Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Sysco

Sysco Vendor Cyber Rating & Cyber Score

sysco.com

Sysco is the global leader in selling, marketing and distributing food and related products to customers who prepare meals away from home. This includes restaurants, healthcare and educational facilities, lodging establishments, entertainment venues, and more. Sysco operates almost 340 distribution centers, in over 10 countries, with 76,000 colleagues serving approximately 730,000 customer locations. The company generated sales of more than $81 billion in fiscal year 2025 that ended June 28, 2025. As the world’s largest food-away-from-home distributor, Sysco offers customized supply chain solutions, bespoke specialty product offerings, and culinary support to drive customers to innovate and optimize their operations. We act as a trusted


Sysco A.I CyberSecurity Scoring

Sysco
Company Information
Website:http://www.sysco.com
Employees number:35,617
Number of followers:440,589
NAICS:722
Industry Type:Food and Beverage Services
Homepage:sysco.com
Sysco Risk Score (AI oriented)
Between 550 and 599
logo
SyscoFood and Beverage Services
Updated:
07/08/2026
575/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Sysco Global Score (TPRM)
xxxx
logo
SyscoFood and Beverage Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Sysco
SyscoVery Poor
Current Score
575Ca (VERY POOR)
01000
6 incidents
-59 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
575Before Incident
JULY 2026
628Before Incident
Breach
13 Jul 2026Sysco
Brinks Home: ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Brinks Home Suffers Data Breach Following Vishing Attack by ShinyHunters

570After Incident
CRITICAL-58
BRI1785435859
Brinks Home Suffers Data Breach Following Vishing Attack by ShinyHunters Brinks Home, a leading residential security provider serving over 1 million customers across the U.S., Canada, and Puerto Rico, disclosed a data breach after hackers infiltrated its systems. The company detected the attack on July 20 and immediately launched an incident response, enlisting forensic experts to contain the breach. While alarm monitoring and system functionality remained unaffected, the threat actor identified as the ShinyHunters extortion gang claimed to have stolen sensitive data. According to ShinyHunters, the breach occurred on July 13 via a Microsoft Entra voice phishing (vishing) attack, in which an employee was tricked into completing an authentication process, granting the hackers access. The group alleges it exfiltrated: - 1.1 million+ rows of customer data from Salesforce’s "Contacts" object, - 4,000+ rows of employee PII, including names, emails, job titles, and phone numbers, - 3.8 million+ customer support chat logs from Brinks’ Care Cresta instance. Brinks Home confirmed the attacker’s threat to leak the data but has not verified the full scope of the stolen information. The company stated it is still investigating and will notify affected individuals if their data is confirmed compromised. In the meantime, Brinks warned customers about potential fraudulent messages exploiting the incident. With $830 million in annual revenue and 1,500 employees, Brinks Home offers security systems, smart home devices, and monitoring services. The breach highlights the growing risk of vishing attacks targeting enterprise authentication systems.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Customer and employee data, customer support chat logsSystems Affected: Salesforce Contacts object, Care Cresta instanceOperational Impact: Alarm monitoring and system functionality remained unaffectedBrand Reputation Impact: Potential brand reputation damage due to data breachIdentity Theft Risk: High (PII exposed)
DATA BREACH
Customer dataEmployee PIICustomer support chat logsNumber Of Records Exposed: 1.1 million+ (customer data), 4,000+ (employee PII), 3.8 million+ (chat logs)Sensitivity Of Data: High (PII, chat logs)Data Exfiltration: YesPersonally Identifiable Information: Names, emails, job titles, phone numbers
JUNE 2026
681Before Incident
Breach
01 Jun 2026Sysco
Sysco: Have I Been Pwned’s Post

Sysco Hit by ShinyHunters Extortion Campaign

624After Incident
CRITICAL-57
SYS1782671069
Sysco Hit by ShinyHunters Extortion Campaign, Exposing 2.7M Email Addresses Earlier this month, global foodservice distributor Sysco fell victim to an extortion campaign by the cybercriminal group ShinyHunters. The breach resulted in the exposure of 2.7 million unique email addresses, along with a significant volume of corporate contact details. Analysis of the leaked data revealed that 44% of the compromised email addresses were already linked to LinkedIn profiles, suggesting a high concentration of professional and business-related accounts. The incident highlights the ongoing threat posed by extortion-focused cyberattacks, where stolen data is often leveraged for financial gain or further malicious activity. Sysco, a major player in the food distribution industry, has not publicly detailed the full scope of the breach or its response measures. The exposure of corporate contact information raises concerns about potential follow-on attacks, including phishing and social engineering campaigns targeting affected organizations. The incident underscores the persistent risks faced by enterprises handling large volumes of sensitive data.
INCIDENT DETAILS -
TYPE
Extortion
MOTIVATION
Financial gain
IMPACT
Data Compromised: 2.7 million unique email addresses and corporate contact details
DATA BREACH
Email addressesCorporate contact detailsNumber Of Records Exposed: 2.7 millionSensitivity Of Data: High (44% linked to LinkedIn profiles)Personally Identifiable Information: Email addresses
MAY 2026
679Before Incident
APRIL 2026
739Before Incident
Breach
23 Apr 2026Sysco
Sysco Corp.: Sysco Corp Data Breach Exposes Social Security Numbers

