Cyber Incident Victim: apetito Ltd.
Date:
Jun 2022
Location:
United Kingdom
Summary
Apetito Ltd., parent company of Wiltshire Farm Foods, experienced a cyber attack disrupting its computer systems and causing significant operational impacts. The incident halted most deliveries for several days and prevented customer communications due to inaccessible contact details, though no credit card data was compromised. The company advised affected customers to reach out directly to local depots while working to restore services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around June 26, 2022, UK-based food supplier apetito Ltd. and its subsidiary Wiltshire Farm Foods experienced a disruptive cyber attack affecting their computer systems. The incident caused severe operational disruptions across both companies, which specialize in supplying ready meals to thousands of customers in Western England, including multiple hospitals. The attack rendered critical systems inoperable, preventing the companies from processing deliveries or accessing customer contact information. This resulted in widespread delivery cancellations and delays, with the organizations publicly confirming their inability to fulfill orders for multiple days following the attack. No evidence of credit card data theft was identified, according to company statements.

The companies immediately prioritized system recovery efforts while publicly apologizing to affected customers through a formal statement. Due to the inability to access telephone numbers stored in compromised systems, Wiltshire Farm Foods advised customers expecting deliveries to proactively contact their local depots for updates. Operational impacts extended beyond customer deliveries to internal communications and logistics coordination. The organization emphasized ongoing remediation work but did not disclose technical details about the attack vector, responsible threat actors, or specific systems affected beyond general references to computer infrastructure. Recovery timelines remained unspecified in available communications, though the company committed to restoring services as rapidly as possible.
