RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura Sushi — Threadlinqs Intelligence
As of 2026-07-22, RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura Sushi is a high-severity ransomware threat attributed to Ransomhouse, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1639 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Ransomhouse · FINANCIAL
On July 13, 2026, Japan's largest cold-chain logistics operator Nichirei Corporation was hit by a cyberattack that disrupted refrigerated warehouse and shipping operations across its 140 distribution
Nichirei Corporation, Japan's largest frozen-food manufacturer and cold-chain logistics provider, experienced a system outage beginning Monday, July 13, 2026, that Nichirei confirmed on July 15-16 was the result of unauthorized access. The company proactively disconnected key systems as a containment measure, withholding technical details of the intrusion (attack vector, malware family, and whether encryption occurred) to "avoid security risks" and prevent further damage. The disruption struck Nichirei Logistics Group's refrigerated warehouse network — approximately 140 temperature-controlled distribution centers serving about 5,000 business partners — halting incoming and outgoing shipments of frozen food products.
The operational fallout cascaded rapidly through Japan's food supply chain. KFC Japan, which outsources chicken and ingredient delivery to Nichirei's logistics subsidiary, warned that all 1,300+ of its nationwide restaurants could be affected, resulting in ingredient shortages, menu limitations, reduced operating hours, and temporary closures at some locations. Aeon supermarkets reported shortages of frozen food items. Kura Sushi reported shipment delays at stores in western Japan. TableMark was unable to ship products to retail and commercial clients. Hotto Motto and Yayoi Ken, both major Japanese fast-casual/bento chains, also experienced delivery delays.
Nichirei acknowledged that some of the affected servers stored personal information and submitted an initial report to Japan's Personal Information Protection Commission (PPC) regarding the possibility of a data leak, stating it would promptly report to relevant parties if leakage were confirmed. The company engaged an external cybersecurity specialist firm to support recovery and began a phased restoration of systems starting Friday, July 17, 2026, with no confirmed date for full recovery given as of July 22.
On July 22, 2026, cybersecurity firm S&J (via its president Nobuo Miwa) confirmed that the double-extortion ransomware/data-extortion group RansomHouse had posted a claim of responsibility on its dark-web leak site, displaying what it represented as stolen internal Nichirei data (including confidential and project documents) and urging the company to make contact to prevent a public leak. RansomHouse's post reportedly listed "Encrypted: July 13, 2026" and a status of "EVIDENCE — It's up to you," consistent with the group's typical 4-6 day negotiation window before public disclosure of stolen data. Nichirei has not verified the authenticity of the leaked evidence pack as of this writing. Commentators have noted RansomHouse also claimed an October 2025 attack on Japanese office-supply e-commerce firm ASKUL (approximately 1.1 TB reportedly exfiltrated), raising the possibility of a pattern of targeting Japanese logistics/e-commerce infrastructure by the same group, though no technical overlap has been publicly confirmed between the two intrusions.
RansomHouse is a double-extortion data-extortion group first observed in December 2021, notable for de-emphasizing encryption in favor of data theft and threatened publication — encryption (via its Babuk-derived "Mario"/"White Rabbit" encryptor branding) is typically only deployed if ransom demands are not met. The group has previously claimed victims including AMD, ADATA, IFX Networks (Colombian government ministries, 2023 supply-chain incident), Christie's auction house, Saskatchewan Liquor and Gaming Authority, and a major U.S. semiconductor company (450GB exfiltrated). RansomHouse has documented ties to Iranian state-sponsored initial access broker Pioneer Kitten (Fox Kitten/UNC757/Lemon Sandstorm), which supplies footholds via exploitation of edge appliances (Citrix, Palo Alto Networks, Check Point). The group's known toolkit includes Mimikatz and ProcDump for credential theft/LSASS dumping, Cobalt Strike and Vatet loader, Advanced IP Scanner and TeamViewer for reconnaissance/remote access, MEGAsync/Rclone
Target sectors: food and beverage, logistics, cold-chain warehousing, retail, restaurants and food service
Target regions: japan, East Asia
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1190, T1566, T1078, T1087, T1083, T1135, T1217, T1570, T1021, T1021