ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Delaware North data breach compromised customers' driver's licences and state IDs

Global food service and hospitality company Delaware North said it experienced a data security incident in January that compromised the personal details of thousands of customers.

 

The Buffalo, New York-headquartered company said the data security incident took place on January 27, 2026, when a threat actor compromised an employee’s Microsoft account to gain access to its internal systems.

 

The company announced the data breach incident in breach notification reports filed with the offices of multiple Attorneys General in the US, including in Texas, New Hampshire and Maine.

 

It said that the security incident was discovered on January 28, following which it promptly secured the compromised account and launched and investigation to determine the nature and scope of the unauthorised activity.

 

The investigation revealed that a threat actor used the compromised Microsoft account to access Delaware North’s internal systems and made copies of certain files that contained the personal information of the company’s customers.

 

The compromised information included customers’ names, driver’s licence numbers and state-issued identification numbers. Delaware North, which employs over 55,000 people worldwide and has over $3.2 billion in annual revenues, said the data breach incident affected 1,133 New Hampshire residents and 132 residents of the state of Maine.

 

The company did not state in its letters to affected customers if it had identified the threat actor who was behind the cyber attack or if it had received a ransom note from the threat actor.

 

"We encourage you to remain vigilant by reviewing your financial account statements and credit reports for any unauthorised activity. If you see unauthorised charges or activity, please contact your financial institution immediately," it said.

 

Delaware North is offering complimentary credit and identity monitoring services through Kroll to all affected residents, including credit monitoring, fraud consultation and identity theft restoration services.

 

At the time of reporting, the cyber attack had not been claimed by any individual threat actor or cyber crime group. However, several class action law firms across the US have latched on to the incident, advising affected customers to pursue possible class action against the company to claim compensation.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543