RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura Sushi

RansomHouse Ransomware Attack Disrupts Nichirei Japanese (TL-2026-1639), also tracked as Nichirei RansomHouse Incident, is a high-severity ransomware operation, first published 2026-07-22. It is attributed to Ransomhouse with medium confidence, affects Nichirei Corporation Nichirei Logistics Group refrigerated warehouse, maps to 23 MITRE ATT&CK techniques (T1003, T1005, T1020), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1639

Threat ID
TL-2026-1639
Also known as
Nichirei RansomHouse Incident, Nichirei Cold-Chain Ransomware Attack
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Ransomhouse
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
food and beverage, logistics, cold-chain warehousing, retail, restaurants and food service
Target regions
japan, East Asia
Detection rules
9
Indicators of compromise
20

Malware and tooling in RansomHouse Ransomware Attack Disrupts Nichirei Japanese

Malware and tooling: Mario, MarioLocker, WhiteRabbit, Advanced IP Scanner, Cobalt Strike, MEGAsync, Mimikatz, MrAgent, ProcDump, Rclone - S1040, TeamViewer, Vatet loader

On July 13, 2026, Japan's largest cold-chain logistics operator Nichirei Corporation was hit by a cyberattack that disrupted refrigerated warehouse and shipping operations across its 140 distribution centers, cascading to roughly 5,000 downstream business partners including KFC Japan (1,300+ stores), Aeon supermarkets, Kura Sushi, Hotto Motto, Yayoi Ken, and TableMark. On July 22, 2026 the double-extortion group RansomHouse claimed responsibility on its dark-web leak site, asserting data theft and displaying an evidence pack while alleging Nichirei's IT department was concealing the incident.

How RansomHouse Ransomware Attack Disrupts Nichirei Japanese works

Nichirei Corporation, Japan's largest frozen-food manufacturer and cold-chain logistics provider, experienced a system outage beginning Monday, July 13, 2026, that Nichirei confirmed on July 15-16 was the result of unauthorized access. The company proactively disconnected key systems as a containment measure, withholding technical details of the intrusion (attack vector, malware family, and whether encryption occurred) to "avoid security risks" and prevent further damage. The disruption struck Nichirei Logistics Group's refrigerated warehouse network — approximately 140 temperature-controlled distribution centers serving about 5,000 business partners — halting incoming and outgoing shipments of frozen food products.

The operational fallout cascaded rapidly through Japan's food supply chain. KFC Japan, which outsources chicken and ingredient delivery to Nichirei's logistics subsidiary, warned that all 1,300+ of its nationwide restaurants could be affected, resulting in ingredient shortages, menu limitations, reduced operating hours, and temporary closures at some locations. Aeon supermarkets reported shortages of frozen food items. Kura Sushi reported shipment delays at stores in western Japan. TableMark was unable to ship products to retail and commercial clients. Hotto Motto and Yayoi Ken, both major Japanese fast-casual/bento chains, also experienced delivery delays.

Nichirei acknowledged that some of the affected servers stored personal information and submitted an initial report to Japan's Personal Information Protection Commission (PPC) regarding the possibility of a data leak, stating it would promptly report to relevant parties if leakage were confirmed. The company engaged an external cybersecurity specialist firm to support recovery and began a phased restoration of systems starting Friday, July 17, 2026, with no confirmed date for full recovery given as of July 22.

On July 22, 2026, cybersecurity firm S&J (via its president Nobuo Miwa) confirmed that the double-extortion ransomware/data-extortion group RansomHouse had posted a claim of responsibility on its dark-web leak site, displaying what it represented as stolen internal Nichirei data (including confidential and project documents) and urging the company to make contact to prevent a public leak. RansomHouse's post reportedly listed "Encrypted: July 13, 2026" and a status of "EVIDENCE — It's up to you," consistent with the group's typical 4-6 day negotiation window before public disclosure of stolen data. Nichirei has not verified the authenticity of the leaked evidence pack as of this writing. Commentators have noted RansomHouse also claimed an October 2025 attack on Japanese office-supply e-commerce firm ASKUL (approximately 1.1 TB reportedly exfiltrated), raising the possibility of a pattern of targeting Japanese logistics/e-commerce infrastructure by the same group, though no technical overlap has been publicly confirmed between the two intrusions.

