Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Empire Company Limited, Sobeys’ parent company, reported an IT systems issue on November 7, 2022. An Alberta privacy commissioner decision later recorded that Sobeys had determined on November 4 that an unauthorized third party had encrypted multiple systems in a ransomware attack, following initial network access on October 14. Grocery stores remained open, but pharmacy and checkout-related services were disrupted. The public record does not establish that all potentially affected personal information was stolen.

What happened in the Sobeys ransomware attack?

The incident affected Sobeys operations and affiliated services. The dates differ because the company’s public announcement and the regulator’s later account describe different stages of the event.

Date What the record says
October 14, 2022 The Alberta privacy commissioner’s decision concerning Sobeys Capital records the reported investigation finding that an employee downloaded and executed a file sent in connection with a phishing attempt, providing initial network access.
November 3, 2022 The decision says Sobeys became aware of a potential IT issue.
November 4, 2022 Sobeys determined that multiple systems had been encrypted by an unauthorized third party in a ransomware attack, according to the Alberta decision.
November 7, 2022 Empire publicly reported an IT systems issue. It said grocery stores remained open without significant disruption, while some in-store services were intermittent and some pharmacies had technical difficulties fulfilling prescriptions. Empire’s November 7, 2022 announcement quoted Chief Operating Officer Pierre St-Laurent: “At Sobeys, exceeding the needs of our customers is always our top priority. Our sole focus right now is on getting this problem rectified and we will provide further updates as relevant information becomes available.”

The October and November incident details are from the Office of the Information and Privacy Commissioner of Alberta’s February 2, 2023 decision P2023-ND-007 concerning Sobeys Capital Incorporated. The public record cited here does not include a complete technical forensic report.

Were Sobeys pharmacies and stores affected?

Empire’s public announcement said its grocery stores stayed open without significant disruption at that point. The company’s fiscal 2023 second-quarter reporting, published December 15, 2022, gives a fuller account of temporary service effects:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
  • Bundle: 4 locks + 1 key.
  • Easy to Use: It can be installed by hand.
  • All-Purpose Key: A common key can be used to unlock 9 different products within the Essential series.
  • Pharmacy services were shut down for four days.
  • Self-checkouts, gift cards and Scene+ point redemption were affected for approximately one week.
  • Some product availability was temporarily affected, but Empire said its retail network operated with little disruption and supply chains had no disruption.

Empire said it activated incident-response and business-continuity plans, brought in outside cybersecurity specialists, isolated the source and took preventive measures that included shutting down some systems. It described a controlled, phased restoration and the use of workarounds to support continuity of supply chain, product availability, costing and retail pricing. These are the company’s reported response and operational effects.

Was customer or employee data stolen?

The available official records do not support a blanket claim that all affected personal information was stolen. They also do not establish that no information was accessed. The distinction is between what the investigation had found and what the regulator said could not be ruled out.

In its February 2, 2023 Sobeys Capital decision, the Alberta privacy commissioner recorded the company’s report that its forensic investigation had found no evidence of actual access to or exfiltration of personal information from impacted systems. The company could not rule out access to or exfiltration of certain personal information. The commissioner concluded that the intrusion and possibility of exfiltration created a real risk of significant harm, even without evidence of actual misuse or public posting, and required notification of affected Alberta individuals.

Sobeys Capital: affected Alberta employees

Decision P2023-ND-007 records approximately 115,175 affected Alberta employees. Information potentially involved included names, email and residential addresses, full or partial Social Insurance Numbers or other government identification, bank account numbers, and employment information. The categories were potentially involved; the decision does not say every listed field was taken for every person.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed Health Care Services: a separate affected population

A separate February 2, 2023 decision, P2023-ND-008, concerns Managed Health Care Services, Inc. (MHCSI), a benefits-administration affiliate reported by Sobeys Capital. It records approximately 172,872 affected Alberta individuals. This is a separate population from the Sobeys Capital employee count.

For one affected group, the MHCSI decision lists name, date of birth, address, email and benefits plan identification numbers. For another, it also lists benefits claim details—including drug name, dosage, diagnosis and treatment—along with Social Insurance Numbers, government identification and dependent information. The commissioner likewise found a real risk of significant harm and required notification. The decision’s listed categories should not be read as proof that every data type applied to every individual.

What the company said about notifications

Sobeys’ fiscal 2023 sustainability report says potentially impacted individuals were notified in March 2023. The report says those notifications stated that the company had seen no evidence that personal data was accessed or removed from its servers. That is a later company statement about the evidence found; it does not reverse the regulator’s earlier conclusion that access or exfiltration could not be ruled out and that notification was required.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How much did the ransomware attack cost Empire?

Empire’s earnings-impact estimates changed as the company reported results over time. They cover net earnings, not a measure of stolen data or outage duration alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reporting date Empire’s reported estimate What it covered
December 15, 2022 Approximately $25 million, net of insurance recoveries Initial estimate of the impact on fiscal 2023 annual net earnings, reported with Empire’s fiscal 2023 second-quarter results.
June 2023 At least $15 million Fiscal 2023 net earnings impact attributed to temporary loss of advanced planning, promotion and fresh-item-management tools; temporary pharmacy closures; and customers’ inability to redeem gift cards and loyalty points.
June 2023 Approximately $32 million over fiscal 2023 and fiscal 2024, net of estimated insurance recoveries Empire’s later estimate of the final net earnings impact, reported with its fourth-quarter and fiscal 2023 results.

The approximately $25 million figure was an initial estimate; the approximately $32 million figure was the later estimate for the combined fiscal 2023 and fiscal 2024 impact. They were reported at different times and describe different periods or components, rather than competing final measurements of a data breach.

What Empire said about its cybersecurity program

In its fiscal 2023 sustainability report, Sobeys described a three-year cybersecurity roadmap and a program that included layered protection, monitoring, endpoint detection and response, cloud security controls, threat hunting, threat intelligence, vulnerability management and security risk assessments. This is the company’s description of its program as of fiscal 2023; it is not independent assurance, evidence about present-day controls, or an explanation of why the incident occurred.

Quick Recap

Bestseller No. 1
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Bundle: 4 locks + 1 key.; Easy to Use: It can be installed by hand.
$34.82

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.