Wed 22 Jul 2026 / 15:03 ET
Kernel
Security 3 min read

Nichirei restores cold-chain operations after cyberattack claim

Japan’s largest refrigerated logistics operator says frozen food shipments should normalize this week as RansomHouse threatens to leak alleged data.

Dana Voss

By Dana Voss / Security Correspondent

Nichirei restores cold-chain operations after cyberattack claim
img: The Record

Nichirei Logistics Group is bringing its cold-chain network back online after a cyber incident disrupted food deliveries across Japan, including shipments to KFC restaurants. The company said Wednesday that affected warehouse operations and frozen food deliveries are expected to return to normal by the end of the week.

The outage hit the unglamorous machinery that keeps food retail working: refrigerated warehouses, delivery routing, and the systems that let manufacturers, supermarkets, and restaurant chains move perishable goods on schedule. Nichirei is Japan’s largest refrigerated logistics company and runs a nationwide network of about 140 refrigerated distribution centers, so a systems failure there does not stay politely contained inside IT.

Nichirei said it is still investigating the incident and has not named a culprit. The company said some affected servers contained personal information and that it had notified the people involved. Nichirei has not confirmed that data was stolen and has not given more technical detail about how the attack unfolded.

RansomHouse, an extortion group that appeared in March 2022, claimed responsibility late Tuesday by listing Nichirei on its dark web leak site. The group told Nichirei’s management to make contact and threatened to publish what it described as confidential data, projects, and documents. It did not say publicly whether it had demanded money.

RansomHouse’s usual pitch is data theft and pressure, rather than the classic ransomware routine of encrypting files and selling the key back to the victim. The group presents itself as a “force for good” that exposes weak corporate security. That branding is self-serving, as extortion branding tends to be. Cybersecurity firm Analyst1 has previously linked RansomHouse activity to Russia-aligned threat actors, including Alphv/BlackCat, LockBit 3.0, and RagnarLocker.

The operational damage was already visible before RansomHouse made its claim. KFC Japan said last week that delivery problems at a Nichirei subsidiary had caused ingredient shortages, including Original Recipe chicken. Some of KFC Japan’s more than 1,300 restaurants cut menus or reduced opening hours as a result.

By Wednesday, KFC Japan said deliveries had restarted and all of its restaurants were back to normal service. The company marked the recovery with a discount campaign for Original Chicken using the slogan “Chicken is back!” The marketing department, at least, recovered quickly.

RansomHouse has targeted Japan before. The group previously claimed an attack on Askul, a Japanese retailer, after the company reported disruption to its e-commerce operations and disclosed a breach involving customer and supplier information.

Nichirei’s incident also lands during a run of cyber disclosures from large Japanese companies. KDDI, one of Japan’s biggest telecom providers, the Japanese arm of insurer Aflac, electronics maker Nidec, and Sapporo Holdings have all reported cyberattacks in recent weeks. There is no public evidence tying those incidents together, and the attackers behind them have not been identified.

This story draws on original reporting from The Record.

More Security/

view all ↗