HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
SYSCO CORPORATION
bd_9478a567d0d14141 · schema v1 · pii pii-v1
Full breach record for SYSCO CORPORATION →Sysco Corporation notified the NH AG of a cybersecurity event where an external threat actor gained unauthorized access to systems starting Jan 14, 2023. Discovered March 5, 2023, the incident likely involved PII of employees and limited customer/supplier data. 199 NH residents were notified. Sysco engaged forensic professionals, contacted law enforcement, and offered 24 months of credit monitoring via Experian.
Leak gap clock⏱ Leak >30d10 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 72 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_090a229785805243California State AGfiled 2023-05-16Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sysco-corporation-20230516.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 16, 2023
- Raw hash
- f6e3dd61eb857605c23942daa71a1d8cfdf1d603f231f2fb0daefb718c40f10f
Reporting entity
- Name
- SYSCO CORPORATIONnorm: sysco
- Domain
- sysco.com
Victim entity
- Name
- SYSCO CORPORATIONnorm: sysco
- Domain
- sysco.com
Incident
- Discovered
- Mar 5, 2023
- Materiality determined
- Mar 31, 2023
- Notification sent
- May 5, 2023
- Affected individuals
- 199
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.