Nichirei
Incident posture
Timeline
Summary
Nichirei, a Japanese frozen food and logistics provider, suffered a cyberattack that disrupted its refrigerated warehouses and shipment operations, affecting thousands of customers including major restaurant chains such as KFC Japan. The attack led to system outages that halted inbound and outbound logistics, caused ingredient shortages and reduced services at downstream businesses, and prompted the company to isolate affected networks while working with external security experts to restore operations. During the investigation, the company confirmed that some compromised servers contained personal information and reported the incident to data protection authorities, though it has not disclosed the full scope of any data exfiltration. A ransomware‑linked extortion group claimed responsibility via a dark web leak site, asserting theft of confidential data, while the company noted it was withholding technical details to prevent further damage and anticipated a gradual return to normal service.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 13, 2026, Nichirei detected system failures and confirmed that its servers had been subject to a cyberattack. The company immediately established an emergency response headquarters and began investigating with an external cybersecurity firm while cooperating with police and authorities. To contain the attack, Nichirei disconnected its group systems on July 13, which disrupted refrigerated warehouse operations and frozen food shipments. The disruption affected approximately 140 distribution centers and a fleet of about 7,000 refrigerated vehicles serving roughly 5,000 customers across Japan. Major clients such as Kentucky Fried Chicken Japan reported ingredient shortages, reduced menus, shortened opening hours and temporary closures at over 1,300 restaurants due to delayed deliveries. Other businesses including supermarket chains Aeon, restaurant operators Hotto Motto and Yayoi Ken, conveyor‑belt sushi chain Kura Sushi and frozen food manufacturer TableMark also experienced product shortages and delivery delays.
On July 22, 2026, the extortion group RansomHouse claimed responsibility for the attack via its dark web leak site, stating it had exfiltrated confidential data and threatening to release it unless contacted by Nichirei. Nichirei acknowledged the breach, confirmed that some affected servers contained personal information and notified the individuals concerned, while also submitting an initial report to Japan's Personal Information Protection Commission. The company did not disclose the specific type or volume of data exfiltrated and said no evidence indicated that data had been encrypted or destroyed; the primary impact was operational disruption coupled with the threat of data exposure. Nichirei began gradually restoring affected operations on July 17 after implementing security measures with the external specialist, and expected all locations to return to normal operations by the end of July 2026.
The firm continued to assess the financial impact of the incident while planning to release its first‑quarter 2026 financial results on August 7 as scheduled. For the fiscal year ended March 2026, Nichirei reported net sales of Y716.14 billion, operating profit of Y38.99 billion and profit attributable to owners of parent of Y27.33 billion, and had forecast net sales of Y609.40 billion for the nine‑month transition period ending December 2026 as it shifted its year‑end from March to December.
Sources
Sources available to members: 8 sources.