Sysco Corp. Data Breach Exposing Personal Information

677After Incident
CRITICAL-62
SYS1785508066
Sysco Corp. Confirms Data Breach Exposing Personal Information in Second Major Cyberattack of 2026 Sysco Corp., the world’s largest foodservice distributor, has notified individuals of a cyberattack that compromised personal data, marking the company’s second major breach in 2026. The incident was first detected on April 23, 2026, when unauthorized activity was identified in parts of Sysco’s computer systems. After containing the threat, the company launched an investigation and discovered on May 5, 2026, that an unauthorized third party had accessed certain files. A subsequent review concluded on June 25, 2026, that these files contained personal information. The breach was publicly linked to the threat actor group ShinyHunters, which claimed responsibility on June 14, 2026, via a post on the Tor network. The group alleged it had exfiltrated over 61 million Salesforce records, including customer and employee data, personally identifiable information (PII), and internal corporate documents. ShinyHunters threatened to publish the data within three days, though it remains unclear whether the full dataset was released. The exposed information included names and Social Security numbers, though the total number of affected individuals has not been disclosed. Sysco reported the breach to the Massachusetts Office of Consumer Affairs and Business Regulation and the Vermont Attorney General, and began mailing notification letters to impacted individuals on July 22, 2026. This incident follows a prior attack on May 6, 2026, when Sysco was targeted by the Qilin ransomware group, just weeks before the current breach was detected. In response to the latest compromise, Sysco is offering 24 months of complimentary identity theft protection and credit monitoring through Experian IdentityWorks, with enrollment required by October 31, 2026. Affected individuals may contact Sysco’s dedicated support line for assistance.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Exfiltration
IMPACT
Data Compromised: Personal information, including names and Social Security numbersSystems Affected: Salesforce records, internal corporate systemsBrand Reputation Impact: Likely significant due to second major breach in 2026Identity Theft Risk: High (Social Security numbers exposed)
DATA BREACH
Personally Identifiable Information (PII)Internal corporate documentsNumber Of Records Exposed: Over 61 million Salesforce recordsSensitivity Of Data: High (Social Security numbers, customer and employee data)Data Exfiltration: Yes (claimed by ShinyHunters)NamesSocial Security numbers
MARCH 2026
734Before Incident
FEBRUARY 2026
733Before Incident
JANUARY 2026
731Before Incident
DECEMBER 2025
730Before Incident
NOVEMBER 2025
728Before Incident
OCTOBER 2025
727Before Incident
SEPTEMBER 2025
725Before Incident
MAY 2023
725Before Incident
Breach
01 May 2023Sysco
Sysco

Sysco Data Breach (2023)

663After Incident
CRITICAL-62
SYS5792657090725
Sysco, the world’s leading food service company, experienced a data breach in 2023 that exposed customer and employee data, leading to a class action lawsuit. The breach resulted in victims spending significant time and money on identity theft and fraud protection, with an increased risk of future fraud. Plaintiffs alleged Sysco’s inadequate cybersecurity measures failed to prevent the incident. While Sysco denied wrongdoing, it agreed to a $2.3 million settlement, offering eligible U.S. residents (who received breach notices in May 2023) up to $5,000 for documented losses, credit monitoring, and residual cash payments. The breach’s consequences included financial burdens, reputational damage, and long-term vulnerability for affected individuals, with claims requiring proof of expenses and a valid class member ID by the September 8, 2025 deadline.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $2.3 million (settlement amount)
DATA BREACH
Personally Identifiable Information (PII)Sensitivity Of Data: High (risk of identity theft and fraud)
MARCH 2023
765Before Incident
Breach
01 Mar 2023Sysco
Sysco

Sysco Data Breach

721After Incident
CRITICAL-44
SYS222728523
Sysco, the global food distribution giant, suffered from a data breach, that exposed data including customer and employee data. The exposed data includes data relating to the operation of the business, customers, employees, and personal data, reads a 10-Q quarterly report filed with the U.S. SEC. This data extraction has not impacted Sysco’s operational systems and related business functions, and its service to customers continued uninterrupted. Sysco also notified federal law enforcement. The security team at Sysco added further measures as a result of the incident to guard against a similar compromise in the future.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
customer dataemployee databusiness operational datapersonal data
DATA BREACH
customer dataemployee databusiness operational datapersonal data
JANUARY 2023
815Before Incident
Breach
14 Jan 2023Sysco
Sysco Corporation

Sysco Corporation Data Breach

764After Incident
HIGH-51
SYS351072625
The California Office of the Attorney General reported a data breach involving Sysco Corporation on May 16, 2023. The breach occurred on January 14, 2023, where unauthorized access to systems potentially exposed personal information of current and former colleagues, including names and social security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesSocial Security Numbers
DATA BREACH
NamesSocial Security NumbersSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Sysco ?
?
What was Sysco's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Sysco's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Sysco's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Sysco's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Sysco's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Sysco's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Sysco ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Sysco's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?