, with an increased risk of future fraud. Plaintiffs alleged Sysco’s inadequate cybersecurity measures failed to prevent the incident. While Sysco denied wrongdoing, it agreed to a $2.3 million settlement, offering eligible U.S. residents (who received breach notices in May 2023) up to $5,000 for documented losses, credit monitoring, and residual cash payments. The breach’s consequences included financial burdens, reputational damage, and long-term vulnerability for affected individuals, with claims requiring proof of expenses and a valid class member ID by the September 8, 2025 deadline.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2023
765
Breach
01 Mar 2023 • Sysco
Sysco
Sysco Data Breach
721
CRITICAL-44
SYS222728523
Sysco, the global food distribution giant, suffered from a data breach, that exposed data including customer and employee data.
The exposed data includes data relating to the operation of the business, customers, employees, and personal data, reads a 10-Q quarterly report filed with the U.S. SEC.
This data extraction has not impacted Sysco’s operational systems and related business functions, and its service to customers continued uninterrupted.
Sysco also notified federal law enforcement.
The security team at Sysco added further measures as a result of the incident to guard against a similar compromise in the future.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
815
Breach
14 Jan 2023 • Sysco
Sysco Corporation
Sysco Corporation Data Breach
764
HIGH-51
SYS351072625
The California Office of the Attorney General reported a data breach involving Sysco Corporation on May 16, 2023. The breach occurred on January 14, 2023, where unauthorized access to systems potentially exposed personal information of current and former colleagues, including names and social security numbers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Sysco ??
What was Sysco's A.I Rankiteo Cyber Score in July 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in June 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in May 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in April 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in March 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in February 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in January 2026 ??
What was Sysco's A.I Rankiteo Cyber Score in December 2025 ??
What was Sysco's A.I Rankiteo Cyber Score in November 2025 ??
What was Sysco's A.I Rankiteo Cyber Score in October 2025 ??
What was Sysco's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Sysco's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Sysco ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Sysco's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?