Everything we know about the Peter Green Chilled cyber attack
A ransomware attack on the chilled food distributor highlights the supply chain risks within the retail sector
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Following cyber attacks on several British retailers, food logistics company Peter Green Chilled has been hit by a ransomware attack too.
In an email seen by the BBC, the firm, which supplies several major UK supermarkets, said the incident took place last week, but that its transport operations weren't affected.
The distributor is working with clients on how to keep deliveries going, it said, but has suspended order processing for the time being. It's not known whether the company has received a ransom demand, or who carried out the attack.
Somerset-based Peter Green transports chilled food, mainly to regional stores. It supplies several major supermarkets in the UK, including Asda, Morrisons, Sainsbury's, Tesco, and Waitrose, as well as M&S and Co-op.
The short shelf life of the products that the company handles increases the pressure to pay the ransom - though it's not known whether Peter Green has done so. The tactic mirrors the strategy used by attackers when targeting the healthcare and manufacturing sectors, focusing on operational disruption rather than data theft.
"Food suppliers like Peter Green Chilled are increasingly attractive targets for cybercriminals - not just for the data they hold, but because any operational disruption has immediate and far-reaching consequences. In industries where downtime hits supply chains within hours, the stakes couldn’t be higher," said Lee Driver, vice president of managed security services at Ekco.
"Like retail, the food supply chain is a sprawling ecosystem of suppliers, logistics providers, and digital infrastructure. Once attackers find a way in, they can move laterally at speed - crippling systems that underpin everything from production to delivery."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The incident follows recent attacks on the Co-op, Harrods, and M&S - the latter of which is continuing to feel the consequences. The company said this week that it expects disruption to its online services to last until July and that its profits are likely to be down by around £300 million as a result.
According to Sophos, 45% of retail organizations were hit by ransomware last year - down from 69% in 2023. However, the retail sector reported the second-highest data extortion rate, at 5%, and the mean cost to recover was $2.73 million, up from $1.85 million in 2023.
Six-in-ten organizations paid the ransom, marking an increase from 43% the year before, although the average payment fell by two-thirds.
"In food retail, even short-term disruption can lead to spoilage, logistical bottlenecks, and loss of consumer trust," commented David Mound, senior penetration tester at third-party risk management platform SecurityScorecard.
"Attackers are no longer just targeting data; they’re targeting urgency. In environments where product expiration and just-in-time delivery are business-critical, threat actors understand that every hour offline amplifies the pressure to pay."
MORE FROM ITPRO
- ]Why retail is a top target for cyber attacks
- Harrods hit by cyber attack as UK retailers battle threats
- Cyber attacks have rocked UK retailers – here's how you can stay safe
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
ITPro Best of Show NAB 2026 awards now open for entriesThe awards are a fantastic opportunity for companies to stand out at one of the industry's most attended shows
-
Mistral CEO Arthur Mensch thinks 50% of SaaS solutions could be supplanted by AINews Mensch’s comments come amidst rising concerns about the impact of AI on traditional software
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwiseNews Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals
-
Everything we know so far about the Nike data breachNews Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Hacker offering US engineering firm data online after alleged breachNews Data relating to Tampa Electric Company, Duke Energy Florida, and American Electric Power was allegedly stolen
-
Cybersecurity experts face 20 years in prison following ransomware campaignTwo men used their tech expertise to carry out ALPHV BlackCat ransomware attacks
