WinnDixie.jpg

TAMPA – A Florida man alleges supermarket chain Winn-Dixie failed to take precautions to keep his and others’ private information secure.

Plaintiff George Aretino of Hudson, Florida, filed his class action complaint in U.S. District Court for the Middle District of Florida.

In his 33-page filing, Aretino alleges defendant The Winn-Dixie Company LLC’s “inadequate digital security and notice process” exposed his and class members’ private information to criminals.

According to Aretino’s complaint, on Aug. 3, 2026, Ransomware.live, a dark web monitoring service, detected that the cybercriminal threat group Anubis had claimed responsibility for an attack on Winn-Dixie’s systems in a post published to Anubis’ dark web leak site.

“Anubis claims to be in possession of Defendant’s internal documents and may have acquired personal information belonging to current and former employees,” the filing states.

Such information includes names, contact information, and other “sensitive” personal information belonging to current and former employees, the lawsuit claims.

Aretino alleges that as of his filing, Winn-Dixie has not confirmed the data breach.

He argues that Jacksonville-based Winn-Dixie had an obligation to keep his and others’ personal information “confidential, safe, secure, and protected.”

“Plaintiff’s claims arise from Defendant’s failure to properly secure and safeguard Private Information that was entrusted to it, and its accompanying responsibility to store and transfer that information,” the complaint states.

Aretino accuses the grocery chain of negligence, negligence per se, unjust enrichment, breach of implied contract, and breach of confidence.

“Plaintiff and Class Members have lost the ability to control their Private Information and are subject to an increased risk of identity theft,” the complaint states.

According to his filing, stolen private information is often trafficked on the “dark web,” a heavily encrypted part of the Internet that is not accessible via traditional search engines.

Law enforcement has difficulty policing the “dark web” due to this encryption, which allows users and criminals to conceal their identities and online activity.

For example, Aretino claims personal information can be sold at a price ranging from $40 to $200, and bank details have a price range of $50 to $200.

Criminals, he alleges, also can purchase access to entire company data breaches for $900 to $4,500.

“The FTC directs businesses to use an intrusion detection system to expose a breach as soon as it occurs, monitor activity for attempted hacks, and have an immediate response plan if a breach occurs,” the complaint states.

“Immediate notification of a data breach is critical so that those impacted can take measures to protect themselves.”

Winn-Dixie, Aretino contends, failed to do any of the above.

As a result, he alleges class members have suffered and will continue to suffer financial losses caused by the misuse of their private information; lost time associated with detecting and preventing identity theft; and the theft of their personal and financial information.

He alleges he has already spent “several hours” researching the breach, reviewing his accounts, monitoring his credit reports and engaging in other “mitigation efforts.”

“This is valuable time that Plaintiff Aretino would have spent on other activities, including but not limited to work and/or recreation,” the complaint notes.

“As a consequence of and following the Data Breach, Plaintiff Aretino has experienced a significant uptick in spam calls, messages, and emails.”

He estimates the class has thousands of class members, if not more, and the amount in controversy exceeds $5 million.

He seeks damages, pre-judgment interest, attorney fees and litigation expenses.

Gold Law in Miami Beach is representing Aretino in the action.

Judge John L. Badalamenti for the Middle District of Florida has been assigned the case.

More News