RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura Sushi
RansomHouse Ransomware Attack Disrupts Nichirei Japanese (TL-2026-1639), also tracked as Nichirei RansomHouse Incident, is a high-severity ransomware operation, first published 2026-07-22. It is attributed to Ransomhouse with medium confidence, affects Nichirei Corporation Nichirei Logistics Group refrigerated warehouse, maps to 23 MITRE ATT&CK techniques (T1003, T1005, T1020), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1639
- Threat ID
- TL-2026-1639
- Also known as
- Nichirei RansomHouse Incident, Nichirei Cold-Chain Ransomware Attack
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Ransomhouse
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- food and beverage, logistics, cold-chain warehousing, retail, restaurants and food service
- Target regions
- japan, East Asia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in RansomHouse Ransomware Attack Disrupts Nichirei Japanese
Malware and tooling: Mario, MarioLocker, WhiteRabbit, Advanced IP Scanner, Cobalt Strike, MEGAsync, Mimikatz, MrAgent, ProcDump, Rclone - S1040, TeamViewer, Vatet loader
On July 13, 2026, Japan's largest cold-chain logistics operator Nichirei Corporation was hit by a cyberattack that disrupted refrigerated warehouse and shipping operations across its 140 distribution centers, cascading to roughly 5,000 downstream business partners including KFC Japan (1,300+ stores), Aeon supermarkets, Kura Sushi, Hotto Motto, Yayoi Ken, and TableMark. On July 22, 2026 the double-extortion group RansomHouse claimed responsibility on its dark-web leak site, asserting data theft and displaying an evidence pack while alleging Nichirei's IT department was concealing the incident.
How RansomHouse Ransomware Attack Disrupts Nichirei Japanese works
Nichirei Corporation, Japan's largest frozen-food manufacturer and cold-chain logistics provider, experienced a system outage beginning Monday, July 13, 2026, that Nichirei confirmed on July 15-16 was the result of unauthorized access. The company proactively disconnected key systems as a containment measure, withholding technical details of the intrusion (attack vector, malware family, and whether encryption occurred) to "avoid security risks" and prevent further damage. The disruption struck Nichirei Logistics Group's refrigerated warehouse network — approximately 140 temperature-controlled distribution centers serving about 5,000 business partners — halting incoming and outgoing shipments of frozen food products.
The operational fallout cascaded rapidly through Japan's food supply chain. KFC Japan, which outsources chicken and ingredient delivery to Nichirei's logistics subsidiary, warned that all 1,300+ of its nationwide restaurants could be affected, resulting in ingredient shortages, menu limitations, reduced operating hours, and temporary closures at some locations. Aeon supermarkets reported shortages of frozen food items. Kura Sushi reported shipment delays at stores in western Japan. TableMark was unable to ship products to retail and commercial clients. Hotto Motto and Yayoi Ken, both major Japanese fast-casual/bento chains, also experienced delivery delays.
Nichirei acknowledged that some of the affected servers stored personal information and submitted an initial report to Japan's Personal Information Protection Commission (PPC) regarding the possibility of a data leak, stating it would promptly report to relevant parties if leakage were confirmed. The company engaged an external cybersecurity specialist firm to support recovery and began a phased restoration of systems starting Friday, July 17, 2026, with no confirmed date for full recovery given as of July 22.
On July 22, 2026, cybersecurity firm S&J (via its president Nobuo Miwa) confirmed that the double-extortion ransomware/data-extortion group RansomHouse had posted a claim of responsibility on its dark-web leak site, displaying what it represented as stolen internal Nichirei data (including confidential and project documents) and urging the company to make contact to prevent a public leak. RansomHouse's post reportedly listed "Encrypted: July 13, 2026" and a status of "EVIDENCE — It's up to you," consistent with the group's typical 4-6 day negotiation window before public disclosure of stolen data. Nichirei has not verified the authenticity of the leaked evidence pack as of this writing. Commentators have noted RansomHouse also claimed an October 2025 attack on Japanese office-supply e-commerce firm ASKUL (approximately 1.1 TB reportedly exfiltrated), raising the possibility of a pattern of targeting Japanese logistics/e-commerce infrastructure by the same group, though no technical overlap has been publicly confirmed between the two intrusions.
RansomHouse is a double-extortion data-extortion group first observed in December 2021, notable for de-emphasizing encryption in favor of data theft and threatened publication — encryption (via its Babuk-derived "Mario"/"White Rabbit" encryptor branding) is typically only deployed if ransom demands are not met. The group has previously claimed victims including AMD, ADATA, IFX Networks (Colombian government ministries, 2023 supply-chain incident), Christie's auction house, Saskatchewan Liquor and Gaming Authority, and a major U.S. semiconductor company (450GB exfiltrated). RansomHouse has documented ties to Iranian state-sponsored initial access broker Pioneer Kitten (Fox Kitten/UNC757/Lemon Sandstorm), which supplies footholds via exploitation of edge appliances (Citrix, Palo Alto Networks, Check Point). The group's known toolkit includes Mimikatz and ProcDump for credential theft/LSASS dumping, Cobalt Strike and Vatet loader, Advanced IP Scanner and TeamViewer for reconnaissance/remote access, MEGAsync/Rclone for exfiltration, and MrAgent for automated ESXi ransomware deployment. No specific initial access vector, malware sample, or IOC has yet been publicly confirmed for the Nichirei intrusion itself; this record documents the incident using verified public reporting plus RansomHouse's established TTP baseline from prior confirmed intrusions, pending release of forensic detail from Nichirei or its incident-response partner.
