Skip to content
Ransomware Attack Puts a Chill On Japanese Frozen

Ransomware Attack Puts a Chill On Japanese Frozen

Darkreading Robert Lemos July 23, 2026

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.

Nichirei, a Japan-based frozen-food supplier and logistics firm, has largely recovered after a cyberattack disrupted its operations last week, resulting in curtailed shipments and leading Kentucky Fried Chicken franchises in the country to warn of shortages.

Russia-linked ransomware group RansomHouse reportedly claimed credit for the breach earlier this week, posting some Nichirei data to the Dark Web. Nichirei acknowledged the breach but has only provided limited details on the actual events, which impacted its logistics and shipping operations.

"We are proceeding with business recovery after implementing security measures in collaboration with an external security firm," the company said in a July 22 Japanese-language statement (translated via Kagi Translate). "Regarding the warehousing and frozen food shipping operations affected by the system failure, all locations are scheduled to transition to normal operations within this week."

The incident combines the top two threats affecting Japanese companies: Ransomware and attacks targeting supply chains and subcontractors, according to an annual list published by the Information-technology Promotion Agency, part of Japan's Ministry of Economy, Trade, and Industry (METI). The cyber-risks surrounding the adoption of AI came in third — the first time that threat appeared on the list. In October 2025, Japanese beer giant Asahi suffered a ransomware attack that disrupted beer shipments for nearly two weeks , impacted business operations for two months, and required until this February to completely rebuild systems and recover data.

Nearly half of all Japanese companies (46%) have suffered a ransomware attack, according to a survey by the Japan Institute for the Promotion of Digital Economy and Community (JIPDEC). The National Police Agency (NPA) recorded 226 reports of ransomware attacks resulting in damage in 2025.

The attack on Nichirei had a direct impact on its approximately 5,000 customers, including Kentucky Fried Chicken, which warned last week that its franchises in Japan may have cut back hours. Nichirei manages a fleet of 7,000 refrigerated vehicles from 141 different logistics centers and warehouses.

The ripples of the ransomware attack demonstrates how a tightly knit supply chain can be dramatically impacted by a cybersecurity event, says Collin Hogue-Spears, senior director of solution management at Black Duck, a software-security firm.

"Attackers compromised one company's servers, [and] Japan's procurement model spread that compromise across the national food supply," he says.

Companies need to practice ransomware recovery, he says. A good backup strategy is not enough if restoration takes weeks. If prevention requires severing the network, then the company has to be able to operate offline, says John Gallagher, vice president at Viakoo, a provider of automated IoT cyber hygiene.

"Nichirei's decision to sever internal networks is a classic response to active encryption or lateral movement across operational subnetworks," he says, adding: "Japan's logistics ecosystem operates on hyper-efficient [just in time] delivery models with minimal buffer inventory. A 48-hour network freeze quickly leads to empty supermarket shelves and stock-outs at major food service chains."

Last year, the ransomware group Qilin claimed credit for the Asahi attack, which resulted in the leak of data on 1.9 million people and disrupted production and shipping to such a degree that the event cut revenue for the company's divisions by 10% to 30% year over year — depending on the subsidiary — for Q4 2025, according to a company review of the incident .

In Japan, following the passage of the Active Cyber Defense Act last year, companies must report incidents, and the government can aid in response by shutting down servers used by attackers. Yet, companies — especially suppliers that other businesses rely on — should not rely on the government nor merely follow government guidelines, if they want to recover quickly from a potential attack — they need to practice recovery, says Viakoo's Gallagher.

"Getting critical operational functions back online differs significantly from rebooting a server," he says. "Companies often resume basic shipments using manual workarounds, isolated backup servers, or air-gapped terminal setups."

The RansomHouse ransomware group is a relatively new group, known for double-extortion attacks, experts say. Nichirei confirmed that personal data had been stolen in the attack. Media outlets reported that a subset of the data has been published online .

Otherwise, it's too soon to reveal other details of the attacks, the company stated.

"We are continuing our investigation with the assistance of an external security firm," Nichirei said in its Japanese-language update on July 22. "Furthermore, as we are coordinating our response with the police and relevant authorities, we will refrain from disclosing specific details regarding the cyberattack."

Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity.

A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports.

Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major).

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Prevention at Machine Speed: Hunting Beyond Known Detections

0-Day to 10x Discovery: Security at the Speed of Mythos

When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure

Governing the Agent; Identity Security in the Age of Autonomous AI

Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything