Subway reportedly hit by LockBit ransomware - but is it half-baked speculation?

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Subway has allegedly suffered a data breach at the hands of none other than the notorious LockBit ransomware gang.

According to The Register, the ransomware-as-a-service provider added the sandwich makers to its data leak site earlier this week after one of its affiliates made away with gigabytes of sensitive data.

"We exfiltrated their SUBS internal system which includes hundreds of gigabytes of data and all financial [aspects] of the franchise, including employee salaries, franchise royalty payments, master franchise commission payments, restaurant turnovers etc," LockBit stated. "We are giving some time for them to come and protect this data, if no[t], we are open to sell to competitors."

No comment

In other words, demands were sent Subway’s way, and the affiliate that breached it is now waiting for a response.

At the same time, Subway is giving everyone the silent treatment. Maybe the company tried to keep the news quiet, and maybe it wasn’t even aware of the attack until LockBit boasted about it.

"The biggest sandwich chain is pretending that nothing happened," the group apparently said. 

Subway has allegedly told media sources it is investigating the claims of the breach. If you were wondering how it could be possible that a company wasn’t aware of a ransomware attack (given its disruptive potential) - hackers have started skipping the encryption part and moving straight to the part where they steal the data.

This is a relatively new development that started occurring in the past couple of years. Apparently, building, developing, maintaining, and deploying ransomware on the target system became too cumbersome. Also, with companies getting better at backing up their data and defending from infections, in some instances insisting on the encryptor simply isn’t worth it. Instead, the threat actors would just steal the data and demand money in exchange for not leaking it to the public. 

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
sewage water treatment
Southern Water denies claims it offered $750,000 ransom to ransomware hackers
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
Ransomware
Lee Enterprises blames cyberattack for encrypting critical systems as US newspaper outages drag on
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
MetLife denies hack after ransomware group claims attack
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI