The infamous Snatch ransomware group said it launched a major cyber attack on American food Manufacturer Kraft Heinz and listed the company on its data leak site.
On August 16, the group listed Kraft Heinz on its dark web site but did not make the listing visible until December 14. The group is yet to share data samples allegedly stolen from the company to prove its claims.
Kraft Heinz produces a variety of food products under several brands such as Kraft, Heinz, Oscar Mayer, Philadelphia and Planters. The company is one of the world’s largest food and beverage manufacturers.
Last week, a Kraft Heinz spokesperson acknowledged the Snatch ransomware group’s claims, stating that the company has launched an investigation to look into a now-decommissioned marketing website and validate Snatch’s claims, but its daily operations haven’t faced any disruptions yet.
“We are reviewing claims that a cyberattack occurred several months ago on a decommissioned marketing website hosted on an external platform, but are currently unable to verify those claims,” the spokesperson said.
“Our internal systems are operating normally, and we currently see no evidence of a broader attack,” he
added.
Kraft Heinz did not state whether the hacker group has demanded a ransom or if the attack impacted its daily operations. The ransomware attack, if the Snatch group’s claims prove to be true, will be another major attack on leading food producers in 2023.
Earlier this year, Ireland-based food production giant Dole also suffered a ransomware attack that compromised the sensitive personal information of its employees and affected its daily operations.
“In February of 2023, we were the victim of a sophisticated ransomware attack involving unauthorised access to employee information. Upon detecting the attack, we promptly took steps to contain the attack, retained the services of leading third-party cybersecurity experts, and notified law enforcement,” Dole said in an SEC filing.
Dole notified the offices of Attorney Generals of California and Maine that sensitive personal information like names, addresses, telephone numbers, driver’s licenses, Social Security numbers, passport numbers, dates of birth, and other employment-related information were compromised in the cyber attack.
The food production giant also informed the office of the Attorney General of Maine that at least 3,885 individuals were impacted in the security incident.