Dole shut down North American operations after ransomware attack
- Organization
- Dole plc
- Exploit
- Ransomware
- Industry
- Agribusiness
Dole plc, the Dublin-headquartered fresh produce group, confirmed in late February 2023 that it had been hit by ransomware and had shut down systems across its North American operations. The disclosure followed the surfacing of an internal memo dated February 10 in which Emanuel Lazopoulos, a senior vice president in Dole's Fresh Vegetables division, told retailers the company was in the midst of a cyber attack.
The memo said Dole's plants were shut for the day and that all shipments were on hold. The disruption reached store shelves: retailers in New Mexico and Texas reported being unable to stock Dole salad kits, and shoppers posted about missing products.
In a public statement Dole said it had moved quickly to contain the attack, engaged outside cybersecurity specialists and notified law enforcement. The company characterised the operational impact as limited, though it did not say how long production had been halted or how many facilities were involved.
No group claimed responsibility for the attack, and Dole did not answer questions about whether a ransom had been demanded or paid. As of early March 2023 the investigation was continuing and the company had not disclosed whether any data was taken. Dole later confirmed that employee information had been accessed and put the direct costs of the attack at about $10.5 million.