KFC Japan: Shortages and Closures Across All Stores — Cause Is Unauthorized Access at Nichirei
In July 2026, KFC Japan announced that stores nationwide may face out-of-stock items, restricted menus, and temporary closures. The cause is a system failure from unauthorized access at Nichirei, the logistics company it uses for ingredient distribution. Online ordering and delivery are suspended too. Here is the timeline of how one company's cyber incident stopped a whole restaurant chain.
Table of contents
In July 2026, KFC Japan announced that stores nationwide may face out-of-stock items, restricted menus, and temporary closures. The cause is a system failure from unauthorized access at Nichirei, the logistics company it uses for ingredient distribution. Online ordering and delivery are suspended too. Here is the timeline of how one company's cyber incident stopped a whole restaurant chain.
Kentucky Fried Chicken Japan announced on July 14, 2026 that KFC stores nationwide may see some items out of stock, restricted menus, shortened hours, and temporary closures. Online ordering via the official app and website, mobile order, delivery, and delivery-agent services are also suspended. The cause is a system failure, from unauthorized access, at the logistics company KFC uses for ingredient distribution.
That contractor is the major frozen-food company Nichirei. Nichirei had disclosed the unauthorized access the previous day, July 13, and its cold-storage warehouse handling and frozen-food shipping ground to a halt. One company's systems being attacked has reached all the way to the counter of a downstream restaurant chain. And it is not only KFC: by July 15, shortages had also surfaced at the conveyor-belt sushi chain Kura Sushi and the major supermarket AEON, spreading the damage across restaurants and retailers. Here we lay out, in order, what customers face, how far the impact has spread, and why one company's outage ripples this widely.
Update, August 14: employee data may have leaked, and the attackers published what they stole
On August 14, 2026, Nichirei published its sixth report on the system failure, saying it had confirmed that some employee information held on the affected servers may have leaked. The items named are "employee names, dates of birth, company email addresses, employee numbers, and other HR and labor-management information" for staff at its domestic group companies. The number of affected people is still under investigation and has not been disclosed. Nichirei says that "at this time, no fact of misuse of this personal information has been confirmed," and that it is continuing the investigation with an outside specialist firm, and will notify affected people if further leakage is confirmed.
In the fourth report on July 22, the company was at the precautionary stage of "we have begun notifying people who may be affected." This time the wording moved a step further, to "we have confirmed the possibility of leakage." It is still not a statement that data has been confirmed to have gone outside the company. Note also that the sixth report concerns Nichirei group employees. It is not an announcement that member data of end customers at KFC or other clients has leaked, so there is no action KFC customers need to take right now.
The attackers actually published the stolen data
Four days before that announcement, on the morning of August 10, RansomHouse published the data it claims to have stolen from Nichirei on its dark-web leak site. At the July 21 claim stage it had only shown "EVIDENCE" and demanded contact; with no deal apparently reached, it moved to publication — the standard arc of an extortion-style group that threatens to release stolen data unless it is paid.
Reports differ on the volume. TV Asahi, citing what the security firm S&J verified, said at least 200,000 files were published, including personal data such as phone numbers of Nichirei employees and business partners. Kyodo News, citing security professionals, reported it appears to be "nearly the entire set of the stolen data." The Nikkei reported the published data includes what appear to be internal general-affairs, HR and accounting records, plus business-partner information. Nichirei's position on this is that it "is aware of it but will refrain from commenting."
The distinction worth holding onto: the parties examining the published data are news organizations and security firms, not Nichirei confirming "this came from us." The attacker claims a theft, third parties confirm that plausible-looking data exists, and the victim stays silent because of the investigation. That three-way gap is a recurring shape in ransomware coverage. What Nichirei has officially acknowledged stops at the sixth report's "possibility of leakage of employee information."
If you do business with Nichirei, treat "messages from Nichirei" with care for a while
Company email addresses combined with HR and labor records are convenient raw material for business email compromise (BEC) — impersonating a real employee to send fake invoices or changes of bank account details. Accounting and purchasing staff at companies that trade with Nichirei should, for the time being, verify any change-of-payee request or unfamiliar attachment bearing a Nichirei contact's name through a channel other than email, such as a phone number they already had on file. Nichirei itself is telling people not to open URLs in suspicious messages, not to enter IDs, passwords or personal information, and not to open attachments.
The financial hit: 800 million yen in operating profit, plus a 1 billion yen extraordinary loss
In its first-quarter results for the year ending December 2026, announced on August 7, Nichirei put numbers on the outage for the first time.
| Item | Impact | Breakdown |
|---|---|---|
| Revenue | approx. -5.0 bn yen | Food approx. 2.0 bn yen / Logistics approx. 3.0 bn yen |
| Operating profit | approx. -0.8 bn yen | Holding co. 0.2 / Food 0.2 / Logistics 0.4 bn yen |
| Extraordinary loss | approx. 1.0 bn yen | Response and recovery costs |
| Downtime | 11 days | Detection to normal ops at all sites |
Full-year guidance was revised at the same time: operating profit from 33.8 bn to 30.0 bn yen, and net profit attributable to owners of the parent from 25.2 bn to 20.4 bn yen. The whole of that cut is not attributable to the cyberattack. Of the 3.8 bn yen reduction in operating profit, roughly 0.8 bn is attributed to the attack; most of the rest comes from other factors such as the situation in the Middle East. The 4.8 bn yen cut to net profit also absorbs the 1.0 bn yen extraordinary loss for recovery costs. Summarising this as "a 4.8 billion yen breach" would misstate it.
That said, the figures that do belong to the attack are substantial: 0.8 bn yen off operating profit, 1.0 bn yen in recovery costs, and roughly 5,000 business partners affected, from 11 days of stopped logistics. As a published data point for estimating what a comparable incident would cost your own organisation, the disclosure is unusually concrete.
The store-level impact is over. In its fifth report on July 24, Nichirei lifted its order-volume restrictions and said warehouse handling and frozen-food shipping had returned to normal operations at all sites. KFC resumed normal operations at all stores on July 22. What remains is the investigation into how far the data actually travelled, and the cleanup. Operations came back; the information does not.
Update, July 22: a ransom claim, personal-data notices, and KFC back to normal hours
An attacker group has claimed responsibility. The extortion-focused ransomware group "RansomHouse" posted a claim of the attack on Nichirei on a dark-web leak site. It lists the attack date as July 13, demands contact by saying it has encrypted data and holds proof, and shows links to allegedly stolen data alongside a threat. This is, however, a one-sided claim by the attacker; Nichirei has not officially confirmed any data exfiltration or the group's involvement. Nichirei describes the method only as a "cyberattack" and has not formally labeled it ransomware, but RansomHouse is known as an extortion-specialized group that dangles the release of stolen data to demand money.
On personal data, the situation moved a step further. Back in its second report on July 15, Nichirei confirmed that some affected servers held personal data and reported it to the Personal Information Protection Commission. Then, in its fourth report on July 22, it disclosed that it had begun notifying affected individuals separately. The key point: this does not mean a leak has been confirmed. It is a precautionary contact to people whose data might be exposed, and there is no official statement that external leakage has been confirmed at this time. If you receive a notice from Nichirei or a partner company, follow the instructions in it calmly.
Recovery advanced substantially. In the fourth report, Nichirei said it plans to return all sites to normal operation within the week. In response, KFC Japan announced on July 22 that it had resumed normal operations at all stores. That said, the investigation into the attack method and whether personal data actually left the company is still ongoing, so the full picture will take a bit more time to settle.