RansomHouse is a double-extortion data-extortion group first observed in December 2021, notable for de-emphasizing encryption in favor of data theft and threatened publication — encryption (via its Babuk-derived "Mario"/"White Rabbit" encryptor branding) is typically only deployed if ransom demands are not met. The group has previously claimed victims including AMD, ADATA, IFX Networks (Colombian government ministries, 2023 supply-chain incident), Christie's auction house, Saskatchewan Liquor and Gaming Authority, and a major U.S. semiconductor company (450GB exfiltrated). RansomHouse has documented ties to Iranian state-sponsored initial access broker Pioneer Kitten (Fox Kitten/UNC757/Lemon Sandstorm), which supplies footholds via exploitation of edge appliances (Citrix, Palo Alto Networks, Check Point). The group's known toolkit includes Mimikatz and ProcDump for credential theft/LSASS dumping, Cobalt Strike and Vatet loader, Advanced IP Scanner and TeamViewer for reconnaissance/remote access, MEGAsync/Rclone for exfiltration, and MrAgent for automated ESXi ransomware deployment. No specific initial access vector, malware sample, or IOC has yet been publicly confirmed for the Nichirei intrusion itself; this record documents the incident using verified public reporting plus RansomHouse's established TTP baseline from prior confirmed intrusions, pending release of forensic detail from Nichirei or its incident-response partner.

MITRE ATT&CK techniques used in TL-2026-1639

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1556 Modify Authentication Process

Collection

T1005 Data from Local System

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing

Discovery

T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1217 Browser Information Discovery

stealth

T1134 Access Token Manipulation

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in RansomHouse Ransomware Attack Disrupts Nichirei Japanese

  • Nichirei Corporation — Nichirei Logistics Group refrigerated warehouse management systems
    Vulnerable versions: production systems as of July 13, 2026
  • Nichirei Corporation — Personal information servers (Nichirei Group)
    Vulnerable versions: production systems as of July 13, 2026

Remediation for RansomHouse Ransomware Attack Disrupts Nichirei Japanese

Immediate actions

  • Isolate and disconnect affected warehouse management, logistics, and file-server systems from the corporate network pending forensic triage
  • Rotate all Active Directory credentials and force re-authentication, prioritizing accounts with domain admin or service-account privileges (RansomHouse relies heavily on Mimikatz/LSASS credential theft)
  • Hunt for RansomHouse's known toolkit: Cobalt Strike beacons, Vatet loader, Advanced IP Scanner, TeamViewer, MEGAsync/Rclone exfil activity, and MrAgent on any ESXi hosts
  • Notify Japan's Personal Information Protection Commission (PPC) and affected downstream business partners of confirmed or suspected data exposure
  • Engage external incident-response/forensics support and preserve logs/memory images before remediation actions overwrite evidence

Workarounds

  • Manual/paper-based warehouse dispatch and shipment tracking during system restoration
  • Downstream partners sourcing ingredients from alternate cold-chain logistics providers during the outage window

Longer-term hardening

  • Patch and restrict internet-facing edge appliances (VPN concentrators, Citrix/Palo Alto/Check Point gateways) given RansomHouse's documented use of an Iranian IAB (Pioneer Kitten) that specializes in edge-appliance exploitation
  • Deploy EDR with LSASS-access alerting and Mimikatz/credential-dumping behavioral detections across all Windows hosts
  • Segment cold-chain warehouse management/OT-adjacent systems from corporate IT to limit blast radius of future ransomware events
  • Implement immutable, offline backups for warehouse management and ERP systems with regular restoration testing
  • Establish supply-chain incident communication protocols with major downstream partners (KFC Japan, Aeon, etc.) for faster cascading-impact disclosure

Timeline of RansomHouse Ransomware Attack Disrupts Nichirei Japanese

  • RansomHouse data-extortion group first observed in the wild, emerging as a double-extortion operation that de-emphasizes encryption in favor of data theft and threatened leak-site publication.
  • Unauthorized access causes a system outage at Nichirei Logistics Group, disrupting refrigerated warehouse and shipping operations across roughly 140 distribution centers; RansomHouse's later leak-site post lists this date as the encryption/attack date.
  • Nichirei confirms the outage was caused by a cyberattack but withholds technical details to avoid further security risk.
  • Nichirei publicly discloses the incident and its cascading impact on downstream partners including KFC Japan, which warns all 1,300+ stores nationwide could be affected.
  • Media reporting (SecurityWeek, The Record, CPO Magazine, Cyber Express) confirms disruption spreading to Aeon supermarkets, Kura Sushi, TableMark, Hotto Motto, and Yayoi Ken.
  • Nichirei begins a phased/sequential restoration of affected systems with support from an external cybersecurity specialist firm.
  • Reporting indicates KFC Japan menu items (e.g. chicken) return as Nichirei's restoration progresses, though full recovery timeline remains unconfirmed.
  • Nichirei's submission to Japan's Personal Information Protection Commission regarding possible data leakage is reported alongside RansomHouse's claim.
  • RansomHouse posts a claim of responsibility on its dark-web leak site, displaying an alleged evidence pack of stolen Nichirei internal data and urging contact to prevent public leak; confirmed by cybersecurity firm S&J president Nobuo Miwa.

Sources cited for RansomHouse Ransomware Attack Disrupts Nichirei Japanese

Threats related to RansomHouse Ransomware Attack Disrupts Nichirei Japanese

Detection coverage for TL-2026-1639

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1639 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats