Cyber Incident Victim: Bernard Matthews
Date:
Jan 2019
Location:
United Kingdom
Summary
A suspected cyber-attack compromised the bank account details of approximately 200 employees at a major turkey producer. The company was alerted by its bank and responded by reporting the incident to relevant authorities while implementing enhanced security measures. It stated no further impacts to affected staff had been detected following the breach. The organization employs thousands across East Anglia but confirmed only a subset of workers were impacted by this incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 22, 2019, Bernard Matthews, a Norfolk-based turkey producer employing 3,000 people across East Anglia, was alerted by its bank to a suspected cyber-attack that potentially compromised the bank account details of 200 employees. The company immediately reported the incident to relevant authorities and implemented additional security measures to contain the breach. While the exact method of intrusion and attacker identity remained unspecified in public disclosures, the compromise targeted sensitive financial information of a subset of the workforce. Bernard Matthews confirmed the incident’s scope was limited to employee banking data, with no indication of operational systems or customer information being affected. The company maintained continuous monitoring following the detection but stated no further impacts to colleagues had been observed post-response.

The breach represented a localized data security incident affecting approximately 6.7% of Bernard Matthews’ workforce, though no financial losses or fraudulent transactions were publicly reported as a direct consequence. Organizational response focused on containment through enhanced security protocols and collaboration with banking partners and law enforcement. The company did not disclose technical details regarding the attack vector, duration of unauthorized access, or specific mitigation steps beyond general references to "extra security measures." No ransomware demands, data destruction, or extended downtime to production facilities were mentioned in relation to the event. Bernard Matthews’ public communications emphasized resolution of the immediate threat while maintaining business continuity across its operations.
