
Multinational food retail conglomerate Ahold Delhaize has confirmed that data was stolen from its U.S. business systems during a cyberattack that occurred in November 2024. The confirmation comes after the ransomware group INC Ransom claimed responsibility for the breach and listed the company on its dark web data leak site.
"Based on our investigation to date, certain files were taken from some of our internal U.S. business systems," a spokesperson for Ahold Delhaize told BleepingComputer. The company has not yet disclosed the specific nature or scope of the stolen information, but emphasized that its teams have been working diligently to assess the extent of the breach.
Ahold Delhaize, which operates nearly 8,000 stores across Europe and the United States under banners such as Food Lion, Stop & Shop, Giant Food, and Hannaford, is one of the largest food retailers globally, with annual revenues of around $100 billion and a workforce exceeding 410,000 employees.
The cyberattack was initially disclosed on November 8, 2024, when Ahold Delhaize reported a cybersecurity incident that required shutting down some IT systems as a precaution. At the time, the company acknowledged that the incident had disrupted certain services, including some pharmacies and e-commerce operations across its U.S. brands.
Now, with the emergence of Ahold Delhaize’s name on INC Ransom’s extortion site, and the publication of sample documents allegedly stolen from the retailer, the breach appears to have had more serious implications. When asked if ransomware played a role in the attack, the company declined to comment on the involvement of any specific threat actors or malware.
The company has assured that the investigation is still ongoing, and that it is working closely with law enforcement. "If we determine that personal data was impacted, we will notify affected individuals as appropriate. In addition, we have notified and updated law enforcement," the spokesperson added.
Despite the incident, Ahold Delhaize emphasized that all stores and e-commerce platforms remain operational. "Our stores and online services are open and serving customers. There is no disruption to our retail operations," the company confirmed.
INC Ransom has been actively targeting U.S.-based organizations, with cybersecurity researchers tracking one of its members—known as "Vanilla Tempest" by Microsoft—as being responsible for several recent high-profile attacks. The group most recently claimed responsibility for a data breach at the State Bar of Texas, where sensitive information of over 100,000 members was allegedly compromised.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543