Comparison Overview

UNFI

VS

Suntory Holdings Limited

UNFI

313 Iron Horse Way, Providence, RI, US, 02908
Last Update: 2026-04-02
Between 650 and 699

UNFI is North America’s Premier Food Wholesaler. We transform the world of food for our associates, customers, suppliers and the families we serve every day. With deeper full store selection and compelling brands for every aisle, built on an unmatched heritage in great food and fresh thinking. And smarter food solutions, from fulfillment to insights and beyond, that help entrepreneurs and major brands alike unlock their full potential and transform their businesses – for the better. Better Food. Better Future.

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 17,121
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
2

Suntory Holdings Limited

daiba 2-3-3, Minato-ku,, JP
Last Update: 2026-03-29
Between 750 and 799

As a global leader in the beverage industry, Suntory Group aims to inspire the brilliance of life, by creating rich experiences for people, in harmony with nature. Sustained by the gifts of nature and water, the Group offers a uniquely diverse portfolio of products, from award-winning Japanese whiskies Yamazaki and Hibiki, iconic American whiskies Jim Beam and Maker's Mark, canned ready-to-drink -196 (minus one-nine-six), The Premium Malt’s beer, Japanese wine Tomi, and the world-famous Château Lagrange. Its brand collection also includes non-alcoholic favorites Orangina, Lucozade, Oasis, BOSS coffee, Suntory Tennensui water, TEA+ Oolong Tea, and V energy drink, as well as popular health and wellness product Sesamin EX. Founded as a family-owned business in 1899 in Osaka, Japan, Suntory Group has grown into a global company operating throughout the Americas, Europe, Africa, Asia and Oceania, with an annual revenue (excluding excise taxes) of $20.5 billion in 2025. Its 41,628 employees worldwide draw upon the unique blend of Japanese artisanship and global tastes to explore new product categories and markets.

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 10,553
Subsidiaries: 13
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/unfi.jpeg
UNFI
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/suntory-holdings-limited.jpeg
Suntory Holdings Limited
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
UNFI
100%
Compliance Rate
0/4 Standards Verified
Suntory Holdings Limited
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for UNFI in 2026.

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for Suntory Holdings Limited in 2026.

Incident History — UNFI (X = Date, Y = Severity)

UNFI cyber incidents detection timeline including parent company and subsidiaries

Incident History — Suntory Holdings Limited (X = Date, Y = Severity)

Suntory Holdings Limited cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/unfi.jpeg
UNFI
Incidents

Date Detected: 6/2025
Type:Cyber Attack
Attack Vector: Unknown (likely phishing, exploited vulnerabilities, or third-party compromises), Credential Stuffing (The North Face), Ransomware (implied for M&S, Co-op, United Natural Foods)
Motivation: Financial Gain (ransomware, data theft for fraud/phishing), Disruption (supply chain chaos to pressure payment), Data Exfiltration (customer PII for downstream fraud)
Blog: Blog

Date Detected: 6/2024
Type:Ransomware
Motivation: Financial Gain (Likely Ransomware), Disruption
Blog: Blog
https://images.rankiteo.com/companyimages/suntory-holdings-limited.jpeg
Suntory Holdings Limited
Incidents

Date Detected: 12/2022
Type:Cyber Attack
Attack Vector: External Hacking
Blog: Blog

FAQ

Suntory Holdings Limited company demonstrates a stronger AI Cybersecurity Score compared to UNFI company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

UNFI company has faced a higher number of disclosed cyber incidents historically compared to Suntory Holdings Limited company.

In the current year, Suntory Holdings Limited company and UNFI company have not reported any cyber incidents.

UNFI company has confirmed experiencing a ransomware attack, while Suntory Holdings Limited company has not reported such incidents publicly.

Neither Suntory Holdings Limited company nor UNFI company has reported experiencing a data breach publicly.

Both Suntory Holdings Limited company and UNFI company have reported experiencing targeted cyberattacks.

Neither UNFI company nor Suntory Holdings Limited company has reported experiencing or disclosing vulnerabilities publicly.

Neither UNFI nor Suntory Holdings Limited holds any compliance certifications.

Neither company holds any compliance certifications.

Suntory Holdings Limited company has more subsidiaries worldwide compared to UNFI company.

UNFI company employs more people globally than Suntory Holdings Limited company, reflecting its scale as a Food and Beverage Services.

Neither UNFI nor Suntory Holdings Limited holds SOC 2 Type 1 certification.

Neither UNFI nor Suntory Holdings Limited holds SOC 2 Type 2 certification.

Neither UNFI nor Suntory Holdings Limited holds ISO 27001 certification.

Neither UNFI nor Suntory Holdings Limited holds PCI DSS certification.

Neither UNFI nor Suntory Holdings Limited holds HIPAA certification.

Neither UNFI nor Suntory Holdings Limited holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unwrap() directly. That assumption is false by construction. HistoryStoreProxy::history_index() explicitly returns None for the valid HistoryStoreProxy::WithoutIndex state. when a full node is syncing or otherwise running without the history index, a remote peer can send RequestTransactionsProof or RequestTransactionReceiptsByAddress and trigger an Option::unwrap() panic on the request path. This issue has been patched in version 1.3.0.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and internal network services. This issue has been patched in version 1.5.95.

Risk Information
cvss3
Base: 8.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H