Blue Yonder ransomware attack disrupts grocery and retail supply chains
- Organization
- Blue Yonder
- Exploit
- Ransomware
- Industry
- Software
Blue Yonder, the Arizona based supply chain software provider acquired by Panasonic in 2021, said a ransomware attack on 21 November 2024 disrupted the private cloud environment it uses to host managed services for customers.
The company said the incident was confined to its managed services hosted environment and that it had seen no suspicious activity in its Azure public cloud environment. Blue Yonder engaged external cybersecurity firms, applied defensive and forensic protocols, and said it was working around the clock on recovery. It declined to give a restoration timeline in the days after the attack.
The outage reached retailers that rely on Blue Yonder for warehouse systems. In the United Kingdom, Morrisons said its warehouse management system for fresh food and produce was affected and that it had reverted to a backup process, adding that the outage had disrupted the smooth flow of goods to its stores. Sainsbury's said it had activated contingency plans. US grocers including Kroger and Albertsons, along with Procter and Gamble and Anheuser-Busch, were named among Blue Yonder's customers, though the extent of any disruption at those companies was not detailed.
The timing compounded the impact, falling immediately before the Thanksgiving trading period. As of late November 2024 no group had publicly claimed responsibility, no ransom demand had been disclosed, and Blue Yonder had not said whether customer data was taken.
Updates
-
The Termite ransomware group listed Blue Yonder on its leak site and claimed to have taken 680GB of data, including email lists and insurance documents. Blue Yonder said it was investigating the claim, which it had not confirmed.