Ransomware victim disclosure
← All victimsCedar's Mediterranean Foods, Inc.
listed as Cedars Foods · Claimed by Thegentlemen · listed 20 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileCedar's Mediterranean Foods, Inc. is America's leading hummus and falafel brand, founded in 1981 by the Hamady family in Dearborn, Michigan. The company manufactures a range of Mediterranean products including hummus, falafel, baba ghanoush, and other specialty foods, distributed nationally through major retailers (Costco, Kroger, Walmart, Whole Foods) and foodservice suppliers (US Foods, Sysco).
- Industry
- Food Manufacturing & Distribution — Mediterranean Foods
- Address
- 45 Foundation Avenue, Ward Hill, MA 01835
- Employees
- 110-140
- Founded
- 1981
Attack summary
Severity: low — No proof files, screenshots, or data samples are advertised in the leak post. No confirmation of actual data exfiltration or operational impact. Listing only.The threat actor claims to have compromised Cedar's Mediterranean Foods' systems. The leak post provides no details of what data was exfiltrated, encrypted, or the nature of the attack.
What the group claims
cedarsfoods.com zoominfo.com/c/cedars-mediterranean-foods-inc/22189641 Cedars Foods America's #1 hummus & falafel brand — a 1981-founded Dearborn, Michigan family company (the Hamady family, in the heart of the Arab-American community) that made Mediterranean food mainstream in the US. Products: hummus, falafel, baba ghanoush, taboule, dolmas, pita chips, kibbeh, tzatziki, toum — in retail formats (8–10 oz) and foodservice 10-lb boxes for US Foods, Sysco and Shamrock; clients: Costco, Kroger, Walmart, Whole Foods, Meijer — national reach from a Dearborn plant with ~110–140 staff
Sources
- Victim sitecedarsfoods.com
Source
Indexed 20 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

