KFC Japan suspended online ordering and delivery services nationwide after a cyberattack on logistics provider Nichirei Corp. disrupted ingredient shipments to restaurants across the country. The unauthorized intrusion reportedly struck Nichirei's systems on July 13, causing logistics failures that began affecting KFC locations the following day and interrupting deliveries of frozen foods and other products.
KFC Japan warned that restaurants nationwide could face product shortages, reduced menus, shortened operating hours, and temporary closures as recovery efforts continue. Online orders through the company's app, website, and third-party delivery platforms were halted, and neither KFC Japan nor Nichirei has disclosed a restoration timeline, the specific attack type, or whether any customer or employee data was compromised.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Nichirei said it would start gradually restoring operations affected by the cyberattack beginning Friday. The company did not provide a timeline for full recovery as refrigerated warehouse and shipping operations remained disrupted.
Reporting on July 17, 2026 said Nichirei's cyberattack-related outage was disrupting additional downstream firms, including Ezaki Glico and Kura Sushi. The impacts included delayed ice cream shipments, possible menu changes, and delivery delays, extending the known fallout beyond previously reported retailers and KFC Japan.
NHK reported that Nichirei's system failures were also affecting major retailers and delivery services, including reduced stock at some Aeon and Don Quijote outlets and possible delivery issues for Co-opdeli orders. This expanded the known downstream impact beyond KFC Japan.
Nichirei said some of the servers impacted by the intrusion contained personal information and that it notified Japan's data protection authorities while investigating the incident. The company did not identify the attackers or intrusion method.
Amid the logistics disruption, KFC Japan suspended online ordering through its app, website, and third-party delivery integrations. The company said restoration timing was unclear while the provider worked to recover systems.
Beginning July 14, 2026, the provider's system failure disrupted ingredient deliveries to KFC restaurants across Japan. KFC warned stores could face shortages, reduced menus or hours, and temporary closures.
KFC Japan said a cyberattack struck its third-party logistics provider on July 13, 2026. Teiss identified the provider as Nichirei Corp., which disclosed an unauthorized intrusion affecting its logistics systems and shipments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
10 references tracked. Mallory keeps watching after this page renders.
businessinsurance.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcenichirei.co.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.