Overview
On July 13, 2026, threat actors breached the systems of Nichirei Logistics Group — a subsidiary of Nichirei Corporation and Japan's largest refrigerated cold-chain operator. The attack shut down inbound and outbound warehouse operations across all 140 of the company's distribution centers, triggering cascading frozen food shortages that reached KFC Japan, Aeon supermarkets, Kura Sushi, and thousands of other food industry clients.
On July 22, 2026, Russia-linked extortion group RansomHouse claimed responsibility via its dark web leak site, warning that it possessed "confidential data, projects, and documents" and urging Nichirei to make contact before the information was released.
The Attacker: RansomHouse
RansomHouse is a cybercriminal extortion group that emerged in March 2022. Its model differs from traditional ransomware operators: rather than deploying file-encrypting malware, the group focuses on data theft and pure extortion — stealing sensitive data, then threatening publication unless victims comply.
| Attribute | Detail |
|---|---|
| Active since | March 2022 |
| Affiliation | Russia-linked |
| Model | Data theft + extortion (no encryption required) |
| Prior victims | AMD, Keralty Hospital (Colombia), ASKUL (Japan, 2025) |
The group's 2025 attack on ASKUL, Japan's major e-commerce and logistics company, allegedly netted 1.1 TB of data — suggesting a deliberate pattern of targeting Japanese logistics and supply-chain enterprises.
Attack Timeline
| Date | Event |
|---|---|
| July 13, 2026 | Systems compromised; Nichirei shuts down affected infrastructure |
| July 13, 2026 | Inbound/outbound cold storage and frozen food shipments halted across 140 sites |
| July 17, 2026 | Gradual restoration of operations begins |
| July 22, 2026 | RansomHouse publicly claims responsibility on dark web leak site |
| Late July 2026 | Full operational recovery expected by month-end |
Operational Impact
Nichirei Logistics Group serves approximately 5,000 corporate clients across Japan's food manufacturing, retail, and restaurant sectors. With operations frozen across all 140 distribution centers, supply disruptions cascaded rapidly down the food supply chain.
Clients Directly Affected
| Company | Impact |
|---|---|
| KFC Japan (1,300+ restaurants) | Ingredient shortages → menu restrictions, shortened hours, online ordering suspended |
| Aeon (major supermarket chain) | Frozen goods shortages; inventory later normalized |
| Kura Sushi | Shipment delays and product shortages |
| Hotto Motto | Delivery delays |
| Yayoi Ken | Delivery delays |
| TableMark | Delivery delays |
| Ezaki Glico | Shipment delays |
KFC Japan's disruption was the most visible. With over 1,300 locations dependent on Nichirei's cold-chain, the chain was forced to restrict menus, shorten operating hours, and suspend all digital ordering channels — the official app, website, delivery service integrations, and third-party delivery platforms. KFC Japan later launched a "Chicken is back!" promotional campaign featuring discounted Original Chicken to signal the end of the disruption.
What RansomHouse Claims
RansomHouse's dark web post on July 22 listed Nichirei on its victim page and urged the company to make contact to prevent release of data. The post indicated "Encrypted: July 13, 2026" — though RansomHouse's primary weapon is exfiltration, not encryption.
Nichirei has acknowledged that some affected servers contained personal information and has notified Japan's data protection authorities. However, the company has not confirmed whether data was actually exfiltrated, the scope of any such exfiltration, or whether a ransom demand has been received or paid.
No technical indicators of compromise (IOCs) or specific malware details have been publicly disclosed.
Broader Significance
This attack illustrates a critical blind spot in critical infrastructure security: cold-chain logistics companies are not traditionally considered high-value cyber targets, yet their disruption can immediately affect national food supply chains in ways that create real-world pressure on victims to comply with extortion demands.
Key takeaways for the sector:
- Food logistics is critical infrastructure. A single third-party logistics provider's outage can ripple across thousands of downstream businesses within days.
- Data-theft extortion requires no malware delivery. RansomHouse's model bypasses many traditional ransomware defenses (endpoint protection focused on malicious payloads) — the attack surface is data access and exfiltration, not encryption.
- Japan's logistics sector is a target pattern. With RansomHouse's 2025 ASKUL attack and now Nichirei, there is a demonstrated appetite for targeting Japan's supply-chain operators.
- Segmentation and offline backups are necessary but insufficient. Business continuity planning must account for scenarios where cold-chain operations cannot proceed — not just IT recovery.
References
- The Record — Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies
- The Record — Japanese food logistics giant recovers as extortion group claims cyberattack
- Dark Reading — Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
- CPO Magazine — Cyber Attack on Major Japanese Refrigerated Logistics Provider Disrupts KFC and Other Food Chains
- The Cyber Express — Nichirei Cyberattack Disrupts KFC Japan Supply Chain
- The Japan Times — Hacker group RansomHouse claims responsibility for cyberattack on Nichirei