Archer-Daniels-Midland Company
Incident posture
Linked entities
- Victim
- Archer-Daniels-Midland Company
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Employees of Archer-Daniels-Midland filed a class action alleging that cybercriminals stole and posted personal identifying information to the dark web after gaining access to the company’s network. The cybercriminal group Qilin claimed responsibility for stealing names, dates of birth, addresses, Social Security numbers and driver’s license details, which the plaintiffs said could be used for fraud and identity theft. The complaint alleges the company lacked effective prevention, detection and mitigation controls, including employee training, strong passwords, multilayer security, encryption, multifactor authentication, backups and access restrictions. Plaintiffs also alleged they had not been promptly notified and sought injunctive relief, compensatory damages and punitive damages.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Archer-Daniels-Midland Co., a global agricultural supply chain manager, was hacked in mid-September 2026. A cybercriminal group known as Qilin took responsibility for accessing the company’s systems and stealing employee identification data. The stolen information included employee names, dates of birth, addresses, Social Security numbers, and drivers’ license information. After the intrusion, the data was posted to the dark web, where the plaintiffs said it could be sold to other criminals for fraud and identity theft. The exact length of time the attackers had access to the company’s network before discovery was not known, according to the complaint filed by former employee Matthew Ranney.
The incident led to a class action lawsuit filed by current and former Archer-Daniels-Midland employees. Ranney alleged that the company failed to implement basic cybersecurity controls and did not have effective means to prevent, detect, stop, or mitigate the breach. The lawsuit claimed that the company ignored Federal Trade Commission guidance and did not use standard security measures such as employee training, strong passwords, multilayer security, encryption, multifactor authentication, backup data, and limits on employee access to sensitive information. The plaintiffs said these failures allowed cybercriminals unrestricted access to employee personal identifying information. At least 100 workers were estimated to have been impacted by the breach.
At the time described in the article, Archer-Daniels-Midland had not yet begun notifying affected employees about the breach. The plaintiffs said the delay deprived employees of critical time to contact banks, family members, and credit reporting agencies. They also noted that Social Security numbers generally cannot be replaced by the federal government unless victims can show ongoing harm from active misuse. The employees said they had been required to provide personal information as a condition of employment and expected the company to maintain adequate cybersecurity protections.
The class action sought injunctive relief to protect the interests of affected workers, along with compensatory and punitive damages. The article stated that Archer-Daniels-Midland could not be reached by press time for comment on its cybersecurity practices. The reported consequences centered on exposure of employee identity data, dark web publication of that data, risk of fraud and identity theft, and legal action by affected employees.
Sources
Sources available to members: 1 source.