Back to news
Cybersecurity Alert
June 22, 2026 by EmailMeNow IT Consulting

Sysco: ShinyHunters 61M Salesforce Claim, HIBP 2.7M, and S.D. Tex Employee Class Actions

Updated Aug 2026: ShinyHunters claimed 61M Sysco Salesforce records; HIBP lists 2,691,852 accounts; S.D. Tex suits include Willets 4:26-cv-04926. Audit: sysco.com 70% (ideal 100%).

Source: HIBP · CourtListener · Cybernews

NewsData BreachShinyHuntersSalesforceTexasClass ActionCybersecurityExtortion
ShinyHunters claims Sysco Salesforce data breach

Updated August 5, 2026 — adding Have I Been Pwned indexing (2,691,852 accounts) and S.D. Texas employee class actions that cite the ShinyHunters Salesforce claim.

ShinyHunters claimed to have stolen more than 61 million Salesforce records from Houston-based Sysco Corporation (sysco.com) and threatened publication after a June 18, 2026 deadline (Cybernews / Daily Security Review reporting). Have I Been Pwned later listed a Sysco breach (breach date June 15, 2026; added June 28, 2026) with 2,691,852 affected accounts — a verified HIBP count that is not the same figure as the attacker’s 61M Salesforce-row claim.

Sysco still has not published a comprehensive consumer confirmation matching every public allegation; treat attacker volumes carefully and rely on HIBP / any official Sysco notice for personal exposure checks.

ShinyHunters claims Sysco Salesforce data breach

What ShinyHunters claimed

The group listed Sysco on its leak site on June 15, 2026, alleging:

  • 61+ million records across multiple Salesforce tables
  • Customer account data, restaurant operator contacts, and pricing schedules
  • Employee PII and internal corporate records

Sample files circulated in threat-intelligence channels; independent verification of the full 61M dataset has not been completed publicly.

HIBP listing

FieldDetail
HIBP nameSysco
Domainsysco.com
Breach date2026-06-15
Added2026-06-28
Pwn count2,691,852 (verified)

Check personal emails at haveibeenpwned.com.

Federal class actions (S.D. Tex)

Employee / PII class complaints followed the public claim. Examples:

CaseDocketFiled
Willets v. Sysco4:26-cv-04926Jun 22, 2026
Matthews v. Sysco4:26-cv-04854Jun 18, 2026
Hartwell v. Sysco4:26-cv-04834Jun 17, 2026
Torres v. Sysco4:26-cv-05469Jul 10, 2026
Fyles v. Sysco4:26-cv-06213Aug 3, 2026

The Willets complaint (RECAP) alleges ShinyHunters infiltrated Sysco’s Salesforce environment and that employee PII (names, addresses, DOB, SSNs) was at risk; plaintiff states he learned of the incident through public reporting, not Sysco notice.

Sysco HIBP listing and S.D. Tex class action filings

Second extortion headline in 2026

Qilin previously listed Sysco with a May 12 deadline and sample corporate documents. It remains unclear whether ShinyHunters and Qilin shared access or data.

Why this matters for Texas hospitality

Sysco serves restaurants, healthcare, schools, and hotels worldwide. Confirmed CRM / employee exposure fuels spoofed invoices, EDI phishing, and HR/tax fraud against Texas operators and staff.

Independent cybersecurity audit

EmailMeNow re-audit of sysco.com on August 5, 2026. 100% is the ideal.

DomainOverallIdentityTransportWebsiteRisk
sysco.com70%90%15%45%Good

70% public-domain score does not speak to Salesforce tenant hardening. 15% transport remains the recurring mail-path gap.

Audit link: sysco.com

Website-tech · blacklist · lookalikes · MFA

CheckResult (Aug 5, 2026)
Website-techNext.js (X-Powered-By exposed); DigiCert TLS
BlacklistClear on checked mail/domain lists (CDN SPFBL notes only)
Cybersquat50+ lookalikes to review; several brand-owned redirects
YubiKey / open TOTP (public)Not documented for consumer portals → Unevaluated

Priority actions

  • Check HIBP for personal / work emails; rotate Sysco portal / EDI credentials if instructed.
  • Treat unsolicited Sysco account or pricing emails as suspicious.
  • Watch BEC-style invoices referencing Sysco account numbers.
  • Employees: monitor tax / wage theft after lawsuit headlines.

Run a free audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for Salesforce access reviews and vendor incident planning.


Sources: HIBP — Sysco · CourtListener — Willets v. Sysco 4:26-cv-04926 · Daily Security Review — ShinyHunters Sysco claim · EmailMeNow audit — sysco.com