JBS Hit by Major Ransomware Attack Linked to Russia, Disrupting Global Meat Supply
The world’s largest meat processing company, JBS, suffered a sophisticated ransomware attack that forced the temporary shutdown of operations in Australia, Canada, and the U.S., disrupting a significant portion of global meat production. The attack, detected on Monday, targeted the company’s IT systems, halting nearly a fifth of U.S. beef production and affecting thousands of workers. JBS, which processes roughly a quarter of America’s beef and a fifth of its pork, suspended affected systems immediately but confirmed its backup servers remained uncompromised.
The White House revealed that the ransom demand originated from a criminal group likely based in Russia, prompting direct engagement with Moscow to address the incident. U.S. officials reiterated their stance against paying ransoms, warning it could encourage further attacks. Russia’s Deputy Foreign Minister Sergei Ryabkov acknowledged discussions with the Biden administration regarding the cyberattack.
While JBS’s South American operations remained unaffected, the disruption rippled through supply chains, with supermarkets and major customers like McDonald’s facing potential shortages or price increases. The United Food and Commercial Workers’ Union urged JBS to ensure workers received pay despite the shutdowns. The FBI is investigating the incident, which follows a similar ransomware attack on Colonial Pipeline also linked to Russia that crippled fuel delivery in the southeastern U.S. last month.
JBS, founded in Brazil in 1953, now operates over 150 plants across 15 countries and employs 150,000 people. The company reported "significant progress" in restoring operations, with most plants expected to resume work by Wednesday. The attack underscores the vulnerability of critical food supply chains to cyber threats.
Source: https://www.bbc.com/news/world-us-canada-57318965
JBS cybersecurity rating report: https://www.rankiteo.com/company/jbs
"id": "JBS1780944727",
"linkid": "jbs",
"type": "Ransomware",
"date": "6/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Supermarkets, major customers '
'like McDonald’s, thousands of '
'workers',
'industry': 'Meat processing',
'location': 'Global (primarily Australia, Canada, '
'U.S.)',
'name': 'JBS',
'size': '150,000 employees, over 150 plants across 15 '
'countries',
'type': 'Corporation'}],
'customer_advisories': 'Potential shortages or price increases for customers '
'like supermarkets and McDonald’s',
'data_breach': {'data_encryption': 'Yes (ransomware)'},
'date_detected': '2021-05-31',
'date_publicly_disclosed': '2021-05-31',
'description': 'The world’s largest meat processing company, JBS, suffered a '
'sophisticated ransomware attack that forced the temporary '
'shutdown of operations in Australia, Canada, and the U.S., '
'disrupting a significant portion of global meat production. '
'The attack targeted the company’s IT systems, halting nearly '
'a fifth of U.S. beef production and affecting thousands of '
'workers. The FBI is investigating the incident, which follows '
'a similar ransomware attack on Colonial Pipeline also linked '
'to Russia.',
'impact': {'brand_reputation_impact': 'Potential impact due to supply chain '
'disruptions',
'downtime': 'Temporary shutdown of operations in Australia, '
'Canada, and the U.S.',
'operational_impact': 'Halted nearly a fifth of U.S. beef '
'production, affected thousands of workers',
'systems_affected': 'IT systems, meat processing operations'},
'investigation_status': 'Ongoing (FBI investigating)',
'lessons_learned': 'Vulnerability of critical food supply chains to cyber '
'threats',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': 'Restoring operations using '
'backup servers, enhanced '
'cybersecurity measures '
'(implied)'},
'ransomware': {'data_encryption': 'Yes',
'ransom_demanded': 'Yes (amount not disclosed)'},
'references': [{'source': 'White House, FBI, Reuters, The Guardian'}],
'response': {'containment_measures': 'Suspended affected systems',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'FBI',
'recovery_measures': 'Most plants expected to resume work by '
'Wednesday',
'remediation_measures': 'Restoring operations using backup '
'servers'},
'stakeholder_advisories': 'U.S. officials warned against paying ransoms; '
'Russia engaged in discussions',
'threat_actor': 'Criminal group likely based in Russia',
'title': 'JBS Hit by Major Ransomware Attack Linked to Russia, Disrupting '
'Global Meat Supply',
'type': 'Ransomware'}