Nichirei trucks
Trucks from Nichirei's Cold Express line. Image: Nichirei Logistics Group

Japanese food logistics giant recovers as extortion group claims cyberattack

Japan's largest refrigerated logistics company is gradually restoring operations after a cyberattack disrupted food deliveries nationwide, while the cybercrime group RansomHouse has claimed responsibility and threatened to leak stolen data.

Nichirei Logistics Group said Wednesday that it expects warehouse operations and frozen food shipments affected by last week's system failures to return to normal by the end of the week. 

The company said it continues to investigate the incident and has not attributed it to any specific threat actor.

Late Tuesday, RansomHouse posted Nichirei's name on its dark web leak site, claiming responsibility for the attack and urging the company to make contact to prevent the release of what it described as "confidential data, projects and documents."

"Dear management of Nichirei, we were waiting for you for quite some time, but it seems that your IT department decided to conceal the incident," the group wrote. It did not disclose whether it had issued a ransom demand.

Nichirei has not commented on the hackers' allegations and did not immediately respond to a request for comment.

The company said some of the affected servers contained personal information and that it had notified the individuals concerned. It did not confirm whether any data had been stolen or provide additional details about the attack.

The cyberattack disrupted operations across Nichirei's nationwide network of about 140 refrigerated distribution centers, affecting food manufacturers, supermarket chains and restaurant operators that rely on the company's logistics services.

Among the companies affected was fast-food chain KFC Japan, which said last week that disrupted deliveries from a Nichirei subsidiary caused shortages of ingredients, including its signature Original Recipe chicken, forcing some of its more than 1,300 restaurants to reduce menus and shorten operating hours.

KFC Japan said Wednesday that deliveries had resumed and all restaurants had returned to normal operations. To mark the recovery, the company launched a promotional campaign offering discounted Original Chicken under the slogan "Chicken is back!"

RansomHouse, which emerged in March 2022, is known for directly extorting victims.. Rather than encrypting data, the group threatens to publicly release information it claims to have stolen. It calls itself a "force for good" and says it exposes security weaknesses in companies. Cybersecurity researchers have previously linked RansomHouse to Russia-aligned threat actors, including Alphv/BlackCat, LockBit 3.0 and RagnarLocker.

The group previously claimed responsibility for an attack on Japanese retailer Askul that disrupted its e-commerce operations and prompted the company to disclose a breach affecting customer and supplier information.

Several other major Japanese companies across a range of industries have disclosed cyberattacks in recent weeks, including one of Japan's largest telecommunications providers, KDDI, the Japanese unit of insurer Aflac, electronics manufacturer Nidec and brewer Sapporo Holdings. There is no indication that the incidents are linked, and the threat actors behind them remain unknown.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.