logo
Cyberattack On Whole Foods Supplier Disrupts Supply Chain Again

Cyberattack On Whole Foods Supplier Disrupts Supply Chain Again

Forbes4 hours ago

SAN RAFAEL, CALIFORNIA - JUNE 11: A shelf is seen bare in the frozen foods section of a Whole Foods ... More store on June 11, 2025 in San Rafael, California. United Natural Foods, the primary food distributor to Whole Foods, has paused deliveries to Whole Foods stores after a cyberattack crippled its system. Some Whole Foods stores are experiencing empty shelves and freezers. (Photo by)
On June 5, 2025, a cyberattack forced United Natural Foods Inc., the primary distributor for Whole Foods Market, to shut down its systems and halt deliveries to more than 30,000 grocery stores across North America. Nearly two weeks later, the company is still operating on a limited basis, relying on workarounds and manual processes. This was not a minor glitch but a direct hit to the digital backbone of the food supply chain.
Grocery stores were deemed essential infrastructure during the COVID-19 pandemic, with workers hailed as frontline heroes. Now, in 2025, the breach at UNFI raises a chilling question: what a biological virus could not shut down, could a cyberattack succeed in crippling? If malicious actors can freeze the software that moves food, they can empty shelves, disrupt lives and trigger cascading economic impacts. 'Food security is national security,' one lawmaker warned earlier this year. Congress appears to agree and has introduced the bipartisan Farm and Food Cybersecurity Act of 2025.
What happened, and what could have been done to stop it?
Whole Foods Market locations across the U.S. experienced product shortages after a cyberattack on ... More its primary distributor, United Natural Foods Inc., disrupted supply chains in June 2025.
UNFI, based in Providence, Rhode Island, is North America's largest publicly traded wholesale grocery distributor. The company operates more than 50 distribution centers and supplies approximately 30,000 locations, including supermarkets, independent grocers and food service providers. On June 5, the company detected unauthorized activity on its systems and immediately activated its incident response plan. As a precaution, it took portions of its network offline, which disrupted order processing, fulfillment and shipment capabilities. Law enforcement and external cybersecurity experts were called in to assist with the investigation.
The outage was swift and severe. Automated systems for ordering and inventory went dark, forcing cancellations of employee shifts and a return to manual processes. Business operations were impacted across the board, resulting in significant delivery delays.
UNFI did not publicly disclose the breach until June 9, when it filed an 8-K with the Securities and Exchange Commission. The company warned that disruptions would continue and outlined its reliance on manual workarounds to maintain critical grocery shipments while digital systems remained down.
The downstream impact on retailers was immediate. Whole Foods Market, which depends heavily on UNFI, saw noticeable shortages in key categories. Refrigerated and perishable sections in many stores went empty. Store employees posted apology signs for out-of-stock items and explained delays. Customers posted photos of empty shelves across multiple locations.
Independent grocers and regional chains also reported missed or delayed shipments. Many scrambled to find backup suppliers. Some succeeded, but others simply ran out of stock, leaving consumers with fewer options.
Even the United States military's Defense Commissary Agency was affected. Fifty-three commissary stores reported delays. While some mitigated the issue with manual ordering, many still faced inventory shortfalls.
A single breach had turned into a national supply chain shock. With just-in-time inventory models and limited buffers, grocers were vulnerable to even short-term digital outages. The result was fewer choices for shoppers and deeper concerns for the industry.
As of mid-June, UNFI has not confirmed the source or type of cyberattack. The company has avoided calling it ransomware, and no group has claimed responsibility. Still, experts widely agree that the attack shares several characteristics typical of ransomware events, including a full system shutdown, containment procedures and prolonged disruption.
While unproven, the consensus is that ransomware is the most likely explanation, especially given the sharp rise in attacks against the food and retail sectors. In similar cases, attackers have encrypted systems and demanded payment in exchange for restored access.
On a June 10 earnings call, UNFI Chief Executive Officer Sandy Douglas said only that the company was managing through the incident and focused on safe restoration. The company has shared few details. It remains unclear whether any data was stolen or whether negotiations are ongoing. The lack of attribution could indicate behind-the-scenes engagement with law enforcement, which is common in complex ransomware cases.
Until the investigation is complete, the grocery sector remains on high alert. The breach underscores just how vulnerable essential supply chains have become.
The attack on UNFI is part of a broader trend of attacks on the food supply chain. Recent high-profile incidents include:
Cybercriminals have proven they can cause real-world consequences across the food sector. 'The cyberattack on United Natural Foods is not an isolated incident but part of a growing trend,' said Jeff Wichman, incident response director at Semperis. The risk is no longer hypothetical.
The attack has sparked urgent conversations throughout the grocery industry. Key priorities include:
Cybersecurity is no longer optional. Food supply chains are essential and increasingly targeted. Resilience must be a top priority across every tier of the industry.
By mid-June, UNFI had resumed shipments from most distribution centers and made progress restoring systems. Still, many operations rely on manual processes, and product shortages persist in some regions. The impact is ongoing and visible.
This breach should serve as a turning point. Whole Foods and other retailers must invest in both digital defenses and supply chain resilience. Distributors must act with urgency. In the business of feeding families, downtime is unacceptable. The next attack could hit harder and spread faster. The time to prepare is now.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

H&S expanding use of digital shelf labels
H&S expanding use of digital shelf labels

Yahoo

time4 minutes ago

  • Yahoo

H&S expanding use of digital shelf labels

This story was originally published on C-Store Dive. To receive daily news and insights, subscribe to our free daily C-Store Dive newsletter. H&S Energy Group is adding electronic shelf labels from digital solutions company Aperion to its stores, according to a press release from Aperion's parent company, Hussmann. The retailer tested the labels in seven locations in early 2025, and has now decided to expand the product to all roughly 300 locations. That expansion is expected to complete sometime in 2026. Electronic shelf labels should help H&S make price updates quicker and help create a better customer experience, according to the announcement. H&S's electronic shelf labels will allow the company to instantly update pricing on any item remotely. According to Aperion's brochure, the technology can cut the labor cost of pricing items by up to 90%. The tags can also display additional information, such as whether there's a deal for the item or when something out-of-stock is expected to be back. In its release, Hussmann said H&S plans to eventually use the digital tags for inventory management, digital coupons and loyalty program tie-ins, as well. "This rollout is a key milestone in our broader digital transformation strategy," said Fidaa Mohrez, senior director of operational systems at H&S Energy Group. "By deploying Aperion's Electronic Shelf Labels, we're improving pricing accuracy, reducing manual effort, and delivering a more consistent experience for our customers.' Mohrez also noted that the digital labels cut down on waste, since paper tags won't need to be printed out every time a product or price changes. Since roughly doubling its store count in early 2024 with the acquisition of Andretti Petroleum Group, Orange, California-based H&S has made a number of tech upgrades, including adding car wash subscriptions to its app, adding temperature monitoring to refrigerators, heaters and freezers, and expanding the availability of delivery from its stores. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

Trump's border czar: Immigration raids at farms, hotels to continue
Trump's border czar: Immigration raids at farms, hotels to continue

Axios

time15 minutes ago

  • Axios

Trump's border czar: Immigration raids at farms, hotels to continue

Following a week of immigration whiplash, President Trump's border czar Tom Homan confirmed Thursday that immigration raids will continue in the agriculture and hospitality industries. The big picture: The Trump administration last week said it was pausing some ICE raids that would hurt those industries, but Homan's comments reaffirm that it is reversing course. Zoom in: While workers at places like farms, restaurants and hotels will be targeted, people with criminal backgrounds will be a priority for immigration enforcement officials, Homan said. "We're going to continue to do worksite enforcement operations, even on farms and hotels, but based on a prioritized basis. Criminals come first," Homan told reporters. What he's saying: Asked what he would say to farmers concerned the raids will hurt their jobs and the U.S. economy, Homan said, "Well, first of all, there's a right way and wrong way to hire workers. There are legal programs that bring farm workers in." He continued, "Second of all, I've been saying for years, Congress needs to address this. But because Congress failed, it just doesn't mean we ignore it. It's illegal to knowingly hire an illegal alien." Catch up quick: Trump surprised immigration hardliners last week when his administration announced it would pause some immigration raids following concerns from advisers and Cabinet members that they were hurting the agriculture and hospitality industries. He acknowledged in a Truth Social post that his "very aggressive" policies were ripping longtime workers from jobs that are "almost impossible to replace." But on Monday, the Department of Homeland Security indicated it was reversing course and that farms, hotels and restaurants would again be subject to raids.

High travel costs overshadow political concerns for overseas visitors, says U.S. Travel's CEO
High travel costs overshadow political concerns for overseas visitors, says U.S. Travel's CEO

Travel Weekly

time21 minutes ago

  • Travel Weekly

High travel costs overshadow political concerns for overseas visitors, says U.S. Travel's CEO

CHICAGO -- On U.S. destinations' list of concerns, high prices rank higher than presidential politics, said U.S. Travel Association CEO Geoff Freeman. "As I walk on the floor here and talk to people, the biggest concern I hear from buyers is not about administration policy. The number one concern I hear is the cost of travel," Freeman said on June 16 at U.S. Travel's annual IPW conference this week. "I was talking with someone earlier today who just said they went and got a latte and it was $8. That's just a really expensive latte. And it's fair to say that could be a shock for many travelers and it's something we've got to pay attention to." Freeman also said that while there is some weakness in inbound travel, the numbers are "fine," except for Canada. However, "fine" is a missed opportunity. "We should be driving an increase year-over-year in inbound travel to the United States," he said. "It should be a priority for the country. I appreciate that major events are a priority for the administration -- the World Cup, the Olympics, America's 250th birthday -- and they're driving a lot of focus. I hope we can earn the same focus on driving travel to the United States every day of the week. And we're making inroads with the administration to be able to have those conversations." The National Travel & Tourism Office's most recent overseas visitation numbers showed an 8% year-over-year increase in April, followed by a 2.8% dip in May. Year-to-date international visitation to the U.S. is down 0.8%, mainly due to a weak March, when travel fell 11.6%. The NTTO's numbers do not include Canada, the top source market for U.S. visitors, or land crossings from Mexico. Freeman said there has been a "handwringing, sky is falling" narrative about inbound travel in the media. "That's not what the numbers say," he said. "The numbers say that we have some weakness and softening. A lot of that is fueled by Canada. Canada is a market where the decline cannot be debated, and it also can't be argued why they're doing it. They're rallying around their flag, and we've got work to do to earn their business in the future." Freeman said he's disappointed with mainstream media coverage of international travel to the U.S., saying that the media wants to "use our industry to embarrass the administration. They want to make travel the victim and push this angle that the sky is falling. It's very disappointing." He pointed to efforts from the administration to send a welcoming message to travelers, including the presence of Trump and Vice President J.D. Vance for the rollout of the World Cup Task Force, where Trump and Vance said "very clearly in front of the journalists, 'We want you to come to America.' I think that was the first time they had made that comment in this administration. So we very much appreciate that. "That's not to say there aren't areas I think we can do better," he added. "I think we have to acknowledge that a perception has formed that the U.S. is not as welcoming as it was. That at a customs checkpoint you might get detained or your device might be searched. There's more we need to do to assure the world that we do want them to come, that they are a priority for us. And that's a combination of the White House, the Department of Homeland Security, Brand USA, all working together to address this."

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store