HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTHighContained
Ahold Delhaize
bd_6c1e9546f09b05c6 · schema v1 · pii pii-v1
Full breach record for Ahold Delhaize →Ahold Delhaize USA Services, LLC notified the New Hampshire Attorney General of unauthorized access to internal U.S. business systems between Nov 5-6, 2024. An unauthorized third party obtained files containing PII, SSNs, financial account info, health info, and employment data. ~48,958 NH residents affected. Company engaged external cybersecurity experts and federal law enforcement, offered 2 years of credit monitoring.
Leak gap clock⏱ Leak >30d34 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by inc_ransom about this victim predates this filing by 76 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2d390d6ac37cd64fVermont State AGfiled 2025-06-26(5d gap)Verified
- bd_aadedba96eaafa10Delaware State AGfiled 2025-06-26(5d gap)Verified
- bd_c136e25907ccaf53Indiana State AGfiled 2025-06-26(5d gap)Verified
- bd_fb8a7c8e75597c4aSouth Carolina State AGfiled 2025-06-26(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ahold-delhaize-usa-services-20250701.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2025
- Raw hash
- 40170c392ed443d7d01efa7970a602f83bfec91cde07d1c2cbfbe79e97009145
Reporting entity
- Name
- Ahold Delhaizenorm: ahold delhaize
- Domain
- aholddelhaize.com
Victim entity
- Name
- Ahold Delhaizenorm: ahold delhaize
- Domain
- aholddelhaize.com
Incident
- Discovered
- Nov 6, 2024
- Materiality determined
- —
- Notification sent
- Jun 26, 2025
- Affected individuals
- 48,958
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 34 weeks(237 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.