Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Starbucks, Grocery Stores Hit by Blue Yonder Ransomware Attack

Supply chain management software provider Blue Yonder has been targeted in a ransomware attack that caused significant disruptions for some customers.

Software Supply Chain Attack

A ransomware attack on supply chain management software provider Blue Yonder has caused significant disruptions for some of the company’s customers, including several major firms. 

Arizona-based Blue Yonder revealed on November 21 that its managed services hosted environment had been experiencing disruptions due to a ransomware attack. 

The company immediately launched an investigation and started working on restoring impacted services. In the latest update shared on its website on November 24, Blue Yonder said it had been making steady progress, but did not have a timeline for fully restoring services. 

Blue Yonder said it hired a cybersecurity firm to assist its investigation and restoration efforts, but did not share any other information on the attack itself.

No known ransomware group appears to have taken credit for the attack. However, these types of cybercrime groups only name victims and leak data (if they have stolen any) if the victim refuses to pay up or negotiations stall. 

Blue Yonder provides an end-to-end supply chain platform and claims to have over 3,000 customers across 76 countries, including retailers, manufacturers and logistics services providers.

Advertisement. Scroll to continue reading.

Several high-profile customers have confirmed being impacted by the service disruptions at Blue Yonder. One of them is Starbucks, which said the incident impacted its ability to pay baristas and manage employee schedules. 

In the UK, two of the biggest grocery store chains — Morrisons and Sainsbury’s — have been hit, according to The Grocer.

Morrisons, which uses Blue Yonder solutions for warehouse management, has been using a manual backup system due to the outage. The supermarket said the incident has impacted deliveries from suppliers and the availability of some products. 

Sainsbury’s also confirmed being hit, but said it has procedures in place to mitigate the impact of the incident. 

According to CNN, Blue Yonder solutions are also used by US grocery chains, including Albertsons and Kroger, as well as other types of companies such as Ford, Procter & Gamble, and Anheuser-Busch, but it’s unclear if they have been impacted in any way.

Related: Polyfill Supply Chain Attack Hits Over 100k Websites 

Related: GitLoker Strikes Again: New “Goissue” Tool Targets GitHub Developers and Corporate Supply Chains

Related: Lottie-Player Supply Chain Attack Targets Cryptocurrency Wallets

Related: North Korean APT Exploited IE Zero-Day in Supply Chain Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.