Ransomware Hit a Japanese Frozen-Food Giant and KFC Felt It

A cyberattack on Nichirei, one of Japan's biggest cold-chain logistics companies, froze shipments across the country, left KFC franchises warning of shortages, and put a spotlight on how fragile food supply chains really are.

ThreatVectr Newsdesk· 4 min read
A darkened computer server room with ominous lighting, showcasing advanced digital security tools in action, emphasizing cybersecurity themes
Share

Key points

  • Ransomware, which is malicious software that locks a company's computer systems until a payment is made, struck Nichirei's logistics network in mid-July 2025, disrupting deliveries across Japan.
  • The Russia-linked criminal group RansomHouse claimed responsibility and published some stolen Nichirei data online, including personal information the company confirmed had been taken.
  • Nichirei operates around 7,000 refrigerated trucks from 141 warehouses and serves roughly 5,000 customers, including Kentucky Fried Chicken franchises across Japan.
  • Japan's National Police Agency recorded 226 ransomware attacks causing damage in 2025, and a separate industry survey found 46 percent of Japanese companies have been hit at least once.
  • Nichirei said on 22 July that all affected warehouse and shipping locations were expected to return to normal operations by the end of that week.

Nichirei ships frozen food. Chicken nuggets, pre-made meals, cold cuts. The kind of thing that gets from a warehouse to a fast-food kitchen in a matter of hours, with no room for delay. When criminals broke into the company's computer systems last week, that precision collapsed.

Kentucky Fried Chicken franchises in Japan warned customers they might see reduced hours. Supermarket shelves risked going bare. One breach, one company, and the consequences fanned out across the national food supply.

How did this happen?

A criminal group called RansomHouse broke into Nichirei's internal network, encrypted its systems and stole data. RansomHouse is relatively new and known for what security researchers call "double extortion": they lock your files AND threaten to publish stolen data unless you pay up. Some of that data has already appeared on the dark web, an area of the internet not accessible through normal browsers, where stolen information is regularly bought and sold.

Nichirei confirmed the breach and the data theft in a 22 July statement. The company cut its internal network connections, a standard emergency response when attackers are actively spreading through a system, and brought in an external security firm. It is co-ordinating with Japanese police.

The failure mode here is textbook. Japan's food logistics sector runs on just-in-time delivery: goods move in tight windows with almost no spare stock sitting in reserve. A 48-hour network shutdown does not just inconvenience a warehouse manager. It empties shelves.

Should customers be worried?

If you ate at a KFC in Japan recently and wondered why something was off the menu, now you know why. For anyone whose personal data sits in a Nichirei system, the honest answer is: watch your inbox. When stolen personal data gets published, criminals use it for phishing, where they send convincing fake emails to trick people into handing over passwords or financial details. If you receive unexpected emails claiming to be from a company you deal with, do not click links inside them.

Key fact Detail
Attacked company Nichirei (Japan)
Attack type Ransomware plus data theft
Criminal group RansomHouse
Customers affected Approximately 5,000
Refrigerated vehicles Around 7,000
Breach confirmed 22 July 2025

This is not Japan's first rodeo. In October 2024, beer giant Asahi suffered a ransomware attack by a group called Qilin. That attack disrupted beer production for nearly two weeks, exposed data on about 1.9 million people, and cut revenue by 10 to 30 percent across Asahi subsidiaries in the fourth quarter. Full recovery took until February 2025.

In practice, the pattern is always the same. A supplier gets hit. The supplier's customers find out when goods stop arriving. The post-mortem will say backups existed but restoration took too long, and no one had rehearsed operating offline.

Japan passed the Active Cyber Defense Act last year, which now requires companies to report incidents and lets the government help shut down attacker infrastructure. Good. But legislation does not restore a frozen-food warehouse at 2 a.m. Drilled recovery plans do.

If your business depends on a supplier's network staying up, that supplier's security posture is your problem too.

© 2026 Threat Vectr