Avnet, a global leader in electronic component distribution and supply chain solutions, experienced a significant data breach in late September 2025, impacting its EMEA (Europe, Middle East, and Africa) operations. The breach was detected on September 26, 2025, when unauthorized access was discovered in an externally hosted cloud storage environment supporting an internal sales tool. Attackers managed to steal approximately 1.3 terabytes of compressed data, which could expand to between 7 and 12 terabytes when uncompressed. The compromised data included historical sales records, employee emails, customer contact lists, and other operational information. Avnet responded by rotating all credentials across its Azure and Databricks cloud environments to contain the breach and prevent further unauthorized activity. The company asserted that the majority of the stolen data was unreadable without access to its proprietary sales tool, which remained secure and unaffected by the incident. Despite these claims, both cybersecurity researchers and the threat actor released plaintext samples of the stolen data on dark web leak sites, revealing that some personally identifiable information (PII) such as employee emails and customer contact details were accessible. The threat actor behind the breach stated their motivation was financial, setting up a leak site to pressure Avnet into paying a ransom by publishing data samples. Avnet confirmed that the breach was limited to a single system in the EMEA region and did not disrupt its global operations. The company also stated that it had informed authorities and would be contacting impacted customers and suppliers. The incident has raised concerns about the security of technology supply chains, especially given Avnet's role as a Fortune 500 company with operations in 125 countries and annual revenues of $27 billion. The exposure of PII increases the risk of phishing, identity theft, and other malicious activities targeting both employees and customers. Avnet's prompt response in rotating credentials and securing its cloud environments was aimed at containing the breach, but questions remain about the extent of data exposure. The company has not publicly confirmed the authenticity of the leaked data samples, but the presence of plaintext information on dark web forums suggests that at least some sensitive data is accessible. The breach highlights the ongoing challenges organizations face in securing cloud-based environments and the potential impact of such incidents on global supply chains. Avnet's communication with authorities and affected parties is part of its incident response, but the long-term consequences for its reputation and customer trust are yet to be determined. The event underscores the importance of robust security controls and rapid response measures in mitigating the fallout from large-scale data breaches.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
In its public response, Avnet said the data taken in the breach was unreadable, indicating protections such as encryption or similar safeguards limited the usefulness of the stolen information. This clarification accompanied the company's breach confirmation.
Avnet disclosed that an internal sales tool was compromised in a data breach affecting company information. The incident was publicly reported in early October 2025 across multiple outlets.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.