Nichirei, one of Japan's largest frozen food manufacturers, has confirmed disruption from a cyberattack that began on July 13, 2026, with the ransomware group RansomHouse now claiming responsibility. Japanese security firm S&J reports the group posted a statement on a dark web leak site on Tuesday, alleging it had stolen internal company data. The incident knocked out cold storage operations and halted frozen food deliveries during peak summer demand.
What Happened
Starting July 13, system failures traced to the intrusion disrupted Nichirei's core logistics functions. Cold storage operations and frozen food distribution were interrupted, a significant operational hit for a company whose business depends on maintaining unbroken temperature-controlled supply chains. On Tuesday, roughly a week after the initial outage, the RansomHouse group publicly claimed responsibility via a dark web posting, asserting it had exfiltrated some of the company's internal data. Security firm S&J, which tracks ransomware activity targeting Japanese organizations, surfaced and attributed the claim.
What Was Taken
RansomHouse claims to have stolen "some internal data" from Nichirei, though the group has not yet published a detailed inventory or sample of the allegedly exfiltrated files. The specific types, volume, and sensitivity of the data have not been confirmed. RansomHouse typically operates on a double-extortion model, first encrypting victim systems and then threatening to leak stolen data unless a ransom is paid. The presence of a dark web leak-site posting is consistent with the pressure phase of that playbook, where the actor advertises the breach to force negotiation. Until the group releases proof or Nichirei completes its forensic review, the exact scope of compromised records remains unverified.
Why It Matters
This attack underscores the growing targeting of Japan's food and logistics sector by financially motivated ransomware crews. RansomHouse is the same group reportedly linked to the October 2025 attack on Japanese online retailer Askul, which likewise caused system disruptions, indicating a sustained interest in high-visibility Japanese enterprises with just-in-time operations. For companies running temperature-sensitive or time-critical supply chains, an outage is not merely an IT problem: spoiled inventory, missed deliveries, and downstream retail shortages amplify the leverage attackers hold. The disruption to cold storage during summer heightens the operational stakes and the pressure to pay quickly.
The Attack Technique
The initial access vector has not been publicly disclosed. RansomHouse has historically favored exploitation of exposed or vulnerable perimeter systems and the use of stolen credentials rather than relying exclusively on custom malware, and the group has at times positioned itself as a data-extortion operation. Based on the observed pattern in this incident, the intrusion followed the standard ransomware kill chain: gaining a foothold, moving laterally to reach production and storage-control systems, exfiltrating internal data, and deploying encryption to trigger the system failures that halted operations. Confirmation of the specific entry point awaits Nichirei's incident investigation.
What Organizations Should Do
- Segment operational technology from IT networks so that a corporate breach cannot cascade into cold storage and logistics control systems that keep perishable inventory viable.
- Harden internet-facing systems by patching VPNs, remote access gateways, and edge appliances promptly, and disabling unused external services that RansomHouse-style actors probe for initial access.
- Enforce phishing-resistant multi-factor authentication on all remote and privileged accounts to blunt credential-based entry.
- Maintain offline, immutable backups and rehearse restoration so encryption-driven outages can be reversed without paying a ransom.
- Deploy endpoint detection and monitor for data exfiltration, flagging large outbound transfers and unusual lateral movement before encryption is triggered.
- Prepare an incident response and communications plan tailored to supply-chain disruption, including predetermined steps for perishable-goods contingencies and customer notification.