On March 25, 2026, Good Food Store experienced a ransomware attack claimed by the LockBit 3.0 group. This attack led to the exfiltration of approximately 4 terabytes of data and the encryption and wiping of systems, which forced a multi-day shutdown of 12 store locations and online operations. The company posted an official statement on March 28, 2026, on its website acknowledging a cybersecurity incident that impacted internal systems.
Good Food Store reported that 1.2 million individuals were affected, including customers, employees, and vendors. The data types exposed include names, addresses, email addresses, phone numbers, partial credit/debit card numbers (last 4 digits), bank account details for employees with direct deposit, and Social Security Numbers (SSNs) for approximately 45,000 current and former employees. Medical data was not compromised. Additional data such as purchase histories, loyalty points data, internal emails, and vendor contracts were also exfiltrated.
Good Food Store began mailing notification letters on March 30, 2026, and also sent email notifications to individuals whose SSNs were not involved. The company filed notice with the Montana Attorney General on March 29, 2026, under state data breach notification laws. As of March 31, 2026, details about affected individuals and the scope of the breach continue to emerge, and further notifications or regulatory actions may occur.