JBS, the world’s largest meat processor, paid an $11 million ransom after a cyberattack attributed by the FBI to the REvil ransomware group disrupted operations across North America and Australia. The attack temporarily disabled all of the company’s meat processing plants in the United States, led to plant shutdowns and canceled shifts, and raised concerns about meat supply and prices because of JBS’s central role in the food supply chain. The White House said the company had reported a ransom demand from a criminal organization likely based in Russia, while the FBI investigated and CISA provided technical support as JBS worked to restore systems.
JBS said it decided to pay after most affected facilities were back online in order to reduce the risk that stolen or encrypted data could be destroyed and to limit further disruption to customers and suppliers. The payment drew immediate political scrutiny in Washington: House Oversight and Reform Committee Chair Carolyn Maloney demanded records and an explanation from CEO Andre Nogueira, arguing that ransom payments can encourage more attacks and that Congress needs details from major incidents like JBS and Colonial Pipeline to shape ransomware and cybersecurity legislation.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
House Oversight and Reform Committee Chair Carolyn Maloney sent a letter to JBS USA CEO Andre Nogueira seeking documents and explanations about the company's ransom payment and communications with the attackers. She argued that such payments set a dangerous precedent and that Congress needed details to inform ransomware legislation.
JBS paid an $11 million ransom to the attackers after the incident, saying it did so to prevent critical data from being destroyed and to reduce disruption to its operations. The payment later drew political and public scrutiny because of JBS's role in the food supply chain.
As the disruption became public, the White House said JBS had reported a ransom demand from a criminal organization likely based in Russia. The FBI later attributed the ransomware attack to REvil and CISA provided technical support during the response.
JBS reported significant progress restoring affected systems and said the vast majority of its plants were expected to be operational by the following Wednesday. The company also said its backup servers were not affected.
JBS SA disclosed a cyberattack that disrupted production in North America and Australia, causing plant shutdowns and canceled shifts. The incident temporarily disabled all of the company's meat processing plants and raised concerns about food supply impacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
thehill.com
Open sourceabc.net.au
Open sourcezdnet.com
Open sourcetheverge.com
Open sourcemarketwatch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.