Employees sue global agribusiness following criminal data breach

Employees sue global agribusiness following criminal data breach

The workers accuse Archer-Daniels-Midland of failing to implement basic cybersecurity measures, allowing employees' Social Security numbers and other personal data to be posted to the dark web.(CN) — Employees of Archer-Daniels-Midland Co., a global agricultural supply chain manager, filed a class action against the company after cybercriminals stole employee identification data and posted it to the dark web.“It is unknown for precisely how long the cybercriminals had access to defendant’s network before the breach was discovered,” Matthew Ranney, a former employee, says in the complaint. “In other words, defendant had no effective means to prevent, detect, stop or mitigate breaches of its systems — thereby allowing cybercriminals unrestricted access to its employees’ personal identifying information."The agriculture company was hacked last Tuesday, and the lawsuit was filed just three days later.A notorious cybercriminal group called “Qilin” took responsibility for hacking into the company’s system and stealing employee data including names, dates of birth, addresses, Social Security numbers and drivers’ licenses.The data was posted to the dark web, or an unindexed layer of the internet that requires special software to access, where the class claims it will be sold to other criminals for use in fraud and identify theft.According to Ranney, who represents a class of current and former employees, the agriculture company has yet to begin notifying them of the breach.On average, it takes three months for consumers to discover their identity has been stolen and used, and it takes some individuals up to three years to learn that information, according to the plaintiffs.By not informing them immediately of the breach, either because it had not yet noticed or for some other reason, Ranney says the agriculture company deprived its employees of critical days during which they could notify banks, family members and credit reporting agencies.Social Security numbers cannot be replaced by the federal government unless victims can demonstrate ongoing harm from active misuse of their number, he added.The employees claim the data breach could have been prevented by proper planning and thorough security measures. The agribusiness, they say, ignored guidelines set by the Federal Trade Commission and failed to implement standard security measures such as employee training, strong passwords, multilayer security, encryption, multifactor authentication, backup data and limiting which employees can access sensitive data.Without those security measures, the company opened the door to criminals and directly caused the data breach, according to the class.The class members were required to provide their personal information to the company as a condition of employment, with the expectation the company had adequate cybersecurity measures.“Instead of providing a reasonable level of security that would have prevented the data breach, defendant instead calculated to avoid its data security obligations at the expense of plaintiff and class members by utilizing cheaper, ineffective security measures,” Ranney said.He estimates at least 100 workers were impacted by the data breach. The class is asking the court for injunctive relief to protect its interests as well as compensatory and punitive damages.The Archer-Daniels-Midland Company partners with farmers to purchase and transport crops from areas of supply to areas of demand, according to its website. Some of the company’s products include artificial colors used in mass food production, plant-based proteins, alternative sweeteners and bulk beans. It also makes feeds and macro ingredients for animal nutrition.In the second quarter of 2026, the company reported $1.1 billion in earnings before income taxes. Compared to the prior year quarter earnings of $279 million, the company is rapidly growing.Much of that growth came from margin expansion across the agriculture services and oilseeds section of the company, according to a press release.The company could not be reached by press time for comment on its cybersecurity practices.Subscribe to our free newslettersOur weekly newsletter Closing Arguments offers the latest about ongoing trials, major litigation and rulings in courthouses around the U.S. and the world, while the monthly Under the Lights dishes the legal dirt from Hollywood, sports, Big Tech and the arts.Additional Reads

Original Source

Read the full article at Courthousenews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.