What customers are facing
KFC is warning of the following possible impacts at stores nationwide. Conditions differ by store and change day to day.
| Item | Detail |
|---|---|
| In-store products | Some out of stock, restricted menu |
| Operations | Shorter hours, possible closures |
| Online ordering | App and web both suspended |
| Delivery / pickup | Mobile order, delivery, delivery agents suspended |
| Recovery outlook | Deliveries resuming from Jul 17 (Jul 18 notice) / some stores still short |
| Guidance | Check each store before visiting |
KFC says ingredient deliveries became difficult from July 14, but in a July 18 notice update it said that, following the contractor's staged resumption, deliveries to stores had also resumed in stages. Some stores still see shortages and limited menus, and online ordering, mobile order, delivery, and delivery agents remain suspended. Store operations are fluid: you may find your item unavailable, or the store closed. It urges customers to check each store's status before going.
The sequence so far
Here is the flow from Nichirei's outage coming to light to the impact reaching KFC's counters.
← Swipe to move
Not only KFC: the impact spreads to Kura Sushi and AEON
KFC's announcement stood out at first, but the fallout from Nichirei's outage is spreading across restaurants and retailers. By July 15, the conveyor-belt sushi chain Kura Sushi and the major supermarket AEON had both reported shortages or paused sales of some items. That night the list grew further: the bento chain Hotto Motto and the set-meal chain Yayoiken (both operated by Plenus), and the ice-cream maker Imuraya, also saw shortages or halted shipments. What they share is that they source ingredients and goods through Nichirei's cold-chain logistics (keeping food frozen or chilled in transit).
| Company | Main impact | Guidance |
|---|---|---|
| Kentucky Fried Chicken (KFC) | Nationwide shortages, menu limits, shorter hours, possible closures | Online ordering stopped / check store before going |
| Kura Sushi | Some items out of stock at dozens of stores in the Kansai region | Affected items paused / check at the store |
| AEON | Frozen foods short / online supermarket may pause sales | Sales to resume as supply is confirmed |
| Hotto Motto / Yayoiken (Plenus) | Ingredient shortages on some menu items; service paused | Affected menu items temporarily halted |
| Imuraya | Shipments of some ice-cream products partially halted | Some items hard to get until shipping resumes |
At Kura Sushi, reports say some items such as "yuzu-salt seared bonito" and "aged fugu" are out of stock at dozens of stores in the Kansai region. The cause is a delivery disruption from unauthorized access at a supplier, seen as the impact of Nichirei's outage. Conveyor-belt sushi cycles huge volumes of fresh and frozen ingredients daily, so even a one-day logistics halt quickly shows up on the menu.
At AEON, some items such as frozen foods are out of stock. It has warned that its online supermarket may see shortages or paused sales of frozen foods, ice cream, deli items, and sushi, and says it will resume sales in order as supply is confirmed. That frozen-food shortages appear even at a nationwide supermarket chain shows how widely Nichirei's cold-chain logistics is used behind the scenes of the food supply.
The list grew on the night of the 15th. Plenus, which runs the bento chain Hotto Motto and the set-meal chain Yayoiken, said some menu items had become hard to source and were temporarily paused. The ice-cream maker Imuraya also halted shipments of some products that rely on Nichirei's warehouses. With ice cream and frozen foods at risk of vanishing from shelves in the middle of a heat wave, the impact is steadily becoming visible to consumers.
What these companies share is that none of them was attacked directly; storefront impact comes from one part of the logistics that supports their sourcing and delivery grinding to a halt. Many other companies use Nichirei Logistics' cold chain, so more of them may see shortages or paused sales going forward. None of this is a food-safety issue — it is a supply disruption.
The Nichirei unauthorized access behind it
The starting point is Nichirei. On July 13 it disclosed that its internal systems had suffered unauthorized access by a third party, causing a system outage. The affected operations are the cold-storage warehouse handling run by companies across the Nichirei Logistics Group, and the frozen-food shipping of Nichirei Foods. Even with goods sitting in the warehouse, the systems to move them in and out stopped working, so the goods could not be moved.
According to Nichirei, no leak of personal or customer data outside the company has been confirmed at this point, and the outage is limited to Japan. Meanwhile, the recovery timing is undecided, and the specific method of the unauthorized access — and whether it was ransomware (an attack that holds data hostage for a ransom) — had not been disclosed as of the announcement. It's worth separating what is known from what is not yet known.
On the night of July 15, Nichirei issued a second report stating that its internal servers "were confirmed to have been hit by a cyberattack," formally acknowledging the cause as a cyberattack. It is not disclosing the specific method, citing prevention of further damage. It also said cold-storage handling and frozen-food shipping are expected to resume in stages from July 17 after external security experts verify safety. Because some of the affected servers held personal data, it also disclosed that it had filed an initial report with the Personal Information Protection Commission as a "possible-leak case." No actual external leak has been confirmed at this point, but the investigation continues.
A security lens: what kind of breach, and why Nichirei is a target
It's natural to want to know "what kind of unauthorized access this was," and while Nichirei's second report acknowledged the cause as a cyberattack, as of the night of July 15, 2026, it has not disclosed the intrusion route, the specific method, or whether it was ransomware (an attack that holds data hostage for a ransom). The details of the method are "under investigation," and it says it will not reveal them to prevent further damage. Follow-up reporting also states that the specific systems hit and whether ransomware was involved are still being investigated. What is known: on the early morning of July 13 (around 6:50 a.m.), unauthorized access to internal systems was detected, and the systems running cold-storage handling and frozen-food shipping stopped. No external leak of personal data has been confirmed at this point, but the investigation continues. When a company is hit, pinning down the cause takes time through digital forensics (analyzing records left on devices and networks to determine the intrusion route and scope). Even if definitive claims circulate first, it's safer to wait for official confirmation.
"Was a vulnerability exploited?" is also unknown for now. But in manufacturing and logistics breaches, the common entry points are clear: vulnerabilities in the VPN / remote-access appliances that connect outside to inside, login credentials stolen via phishing, and intrusion through a business partner. VPN appliances in particular are always exposed to the internet and lead deep inside, so they keep being targeted — we track actively exploited VPN appliance flaws and the CISA KEV dashboard of confirmed-exploited vulnerabilities. Which of these applies to Nichirei is something to wait for in follow-up reporting. Recently, beverage giant Asahi Group saw its net profit fall sharply after a ransomware attack, a sign that the food sector is being targeted in succession.
"What kind of organization" is also key to understanding how far the damage spreads. Nichirei's Logistics Group is one of Japan's largest cold-chain logistics operators. Per the company's own figures, its cold-storage capacity holds about an 8.6% domestic share — number one in Japan — and ranks fifth worldwide. It stores and moves the frozen and chilled goods of many food makers, retailers, and restaurant chains: the "invisible infrastructure" of food. That concentration is exactly why, when it stops, the impact spreads widely to partners like KFC — and at the same time, to an attacker, it is a cost-effective target where "stopping one company deals a chained blow." The core of logistics translates an IT outage directly into a real-world "goods don't move." That mechanism is laid out in our explainer on how warehouse and frozen-food flows stop.
Why one company's outage spreads to a whole restaurant chain
Nichirei's Logistics Group is not a company that only moves its own products. It is one of Japan's largest operators of "cold-chain logistics" — storing and moving food while keeping it frozen or chilled — and it handles storage and delivery for many food makers and restaurant chains. KFC was one of them. That is exactly why, when the systems of a single company like Nichirei stop, the storefronts of separate companies that relied on its logistics are hit at the same time.
Frozen and chilled food also has a "time wall" that ambient goods do not. It must be carried within a set time while held at a set temperature, so when systems stop and shipping stalls, filling the gap quickly by other means is hard. If the systems that issue warehouse handling and shipping instructions are down, goods can't leave even if they're in stock. The mechanism by which an IT outage translates directly into "goods don't move" is laid out in detail in our explainer on how a cyberattack halts warehouses and frozen-food flows.
This time it was KFC that surfaced, but many food makers, retailers, and restaurants use Nichirei Logistics' cold chain, and more companies may be affected in the same way. The more that "invisible infrastructure" like logistics is concentrated in one company, the wider and faster the ripple when it stops.
