CSIDB logo
Incident

JBS Foods

Incident posture

Attack window
May 2021
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-01 12:16

Linked entities

Victim
JBS Foods
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2021
Discovered
Undetermined
Disclosed
Jun 2021
Resolved
Jun 2021

Summary

JBS Foods was targeted by a ransomware attack in 2021.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2021, JBS Foods, described as one of the largest meat processing companies in the world, was the target of a major ransomware attack. The attack was attributed to REvil, a Russia-based hacking group that had also been linked earlier in the year to attacks on computer manufacturers Acer and Quanta. The intrusion followed a broader pattern of high-profile ransomware incidents in 2021, including the DarkSide attack on Colonial Pipeline in late April, which had disrupted fuel supplies along the U.S. East Coast and drawn widespread attention to the vulnerability of critical infrastructure. Although government officials urged consumers not to panic-buy meat, the JBS attack raised immediate concerns about potential disruption to the food supply chain given the company's position as the world's largest meatpacker.

The operational consequences of the attack included shutdowns and disruption at JBS processing facilities, which threatened temporary shortages in meat supply across multiple regions. According to the source material, there were no major food shortages that materialized as a direct result of the incident, but the potential impact was significant enough that authorities publicly appealed for calm consumer behavior. The attack fit within a wider trend in which just six ransomware groups were reported to have breached the defenses of 292 organizations during the period, collectively taking more than $45 million in ransom payments. JBS Foods also confirmed the broader financial stakes of ransomware by becoming one of the largest known ransom payers of the year, alongside Colonial Pipeline, which paid $4.4 million in bitcoin to DarkSide.

In response to the encryption of its systems, JBS Foods engaged with cybersecurity experts and internal decision-makers to evaluate options for restoring operations and addressing the attackers' demands. On June 10, 2021, it was publicly confirmed that the company had paid the $11 million ransom demand, reportedly in bitcoin, after consulting with those cybersecurity professionals. The payment was characterized in reporting as one of the largest ransomware payments of all time. The decision to pay reflected the operational pressure the company faced and the limited alternatives available to rapidly decrypt affected systems, given the scale of disruption that had already been imposed on its processing network.

The JBS Foods incident occurred against the backdrop of sharply escalating ransomware activity in 2020 and 2021, with Harvard Business Review reporting that the amount companies paid to hackers grew by approximately 300 percent, driven in part by the rapid shift to remote work during the COVID-19 pandemic and the associated expansion of attack surfaces. The same year had seen over 600 hospitals, clinics, and other healthcare organizations impacted by 92 ransomware attacks, resulting in more than $20 billion in lost revenue, lawsuits, and ransoms paid, according to a Comparitech study cited in the source. Compared to other contemporaneous incidents, the JBS Foods ransom of $11 million exceeded the $4.4 million paid by Colonial Pipeline and Brenntag, while remaining below the $50 million demand issued by REvil against Acer and Quanta, and well under the $70 million REvil later demanded from Kaseya in July. The same REvil group responsible for the JBS attack would subsequently gain access to IT management firm Kaseya's Virtual System Administrator infrastructure, claiming to have encrypted one million systems and affecting around 50 of Kaseya's direct clients and roughly 1,000 businesses, before the FBI obtained REvil's encryption keys, allowing Kaseya to restore client infrastructure without a ransom being paid.

Sources

Sources available to members: 1 source.

CSIDB