Skip to main content
A supermarket shopping cart sits in silhouette before a bright blue swirling storm.
Analyst Insights

Spoilage Alert: Cyberattacks Are Disrupting Europe’s Supermarket ‘Cold Chain’

A recent wave of cyberattacks on cold chain companies—most recently in Germany and the UK—have experts worried about the delivery of food, medicine and other perishables. We offer practical cyber strategies for logistics vendors and consider whether these attacks will ramp up in the U.S.

Hackers have found a new pressure point: perishables.

Take the case of Peter Green Chilled, a UK refrigerated transport company. A few months back, a ransomware attack disrupted the company’s deliveries to Tesco, Aldi, and Sainsbury’s supermarkets. That same month, a cyberattack on Danish dairy giant Arla Foods disrupted logistics across Germany. And last November, ransomware took down Arizona-based Blue Yonder, interrupting shipments to Starbucks stores in North America and the UK’s Morrison supermarket chain.

How much these companies lost in the attacks is difficult to calculate, but UK firms reportedly face an average total cost of recovery of $2.58 million per incident in 2025. Cybercriminals are targeting industries where downtime causes the most harm, with Europe often serving as the initial point of attack before spreading to the United States and beyond.

In fact, the cybercriminal collective Scattered Spider is thought to have used the same playbook earlier this year, deploying voice phishing (a.k.a. vishing) to compromise the helpdesks of UK retailers Marks & Spencer, Co-Op Group, and Harrods. The National Crime Agency announced the arrests of four alleged perpetrators (a 20-year-old woman and three male teens, ages 17 to 19) in July.

While the cold chain attacks have generated far fewer headlines than those incidents linked to popular retailers, cybercriminals recognize just how lucrative attacks on this sector can be. They’ve targeted the cold chain because it operates on strict timelines: Every item has an expiration date, and every delivery is tied to a specific timeframe. By freezing the flow of perishables such as butter, meat, and medicine, attackers can pressure even the most resilient companies into paying.

“This is no longer random opportunism,” says Phil Pluck, CEO of the Cold Chain Federation, which represents the UK’s temperature-controlled logistics sector and includes nearly 300 member organizations. Hackers reportedly orchestrated about 10 other attacks or attempted attacks on member companies in the last 18 months. “We’re constantly under attack, and ransomware groups know how critical this sector is.”

The cold chain heats up

To understand the risk, consider a single pack of butter.

We’re constantly under attack, and ransomware groups know how critical this sector is.
Phil Pluck, CEO, Cold Chain Federation

As Pluck explains it, the butter’s journey might span dozens of systems and hundreds of miles. It moves from producers to warehouses to regional distribution centers before reaching one of the 32,012 supermarkets in the UK alone. Along the way, it has passed through a mesh of shared digital systems designed to track not just location but also temperature, timing, and handling conditions.

Now, multiply that one pack by an estimated 1.1 billion sold each year, add in thousands of hospitals and fast-food outlets, and stretch the process across 365 days and more than 100,000 temperature-controlled trucks. Every movement depends on shared visibility across producers, warehouses, distributors, and retailers. Lose that visibility, and the whole butter supply chain melts down. Cybercriminals know it.

[Read also: A new decentralized cyberdefense model gains traction in the EU]

“Everyone in the chain has to know where the product is, what condition it’s in, and when it needs to move,” says Pluck. “If any part of that goes dark, the whole chain seizes up.”

And going dark is precisely what happens in a ransomware attack, he says.

Ransomware attackers use perishables as leverage

David Mound, a senior penetration tester at SecurityScorecard, a third-party risk specialist, sees the strategy clearly.

Attackers understand that even short disruptions can lead to spoilage and financial loss.
David Mound, senior penetration tester, SecurityScorecard

“Ransomware operators will target organizations where they know the time to pay out is crucial,” he says. “Having a perishable supply chain compounds that urgency.”

In most attacks, adversaries aim to encrypt data, exfiltrate files, and then demand payment in return for access and silence. But with cold chains, the stakes escalate quickly.

“If you’re distributing perishables like dairy, downtime has an immediate cost,” Mound says. “Attackers understand that even short disruptions can lead to spoilage and financial loss.”

[Read also: How a Barclays CISO (chief information security officer) balances security, regulations, and compliance]

And that can affect multiple brands of foods and other products being delivered, plus the many supermarkets and other stores being delivered to. Black Farmer founder Wilfred Emmanuel-Jones told the BBC he had thousands of pounds of meats and other perishables being delivered by Peter Green Chilled at the time of the cyberattack. That’s “thousands and thousands of packs of products, sitting there, and the clock is ticking,” he said.

