Nichirei — RansomHouse ransomware halts Japan's largest frozen-food cold-chain network
RansomHouse-claimed ransomware disrupted Nichirei, Japan's largest frozen-food and cold-chain logistics group, for over a week, curtailing shipments and triggering KFC Japan and Glico supply shortages.
- Target
- Nichirei — RansomHouse ransomware halts Japan's largest frozen-food cold-chain network
- Date public
- 22 July 2026
- Sector
- Consumer Goods
- Attack type
- Ransomware
- Threat actor
- RansomHouse
- Severity
- High
- Region
- Japan
Nichirei Corporation, Japan’s largest frozen-food producer and cold-storage logistics group, began experiencing system failures on 13 July 2026 that disrupted operations across its refrigerated warehousing and frozen-food delivery network. Incoming and outgoing shipments at refrigerated warehouses run by Nichirei group companies were interrupted, and frozen-food deliveries stalled. The disruption reached the brands that depend on Nichirei to move product through the cold chain: Kentucky Fried Chicken franchises in Japan warned of shortages, and confectionery and ice-cream maker Ezaki Glico, known for Pocky, was among the other companies affected.
On or around 22 July the ransomware group RansomHouse claimed responsibility, listing Nichirei on its dark-web leak site and asserting it had exfiltrated confidential data, projects and internal documents. The group threatened to publish the material unless the company made contact. As of the initial disclosures Nichirei had not confirmed the scope of any data theft or whether an extortion demand had been received.
Operations began gradually resuming from 17 July, and Nichirei said its affected locations, including warehousing and frozen-food shipping facilities, were expected to return to normal within the week. The recovery timeline suggests the company’s restoration and continuity processes worked; the fact that physical shipments stopped at all points to where the boundary between corporate IT and operational logistics systems did not hold.
The incident is a clean illustration of concentration risk in a supply chain. A single ransomware event at one operator reached multiple downstream consumer brands simultaneously, because a large share of Japan’s frozen distribution runs through Nichirei’s systems — a dependency those brands are unlikely to have modelled as a cyber risk, since it sits on a supplier’s estate rather than their own. It also sits alongside the fairlife (Coca-Cola) ransomware event of 16 July as a second July 2026 attack in which the damage was measured in halted physical production and distribution rather than leaked records.
A deep-dive will follow if a primary disclosure from Nichirei, a confirmed data-theft scope, or independent post-incident analysis of the intrusion becomes available. Until then this is the catalogue’s reference stub for the event.