America’s Food Basket Data Breach

Alleged

Ransomware claim involving America's Food Basket

Published: Sep 3, 2026 Wallstreet
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
America's Food Basket
Industry
Retail
Threat Actor
Wallstreet
Date of Incident
Sep 3, 2026

Executive Summary

America’s Food Basket, a cooperative grocery-store network operating under the America’s Food Basket and Ideal Food Basket names, has been listed as a victim on the Wallstreet ransomware group’s dark web portal as of September 3, 2026. This network serves communities across the United States through its various store locations, weekly promotions, online shopping, and delivery services, making it a significant entity within the U.S. retail landscape. In the 60 days preceding this listing, Wallstreet claimed approximately six other victims. The group’s operations appear to be exclusively within the United States, and they target organizations opportunistically across various sectors including education, healthcare, retail, manufacturing, and technology. Notable recent victims of Wallstreet include Total Education Solutions, Cedar County Memorial Hospital, T.RAD North America, and Black Hills Bentonite. The inclusion of America’s Food Basket marks the ransomware group’s first observed victim within the consumer grocery sector.

Technical Analysis

SOCRadar’s stealer-log telemetry returned no records for the domain afbasket[.]com in the queried data slice. However, a null result does not definitively confirm the absence of a compromise. The query covers a paginated sample of available logs, and it is possible that credentials may have surfaced under alternate corporate domains, through personal email aliases associated with the company, or within data feeds not included in this specific dataset. Additionally, credentials may have been used and subsequently rotated before being indexed in the queried logs, or they may not have been indexed yet. The absence of directly correlated stealer-log data does not rule out the possibility of a compromise. Infostealer-harvested credentials can be a critical vector for ransomware operations, providing threat actors with access to corporate accounts, Microsoft 365 environments, VPNs, or remote-access portals. While this specific listing on a ransomware leak site does not confirm an active intrusion or data exfiltration, it highlights a potential area of concern that warrants further investigation. The current telemetry data does not confirm that America’s Food Basket is unaffected by credential exposure. Continued monitoring of dark web and stealer-log feeds, proactive credential hygiene checks, and comprehensive reviews of password rotation and multi-factor authentication status are recommended. It is also advisable to monitor alternate corporate domains and review activity logs for Microsoft 365, VPNs, and other remote-access systems for any suspicious or unauthorized access.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.