How ransomware attacks your medicine cabinet

It’s not just about food. For example, cold chains also handle 20% of the UK’s life-saving medicines, making them prone as well, according to Pluck. In fact, during the pandemic in 2020, ransomware disrupted order fulfillment and inventory management for COVID vaccines.

In a recent survey of pharma supply chain leaders, some two thirds cited the lack of real-time visibility as a serious threat to their supply chain, with 83% of companies leveraging real-time tracking and condition monitoring tools to mitigate threats and better secure cold-chain integrity.

[Read also: Streamline your security with remediation visibility]

“When a ransomware attack hits, the company is disabled and often blind,” says Pluck. “Warehouse management systems stop identifying the product. Delivery trucks can’t report their drop-offs. Last Christmas, one attack even halted supplier invoicing because the system couldn’t register incoming goods.”

Ransomware relies on the cold chain’s crumbling perimeter

One reason cold chain logistics are so vulnerable: their reliance on shared systems and third-party vendors. Cold chain companies, large and small, rely on shared management systems. When multiple businesses are connected digitally, one weak link can expose the entire chain.

That includes legacy OT systems that are old, fragile, and often unpatchable.

“We still find Windows NT in the field,” Mound says, referring to a long-retired version of the Microsoft operating system. “Shutting those systems down to update them would disrupt operations, so companies just try to ringfence them. But over time, contractors punch holes in those fences with VPNs (virtual private networks) and remote access. That’s how attackers slip in.”

Pluck recalls one incident where attackers bombarded an employee with hundreds of phishing emails. A month later, posing as the company’s own IT department, they cited the exact number of spam messages and convinced her to grant remote access. Six months later, ransomware crippled the company, resulting in millions of dollars in damages.

Ransomware strategies for the cold-chain gang

According to Pluck, the cold chain sector is “rapidly catching up,” but it remains uneven in its cyber maturity. Larger companies have bolstered their defenses, purchased cyber insurance, and developed continuity plans. But smaller firms often lack the staff and budget to mount a complete defense.

Mound’s advice? Start with the basics.

MFA (multifactor authentication) is a big one,” he says. “Still, we see companies without it.”

Mound also stresses the importance of limiting third-party access through least-privilege and zero trust policies, monitoring user behavior with baselines and Security Information and Event Management (SIEM) alerts, and vetting vendors for security compliance before onboarding. You need to know your third parties and what they’re doing inside your network, he says.

[Read also: What is DORA? Learn how the EU’s regulatory standards focus on an org’s ability to respond to digital attacks and business disruptions]

Pluck emphasizes preparation over improvisation. He recommends maintaining paper-based backups, setting up basic cloud-based fallback systems, and updating incident response playbooks (with clearly assigned disaster recovery roles) before a crisis hits.

“Don’t wait until the attack to figure out who does what,” he says. “You need to know that today.” He also urges companies to communicate quickly with supply chain partners when an attack occurs. “You might not want to tell the world, but you must tell your suppliers. They can help, and so can you when they’re hit.”

Consistent, continued employee training remains essential, Pluck adds.

“People are still the weak link,” he says. “But if you’ve only lost a day’s data and your systems are backed up, you’re already winning.”

The coming crisis for cold chains in the UK, Europe, and U.S.

So far, Europe’s cold chain has managed to avoid a catastrophic collapse. And the United States has only faced sporadic attacks so far against its cold chain. For example, last June, a cyberattack against United Natural Foods (UNFI) disrupted deliveries to grocers like Whole Foods and cost the company more than $350 million.

We deliver over half the UK’s food and a fifth of its critical medicines, yet we’re not recognized as critical national infrastructure.
Pluck

Such attacks might feel like blips to shoppers, but experts warn that a coordinated attack on multiple food or pharma firms, either globally or in the United States, could trigger a more serious crisis.

“The public reacts fast when shelves go empty,” Pluck says. “We saw it during the pandemic. The difference is this time it might not be temporary.”

[Read also: Unpacking DORA – how financial services firms can gain a comprehensive solution that addresses compliance needs with efficiency, agility, and enhanced security]

And government?

“They’re not listening,” he warns. “We deliver over half the UK’s food and a fifth of its critical medicines, yet we’re not recognized as critical national infrastructure. That needs to change before it’s too late.” In contrast, the United States treats cold chain logistics as part of its Food and Agriculture critical infrastructure sector, recognizing its essential role in securing the food and medicine supply.

Resilience through experience offers one note of hope. Companies that survive an attack emerge “stronger, better prepared, and more resilient,” Pluck says. But that wisdom comes at a cost.

“The ones who haven’t been attacked yet often still treat cost as the barrier,” he says. “But the real cost is in not being ready.”