Supply chain β›“ Supply Chain

Sobeys Third-Party Breach (December 2022)

πŸ“… 2022-12-01 🏒 Empire Co.
Primary Source β†—

Incident Details

Inside the turmoil at Sobeys-owned stores after ransomware attack | CBC News. Employees of Empire Co., the parent company of Sobeys, have begun to speak out about the turmoil unfolding inside the grocery chain since a ransomware attack began plaguing its computer systems earlier this month. Workers from across the country say some stores have run short of items because orders cannot be placed as usual, while at others, food that had gone bad initially either piled up or was frozen because it couldn’t be removed from the inventory system. Pharmacies were unable to fill new prescriptions for a week, customers cannot redeem loyalty points or use gift cards, and staff were concerned last week they wouldn’t get paid because the payroll system is down. Third-party company: Empire Co..

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Empire Co.
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2022-12-01 Breach occurred
  2. 2022-11-15 Publicly disclosed