Kraft Heinz investigating possible cyberattack

ID theft
Image credit: Pixabay (Image credit: Future)

Food giant Kraft Heinz is investigating after a notorious ransomware group claimed it had hit the company with a cyberattack.

In an August post to the Snatch extortion group's data leak website, made visible on December 14, claims about a Kraft Heinz breach were made. However, the group failed to back up its claims by providing any proof or screenshots, which is typically the case when a group threatens to leak a company’s data if a ransom fee is not paid.

Kraft Heinz, however, is unsure whether the claims have any credibility, and says that its online services are operating as expected.

Kraft Heinz cyberattack

In a statement to BleepingComputer, a company spokesperson said: "We are reviewing claims that a cyberattack occurred several months ago on a decommissioned marketing website hosted on an external platform, but are currently unable to verify those claims. Our internal systems are operating normally, and we currently see no evidence of a broader attack."

Previously, Snatch has used double-extortion tactics to both encrypt and threaten to leak companies’ data, demanding payment for both decryption and the promise to delete the stolen data.

The group, which has been active since around 2018, also appeared in a joint cybersecurity advisory by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) in September 2023.

It’s an advisory worth reading, as it offers 20 detailed mitigation measures that companies can take to protect themselves against such ransomware attacks.

The report notes that Snatch operates a ransomware-as-a-service (RaaS) model. The group is often observed rebooting machines into Safe Mode to evade detection by popular endpoint protection services.

Previous victims have included the Florida Department of Veterans Affairs and the South African Department of Defense. If the claims of a Kraft Heinz breach end up being true, companies like Philadelphia, Jell-O, and Lunchables could be affected.

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
sewage water treatment
Southern Water denies claims it offered $750,000 ransom to ransomware hackers
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
MetLife denies hack after ransomware group claims attack
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
ID theft
Tata Technologies confirms ransomware attack, says investigation still ongoing
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras