news.mlab.sh
Back to the feed
threat-intel

Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain

High
Summary

A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-linked RansomHouse claimed responsibility for the attack, which involved the theft of personal data and the publication of a portion of it on the Dark Web. The incident highlights the vulnerability of tightly-knit supply chains and the need for robust ransomware recovery practices, particularly in industries reliant on just-in-time delivery models.

A cyberattack on Nichirei, a Japan-based frozen-food supplier and logistics firm, has severely disrupted its operations, leading to curtailed shipments and warnings from Kentucky Fried Chicken franchises in Japan about potential shortages. Russia-linked ransomware group RansomHouse reportedly claimed credit for the breach, posting some Nichirei data to the Dark Web. Nichirei acknowledged the breach but has only provided limited details on the actual events, which impacted its logistics and shipping operations. The attack represents a significant risk to Japan's food supply chain, given Nichirei's role in managing a fleet of approximately 7,000 refrigerated vehicles and operating from 141 different logistics centers and warehouses, serving approximately 5,000 clients.

The incident follows a similar ransomware attack on Asahi beer giant in 2025, attributed to the Qilin ransomware group, which resulted in the leak of data on about 1.9 million people and disrupted production and shipping, cutting revenue for the company's divisions by 10% to 30% year over year. Japan has seen a concerning rise in ransomware attacks, with nearly half of all Japanese companies (46%) suffering an attack in 2025, according to the Japan Institute for the Promotion of Digital Economy and Community (JIPDEC). The National Police Agency (NPA) recorded 226 reports of ransomware attacks resulting in damage in 2025.

Nichirei confirmed that personal data had been stolen in the attack, and media outlets reported that a subset of the data has been published online. The attack underscores the interconnectedness of supply chains and the potential for a single breach to have widespread consequences, as highlighted by Collin Hogue-Spears, senior director of solution management at Black Duck, a software-security firm, who noted that "Attackers compromised one company's servers, [and] Japan's procurement model spread that compromise across the national food supply." Companies need to practice ransomware recovery, he says, emphasizing that a good backup strategy is not enough if restoration takes weeks.

Viakoo's John Gallagher added that Nichirei's decision to sever internal networks is a classic response to active encryption or lateral movement across operational subnetworks, given Japan's logistics ecosystem operates on hyper-efficient [just in time] delivery models with minimal buffer inventory. The RansomHouse ransomware group is a relatively new group, known for double-extortion attacks. Nichirei stated that it is continuing its investigation with the assistance of an external security firm and will refrain from disclosing specific details regarding the cyberattack, coordinating its response with the police and relevant authorities.

Read the full article at Dark Reading