War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64

A tabletop exercise at Infosecurity Europe put ransomware, AI poisoning, and deepfake CEO videos inside a simulated supermarket attack. The blue team held the line. The red team shorted the stock anyway.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64
Share

Key points

  • Semperis ran a two-hour ransomware tabletop exercise at Infosecurity Europe, targeting fictional grocery chain BlueCart with nation-state-linked attacker group APT 64.
  • The red team entered through a logistics partner's API access, then stole loyalty card data and probed Active Directory via phishing and credential theft.
  • When the blue team refused to pay the ransom, the attackers leaked the loyalty data, seeded hacktivist rage-bait on Reddit and 4chan, and published a deepfake CEO video.
  • The red team generated thousands of false alerts to slow analysts; defenders countered with out-of-band communications.
  • The exercise carried no log files or telemetry: the point was decision-making under pressure, not detection.

What was APT 64 actually after?

The adversary group on paper, APT 64 alias Checkout Chaos, split its objectives between financial gain and reputational destruction. That hybrid motive shaped every move the red team made, which is what made it a useful scenario: pure ransomware playbooks don't account for attackers who treat the media cycle as a revenue stream.

BlueCart's crown jewel was an AI-enhanced supply chain command centre governing inventory, logistics, and store fulfilment. The red team's opening play was supply-chain compromise: find a logistics partner with trusted API access, use stolen developer credentials and weak multi-factor authentication enforcement, then pivot through over-privileged service accounts into planning and inventory systems. Loyalty card data came out the other side. Active Directory was probed via phishing and credential theft. A building-management network poorly segmented from IT offered a secondary path to disrupt heating and ventilation.

Should you worry about the deepfake angle?

Yes, and not just the video itself. The blue team refused to pay. The red team leaked the loyalty data anyway, then went further. Thousands of false alerts flooded the security operations centre. Payroll was disrupted. On Reddit and 4chan, the red team seeded rage-bait blaming AI-driven job cuts, recruiting opportunistic hacktivists. A deepfake of BlueCart's CEO, shot to look like a superyacht confession, had him celebrating layoffs as a route to higher margins. Fake delivery orders for perishable goods and sex toys were injected to generate logistical chaos.

Simon Hodgkinson, strategic advisor at Semperis, put it plainly: "Despite the motivation not being financial they did take the opportunity to make money through media manipulation and shorting stock." The deepfake and hacktivist recruitment weren't noise. They were parallel income.

We covered Infosecurity Europe 2026's programme in our preview from 28 May; the Semperis exercise was among the sessions worth watching.

Was the blue team's honeypot claim credible?

The blue team said it had corralled the attackers inside a honeypot throughout, meaning no real customer data was ever exposed. The red team disputed that. Semperis, acting as game master, declined to adjudicate.

Guido Grillenmeier, principal technologist at Semperis, was clear the exercise wasn't a technical drill. Hodgkinson's sharper point: real resilience runs on people and process. The blue team's discipline around minimal viable business continuity, deciding what to stand up first if destructive payloads deployed, is what transfers to an actual incident. The tooling is secondary.

© 2026 Threat Vectr