Everything we know about the Peter Green Chilled cyber attack
A ransomware attack on the chilled food distributor highlights the supply chain risks within the retail sector


Following cyber attacks on several British retailers, food logistics company Peter Green Chilled has been hit by a ransomware attack too.
In an email seen by the BBC, the firm, which supplies several major UK supermarkets, said the incident took place last week, but that its transport operations weren't affected.
The distributor is working with clients on how to keep deliveries going, it said, but has suspended order processing for the time being. It's not known whether the company has received a ransom demand, or who carried out the attack.
Somerset-based Peter Green transports chilled food, mainly to regional stores. It supplies several major supermarkets in the UK, including Asda, Morrisons, Sainsbury's, Tesco, and Waitrose, as well as M&S and Co-op.
The short shelf life of the products that the company handles increases the pressure to pay the ransom - though it's not known whether Peter Green has done so. The tactic mirrors the strategy used by attackers when targeting the healthcare and manufacturing sectors, focusing on operational disruption rather than data theft.
"Food suppliers like Peter Green Chilled are increasingly attractive targets for cybercriminals - not just for the data they hold, but because any operational disruption has immediate and far-reaching consequences. In industries where downtime hits supply chains within hours, the stakes couldn’t be higher," said Lee Driver, vice president of managed security services at Ekco.
"Like retail, the food supply chain is a sprawling ecosystem of suppliers, logistics providers, and digital infrastructure. Once attackers find a way in, they can move laterally at speed - crippling systems that underpin everything from production to delivery."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The incident follows recent attacks on the Co-op, Harrods, and M&S - the latter of which is continuing to feel the consequences. The company said this week that it expects disruption to its online services to last until July and that its profits are likely to be down by around £300 million as a result.
According to Sophos, 45% of retail organizations were hit by ransomware last year - down from 69% in 2023. However, the retail sector reported the second-highest data extortion rate, at 5%, and the mean cost to recover was $2.73 million, up from $1.85 million in 2023.
Six-in-ten organizations paid the ransom, marking an increase from 43% the year before, although the average payment fell by two-thirds.
"In food retail, even short-term disruption can lead to spoilage, logistical bottlenecks, and loss of consumer trust," commented David Mound, senior penetration tester at third-party risk management platform SecurityScorecard.
"Attackers are no longer just targeting data; they’re targeting urgency. In environments where product expiration and just-in-time delivery are business-critical, threat actors understand that every hour offline amplifies the pressure to pay."
MORE FROM ITPRO
- ]Why retail is a top target for cyber attacks
- Harrods hit by cyber attack as UK retailers battle threats
- Cyber attacks have rocked UK retailers – here's how you can stay safe
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
CISO warns agentic AI tied to major risks and failure
News Runtime security and employee oversight are necessary to achieve success with AI agents, according to Haider Pasha
-
Enterprise browsers: the new standard for security?
In-depth The market for enterprise browsers is growing fast – but are their features and security controls enough to compete with free applications?
-
NCA confirms arrest after airport cyber disruption
News Disruption is easing across Europe following the ransomware incident
-
Cyber professionals are losing sleep over late night attacks
News Hackers are biding their time and launching attacks when businesses can’t respond
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant