Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Ahold Delhaize USA reported that a November 2024 cyberattack affected 2,242,521 people. But calling them all “customers” is not supported by the available reporting: the exposed files appear to have been mainly employment-related records, potentially involving current or former workers and their dependents or beneficiaries. The company reportedly said it had no indication that customer payment or pharmacy systems were compromised.
What happened
Ahold Delhaize USA, the U.S. operating unit of grocery group Ahold Delhaize, detected unauthorized access to internal U.S. business systems on November 6, 2024. Breach-notification details summarized in reporting on state filings indicate that files were obtained around November 5–6.
The company disclosed the affected-person count in late June 2025, several months after the incident. The available reports do not establish a specific reason for the interval; investigations and legal review can take time, but that general possibility does not explain this case by itself. The November attack also disrupted some retail operations, including online ordering, delivery, and certain store or pharmacy functions. Those disruptions are separate from what the later investigation identified in the accessed files. The Register reported that the INC ransomware group claimed responsibility; that is an alleged group claim, not conclusive attribution.
Who is included in the 2.24 million figure?
The reported total is 2,242,521 individuals, often rounded to 2.2 million. It should not be read as 2.24 million grocery shoppers. Coverage describes the information as primarily drawn from employment-related records, and the affected population may include current and former employees, dependents, and beneficiaries. Public reporting does not clearly break down the total by those categories.
#1 Best Overall
Ahold Delhaize USA operates several familiar grocery and logistics brands: Food Lion, Stop & Shop, Giant Food, The Giant Company, Hannaford, ADUSA Distribution, and ADUSA Transportation. A connection to one of these brands does not by itself mean a shopper’s account was included in the breach. Supermarket News reported that a Maine filing listed 95,463 affected residents; that state figure does not mean the entire population was in Maine or that everyone counted was a Hannaford customer.
What information may have been exposed?
Depending on the person, reported categories could include:
Rank #2
- Name, mailing address, email address, telephone number, and date of birth
- Social Security number
- Passport or driver’s-license number
- Bank, checking, financial, or investment-account information
- Health-insurance or medical information contained in employment records
- Workers’ compensation information and other employment-related data
The data varied by individual. The reported categories do not mean that every affected person had every type of information exposed, and exposure does not establish that the information was misused.
Were grocery payment cards or pharmacy records affected?
Current reporting says Ahold Delhaize had no indication that customer payment or pharmacy systems were compromised, and that customer credit-card numbers were not found in the affected files. BleepingComputer’s account of the disclosure makes that distinction. It does not prove that no payment-related system was touched during the wider operational incident; it means the reported breach files did not contain customer card numbers.
Rank #3
Likewise, health or medical information in an employment file can relate to benefits, insurance, or workers’ compensation. That is not the same as evidence that grocery customers’ prescription histories or pharmacy-patient databases were taken. Reports say the company had no indication that customer pharmacy systems were compromised.
What affected people should do
If you received a breach notice, follow its instructions and use the credit-monitoring and identity-protection service described there. Ahold Delhaize USA reportedly offered affected individuals two years of these services. Do not rely on a link in an unexpected email or social-media post: verify the notice and provider independently, and use the enrollment details in the official notice. Keep the notice, activation code, deadline, and contact information.
Rank #4
- Review credit reports and financial accounts. Look for unfamiliar inquiries, accounts, transactions, or changes to contact details.
- Consider a credit freeze. A freeze can restrict access to your credit file for new-credit applications. It is different from monitoring, which alerts you to certain activity after it occurs. A freeze is generally the stronger step if you are concerned about someone opening credit in your name.
- Act on exposed credentials if the notice identifies them. Change reused passwords, starting with your email account, and enable multifactor authentication where available. Use a unique password for each important account.
- Watch for identity-based scams. Be alert to unexpected credit, tax, benefits, banking, or account-verification messages. Do not give out Social Security numbers, passwords, or payment details through unsolicited links or calls.
- Check who the notice concerns. Because records may involve employees’ families, a notice could relate to a worker’s dependent or beneficiary information, not only the employee’s own records.
Credit monitoring can help flag certain activity, but it cannot prevent every form of fraud or restore a Social Security number. A credit freeze also does not secure bank accounts, tax records, or existing logins, so account reviews and cautious handling of suspicious messages remain important.
If you shop at one of the brands but received no notice
Shopping at Food Lion, Stop & Shop, Giant Food, The Giant Company, or Hannaford does not establish that you were among the affected individuals. The available reporting points mainly to employment-related records and says there was no indication that customer payment or pharmacy systems were compromised. If you have questions, contact the retailer through its official website or a number on a statement or card—not a number in a suspicious message.
Best Value
As routine precautions, review card and bank activity, use unique passwords for grocery and email accounts, and turn on multifactor authentication where offered. Treat unsolicited messages about “breach settlements,” credit monitoring, or account verification with skepticism; scammers may use a real incident to make an impersonation attempt seem credible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

