In July 2026, the Anubis ransomware group listed "Surtifamiliar" as a victim on its site, claiming to have exfiltrated passport data belonging to the supermarket chain's employees. This incident has not been confirmed by Surtifamiliar, government agencies, or mainstream cybersecurity firms.
Only passport data was mentioned as exposed; there is no information regarding the number of affected individuals or whether other data types like financial or medical information were compromised. No official regulatory filings or breach notifications have been issued by the company. The identity of "Surtifamiliar" as a US supermarket chain remains unconfirmed. Sources suggest it could be a fictional name, a misidentification, or a small local chain.
Details can emerge later as the situation develops, but as of July 2026, the breach lacks official verification, and no official public statements have been made by Surtifamiliar.