Everything we know about the Peter Green Chilled cyber attack
A ransomware attack on the chilled food distributor highlights the supply chain risks within the retail sector
Following cyber attacks on several British retailers, food logistics company Peter Green Chilled has been hit by a ransomware attack too.
In an email seen by the BBC, the firm, which supplies several major UK supermarkets, said the incident took place last week, but that its transport operations weren't affected.
The distributor is working with clients on how to keep deliveries going, it said, but has suspended order processing for the time being. It's not known whether the company has received a ransom demand, or who carried out the attack.
Somerset-based Peter Green transports chilled food, mainly to regional stores. It supplies several major supermarkets in the UK, including Asda, Morrisons, Sainsbury's, Tesco, and Waitrose, as well as M&S and Co-op.
The short shelf life of the products that the company handles increases the pressure to pay the ransom - though it's not known whether Peter Green has done so. The tactic mirrors the strategy used by attackers when targeting the healthcare and manufacturing sectors, focusing on operational disruption rather than data theft.
"Food suppliers like Peter Green Chilled are increasingly attractive targets for cybercriminals - not just for the data they hold, but because any operational disruption has immediate and far-reaching consequences. In industries where downtime hits supply chains within hours, the stakes couldn’t be higher," said Lee Driver, vice president of managed security services at Ekco.
"Like retail, the food supply chain is a sprawling ecosystem of suppliers, logistics providers, and digital infrastructure. Once attackers find a way in, they can move laterally at speed - crippling systems that underpin everything from production to delivery."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The incident follows recent attacks on the Co-op, Harrods, and M&S - the latter of which is continuing to feel the consequences. The company said this week that it expects disruption to its online services to last until July and that its profits are likely to be down by around £300 million as a result.
According to Sophos, 45% of retail organizations were hit by ransomware last year - down from 69% in 2023. However, the retail sector reported the second-highest data extortion rate, at 5%, and the mean cost to recover was $2.73 million, up from $1.85 million in 2023.
Six-in-ten organizations paid the ransom, marking an increase from 43% the year before, although the average payment fell by two-thirds.
"In food retail, even short-term disruption can lead to spoilage, logistical bottlenecks, and loss of consumer trust," commented David Mound, senior penetration tester at third-party risk management platform SecurityScorecard.
"Attackers are no longer just targeting data; they’re targeting urgency. In environments where product expiration and just-in-time delivery are business-critical, threat actors understand that every hour offline amplifies the pressure to pay."
MORE FROM ITPRO
- ]Why retail is a top target for cyber attacks
- Harrods hit by cyber attack as UK retailers battle threats
- Cyber attacks have rocked UK retailers – here's how you can stay safe
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Unlocking data experience as the new revenue opportunity for channel partnersIndustry Insights Upskilling in integration governance will separate the channel winners from the channel losers
-
Acer Revo RB-102 reviewReviews You won't want to hide this gorgeous little mini PC away – but if it's power you're after, you may be left wanting
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals