Updated August 5, 2026 — adding Have I Been Pwned indexing (2,691,852 accounts) and S.D. Texas employee class actions that cite the ShinyHunters Salesforce claim.
ShinyHunters claimed to have stolen more than 61 million Salesforce records from Houston-based Sysco Corporation (sysco.com) and threatened publication after a June 18, 2026 deadline (Cybernews / Daily Security Review reporting). Have I Been Pwned later listed a Sysco breach (breach date June 15, 2026; added June 28, 2026) with 2,691,852 affected accounts — a verified HIBP count that is not the same figure as the attacker’s 61M Salesforce-row claim.
Sysco still has not published a comprehensive consumer confirmation matching every public allegation; treat attacker volumes carefully and rely on HIBP / any official Sysco notice for personal exposure checks.

What ShinyHunters claimed
The group listed Sysco on its leak site on June 15, 2026, alleging:
- 61+ million records across multiple Salesforce tables
- Customer account data, restaurant operator contacts, and pricing schedules
- Employee PII and internal corporate records
Sample files circulated in threat-intelligence channels; independent verification of the full 61M dataset has not been completed publicly.
HIBP listing
| Field | Detail |
|---|---|
| HIBP name | Sysco |
| Domain | sysco.com |
| Breach date | 2026-06-15 |
| Added | 2026-06-28 |
| Pwn count | 2,691,852 (verified) |
Check personal emails at haveibeenpwned.com.
Federal class actions (S.D. Tex)
Employee / PII class complaints followed the public claim. Examples:
| Case | Docket | Filed |
|---|---|---|
| Willets v. Sysco | 4:26-cv-04926 | Jun 22, 2026 |
| Matthews v. Sysco | 4:26-cv-04854 | Jun 18, 2026 |
| Hartwell v. Sysco | 4:26-cv-04834 | Jun 17, 2026 |
| Torres v. Sysco | 4:26-cv-05469 | Jul 10, 2026 |
| Fyles v. Sysco | 4:26-cv-06213 | Aug 3, 2026 |
The Willets complaint (RECAP) alleges ShinyHunters infiltrated Sysco’s Salesforce environment and that employee PII (names, addresses, DOB, SSNs) was at risk; plaintiff states he learned of the incident through public reporting, not Sysco notice.

Second extortion headline in 2026
Qilin previously listed Sysco with a May 12 deadline and sample corporate documents. It remains unclear whether ShinyHunters and Qilin shared access or data.
Why this matters for Texas hospitality
Sysco serves restaurants, healthcare, schools, and hotels worldwide. Confirmed CRM / employee exposure fuels spoofed invoices, EDI phishing, and HR/tax fraud against Texas operators and staff.
Independent cybersecurity audit
EmailMeNow re-audit of sysco.com on August 5, 2026. 100% is the ideal.
| Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|
| sysco.com | 70% | 90% | 15% | 45% | Good |
70% public-domain score does not speak to Salesforce tenant hardening. 15% transport remains the recurring mail-path gap.
Audit link: sysco.com
Website-tech · blacklist · lookalikes · MFA
| Check | Result (Aug 5, 2026) |
|---|---|
| Website-tech | Next.js (X-Powered-By exposed); DigiCert TLS |
| Blacklist | Clear on checked mail/domain lists (CDN SPFBL notes only) |
| Cybersquat | 50+ lookalikes to review; several brand-owned redirects |
| YubiKey / open TOTP (public) | Not documented for consumer portals → Unevaluated |
Priority actions
- Check HIBP for personal / work emails; rotate Sysco portal / EDI credentials if instructed.
- Treat unsolicited Sysco account or pricing emails as suspicious.
- Watch BEC-style invoices referencing Sysco account numbers.
- Employees: monitor tax / wage theft after lawsuit headlines.
Related trackers
- ZenBusiness ShinyHunters litigation
- Hospitality & retail tracker
- Have I Been Pwned 2026
- Texas OAG YTD dashboard
- Ransomware threat landscape
- Kodak / ShinyHunters
- All trackers
Run a free audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for Salesforce access reviews and vendor incident planning.
Sources: HIBP — Sysco · CourtListener — Willets v. Sysco 4:26-cv-04926 · Daily Security Review — ShinyHunters Sysco claim · EmailMeNow audit — sysco.com