MITRE ATT&CK techniques used in TL-2026-1639
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1556 Modify Authentication Process
Collection
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing
Discovery
T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1217 Browser Information Discovery
stealth
T1134 Access Token Manipulation
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
defense-impairment
Affected products and versions in RansomHouse Ransomware Attack Disrupts Nichirei Japanese
- Nichirei Corporation — Nichirei Logistics Group refrigerated warehouse management systems
Vulnerable versions: production systems as of July 13, 2026 - Nichirei Corporation — Personal information servers (Nichirei Group)
Vulnerable versions: production systems as of July 13, 2026
Remediation for RansomHouse Ransomware Attack Disrupts Nichirei Japanese
Immediate actions
- Isolate and disconnect affected warehouse management, logistics, and file-server systems from the corporate network pending forensic triage
- Rotate all Active Directory credentials and force re-authentication, prioritizing accounts with domain admin or service-account privileges (RansomHouse relies heavily on Mimikatz/LSASS credential theft)
- Hunt for RansomHouse's known toolkit: Cobalt Strike beacons, Vatet loader, Advanced IP Scanner, TeamViewer, MEGAsync/Rclone exfil activity, and MrAgent on any ESXi hosts
- Notify Japan's Personal Information Protection Commission (PPC) and affected downstream business partners of confirmed or suspected data exposure
- Engage external incident-response/forensics support and preserve logs/memory images before remediation actions overwrite evidence
Workarounds
- Manual/paper-based warehouse dispatch and shipment tracking during system restoration
- Downstream partners sourcing ingredients from alternate cold-chain logistics providers during the outage window
Longer-term hardening
- Patch and restrict internet-facing edge appliances (VPN concentrators, Citrix/Palo Alto/Check Point gateways) given RansomHouse's documented use of an Iranian IAB (Pioneer Kitten) that specializes in edge-appliance exploitation
- Deploy EDR with LSASS-access alerting and Mimikatz/credential-dumping behavioral detections across all Windows hosts
- Segment cold-chain warehouse management/OT-adjacent systems from corporate IT to limit blast radius of future ransomware events
- Implement immutable, offline backups for warehouse management and ERP systems with regular restoration testing
- Establish supply-chain incident communication protocols with major downstream partners (KFC Japan, Aeon, etc.) for faster cascading-impact disclosure
Timeline of RansomHouse Ransomware Attack Disrupts Nichirei Japanese
- RansomHouse data-extortion group first observed in the wild, emerging as a double-extortion operation that de-emphasizes encryption in favor of data theft and threatened leak-site publication.
- Unauthorized access causes a system outage at Nichirei Logistics Group, disrupting refrigerated warehouse and shipping operations across roughly 140 distribution centers; RansomHouse's later leak-site post lists this date as the encryption/attack date.
- Nichirei confirms the outage was caused by a cyberattack but withholds technical details to avoid further security risk.
- Nichirei publicly discloses the incident and its cascading impact on downstream partners including KFC Japan, which warns all 1,300+ stores nationwide could be affected.
- Media reporting (SecurityWeek, The Record, CPO Magazine, Cyber Express) confirms disruption spreading to Aeon supermarkets, Kura Sushi, TableMark, Hotto Motto, and Yayoi Ken.
- Nichirei begins a phased/sequential restoration of affected systems with support from an external cybersecurity specialist firm.
- Reporting indicates KFC Japan menu items (e.g. chicken) return as Nichirei's restoration progresses, though full recovery timeline remains unconfirmed.
- Nichirei's submission to Japan's Personal Information Protection Commission regarding possible data leakage is reported alongside RansomHouse's claim.
- RansomHouse posts a claim of responsibility on its dark-web leak site, displaying an alleged evidence pack of stolen Nichirei internal data and urging contact to prevent public leak; confirmed by cybersecurity firm S&J president Nobuo Miwa.
Sources cited for RansomHouse Ransomware Attack Disrupts Nichirei Japanese
- Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
- Hacker group RansomHouse claims responsibility for cyberattack on Nichirei
- Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies
- Russian hackers claim responsibility for cyberattack on Nichirei
- Hacker Group Claims to Be Behind Nichirei Cyberattack
- RansomHouse Claims Responsibility for Cyberattack on Nichirei
- Nichirei System Outage: Ransomware Group "RansomHouse" Claims Responsibility, Possibly Same Group Behind ASKUL Attack
- Chicken Back on Menu as Cyber-Hit Nichirei Restores Operations in Japan
- Nichirei getting back online after cyberattack hit KFC supplies
- Cyber Attack on Major Japanese Refrigerated Logistics Provider Disrupts KFC and Other Food Chains
- Nichirei Cyberattack Disrupts KFC Japan Supply Chain
- Freezer food giant's system fault disrupts KFC in Japan: No chicken sold as stores shorten hours
- Threat Profile: RansomHouse
- RansomHouse Threat Group Profile
- RansomHouse: Stolen Data Market, Influence Operations & Other Tricks Up the Sleeve
Threats related to RansomHouse Ransomware Attack Disrupts Nichirei Japanese
Detection coverage for TL-2026-1639
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1639 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.