JBS S.A. Cyberattack
   HOME

TheInfoList



OR:

On May 30, 2021,
JBS S.A. JBS S.A. is a Brazilian company that is the largest meat processing company (by sales) in the world, producing factory processed beef, chicken and pork, and also selling by-products from the processing of these meats. It is headquartered in Sã ...
, a Brazil-based meat processing company, suffered a
cyberattack A cyberattack is any offensive maneuver that targets computer information systems, computer networks, infrastructures, or personal computer devices. An attacker is a person or process that attempts to access data, functions, or other restricted ...
, disabling its beef and pork slaughterhouses. The attack impacted facilities in the
United States The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country primarily located in North America. It consists of 50 states, a federal district, five major unincorporated territorie ...
,
Canada Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tot ...
, and
Australia Australia, officially the Commonwealth of Australia, is a Sovereign state, sovereign country comprising the mainland of the Australia (continent), Australian continent, the island of Tasmania, and numerous List of islands of Australia, sma ...
.


Background

JBS S.A., a Brazil-based meat processing company, supplies approximately one-fifth of meat globally, making it the world's largest producer of beef, chicken, and pork by sales. The attack was compared to the
Colonial Pipeline cyberattack On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that impacted computerized equip ...
, which occurred earlier in the same month. An employee of
Recorded Future Recorded Future is a privately held cybersecurity company founded in 2009, with headquarters in Somerville, Massachusetts. The company specializes in the collection, processing, analysis, and dissemination of threat intelligence. Recorded Future ...
referred to the attack as the largest to date to impact a company focused on food production. Some forty additional attacks on food producers occurred in the twelve months preceding the JBS attack, with targets including beverage company
Molson Coors The Molson Coors Beverage Company is an American-Canadian multinational drink and brewing company incorporated under Delaware General Corporation Law and headquartered in Golden, Colorado and Montreal, Quebec. Molson Coors was formed in 2005 ...
.


Impact

All facilities belonging to
JBS USA JBS USA Holdings, Inc. is an American food processing company and a wholly owned subsidiary of the multinational company JBS S.A. The subsidiary was created when JBS entered the U.S. market in 2007 with its purchase of Swift & Company. JBS speci ...
, JBS' American subsidiary, including those focused on pork and poultry, faced disruption due to the attack. All JBS-owned beef facilities in the United States were rendered temporarily inoperative. Impacted slaughterhouses were located in states including Utah, Texas, Wisconsin, and Nebraska. A notable shutdown was the JBS beef facility in Souderton, Pennsylvania, which is the largest such facility east of Chicago, according to JBS. The beef industry in Australia faced disruption as a result of the attack. JBS "stood down" some 7000 Australian employees on June 2. The
U.S. Department of Agriculture The United States Department of Agriculture (USDA) is the federal executive department responsible for developing and executing federal laws related to farming, forestry, rural economic development, and food. It aims to meet the needs of com ...
was unable to offer wholesale beef and pork prices on June 1. Due to predicted shortfalls in meat production and price increases, the USDA encouraged other companies to increase production. JBS indicated on June 1 that most of its facilities would resume functioning on June 2. The attack heightened awareness of consolidation in the meatpacking industry in the United States, and the corresponding vulnerability to decreased production, should one of the four major meat producers reduce its output. JBS paid the hackers an $11 million ransom. The ransom was paid in
Bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
. American politician
Carolyn Maloney Carolyn Jane Maloney (née Bosher, February 19, 1946) is an American politician serving as the U.S. representative for since 2013, and for from 1993 to 2013. The district includes most of Manhattan's East Side, Astoria and Long Island City i ...
criticized the company for paying the ransom due to concerns it might incentivize further attacks. The attack brought attention to the potentially negative consequences of consolidation in meat production.


Responsibility

The White House announced that the cyberattack was likely conducted by a Russian organization, and news outlets reported that
REvil REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private ransomware-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the ra ...
was culpable. As of June 2, REvil had not taken credit for the attack, and the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and its principal Federal law enforcement in the United States, federal law enforcement age ...
was conducting an investigation into its origins. After a 9 July 2021 phone call between United States president Joe Biden and Russian president
Vladimir Putin Vladimir Vladimirovich Putin; (born 7 October 1952) is a Russian politician and former intelligence officer who holds the office of president of Russia. Putin has served continuously as president or prime minister since 1999: as prime min ...
, Biden told the press, "I made it very clear to him that the United States expects when a ransomware operation is coming from his soil even though it’s not sponsored by the state, we expect them to act if we give them enough information to act on who that is." Biden later added that the United States would take the group's servers down if Putin did not. On 13 July 2021, REvil websites and other infrastructure vanished from the internet.


References

{{Hacking in the 2020s, state=collapsed 2021 in computing Hacking in the 2020s May 2021 crimes in the United States Cyberattacks Crime in Australia 2020s crimes in Canada 2020s crimes in Brazil