Separating "the contractor" from "Nichirei"
One point to get right: in the notice KFC issued on July 14, it explains the cause as "a system failure at a logistics contractor," and does not name that contractor. Tying the contractor to Nichirei is the reporting by various media outlets, combined with Nichirei's disclosure the day before. It is safer not to conflate KFC's official announcement with media reporting as if they carried the same certainty.
That said, the flow is natural: Nichirei admitted the unauthorized access and its impact on frozen-food shipping on the 13th, and KFC announced the impact from a contractor's outage on the 14th. That KFC outsourced ingredient distribution to Nichirei is reported by multiple outlets. The finer details of the facts are best confirmed by waiting for further announcements from both companies.
What customers should do
If you plan to use KFC, check each store's status before going. Even if a store is open, your item may be out of stock, or the menu may be pared down. Online ordering, mobile order, delivery, and delivery agents are currently stopped, so purchases are in-store only.
There's no need to worry excessively. This is not about the safety of the food itself; it is a supply stall caused by a system outage. There's no reason to stockpile, either. The recovery timing is undecided, but KFC says it will give further notice from the 15th based on the contractor's recovery. The surest way to get the latest is each store's guidance and KFC's official site.
The supply-chain cyber-impact angle
This event has the shape of an attack on one company reaching the business of another company it trades with. Nichirei was attacked, but what actually closes stores or runs out of products are trading partners like KFC that used its logistics. However well you protect your own systems, if a connected partner stops, your business stops too.
Food and logistics are fields where an IT outage becomes visible to consumers as "goods don't arrive." That's exactly why preparing in advance for how to move when a contractor or partner goes down — switching to manual work, alternate logistics, how much stock to hold — pays off in keeping the business from stopping entirely. That way of thinking is collected in our piece on logistics and cold-chain preparedness.
Summary
On July 14, 2026, KFC Japan announced that stores nationwide could see out-of-stock items, restricted menus, shorter hours, and temporary closures, and it suspended online ordering and more. The cause is a system failure, from unauthorized access, at the logistics company it uses for ingredient distribution. That contractor is reported to be Nichirei, which disclosed the unauthorized access and its impact on frozen-food shipping the day before, on the 13th. In a second report on the night of the 15th, Nichirei formally acknowledged the cause as a cyberattack and said warehouse handling and frozen-food shipping are expected to resume in stages from July 17. Because some affected servers held personal data, it filed an initial report with the Personal Information Protection Commission as a possible-leak case, though no actual leak has been confirmed so far.
The impact reaches beyond KFC: by July 15 it had spread to Kura Sushi (items out of stock at dozens of Kansai stores) and AEON (frozen-food shortages and paused online-supermarket sales), and that night to Hotto Motto and Yayoiken (Plenus) and Imuraya (halted ice-cream shipments). For customers: check each company's and store's status before visiting or ordering. Because this is not a food-safety issue, there's no need for excessive worry or stockpiling. This is also a case where concentrating cold-chain logistics in one company exposed a modern supply-chain weakness — when that one stops, the impact spreads to multiple partners at once. We'll keep following updates, including the impact on other companies that use Nichirei Logistics.
FAQ
Q. Why is KFC running out of items or closing temporarily?
Because the logistics company KFC uses for ingredient distribution suffered a system failure from unauthorized access. That company's cold-storage handling and shipping stopped, making ingredient deliveries to KFC stores difficult. KFC itself was not attacked, and this is not a food-safety issue.
Q. Is only KFC affected? What about Kura Sushi and AEON?
Not only KFC. Kura Sushi has some items — such as "yuzu-salt seared bonito" and "aged fugu" — out of stock at dozens of stores in the Kansai region. AEON also has shortages of frozen foods, and warned its online supermarket may pause sales of ice cream, deli items, and sushi. All of them use Nichirei's cold-chain logistics, and the impact stems from the supply disruption. Because many companies rely on Nichirei Logistics, more may be affected going forward.
Q. When will it recover?
It has recovered. In its fifth report on July 24, Nichirei lifted order-volume restrictions and said warehouse handling and frozen-food shipping had returned to normal operations at all sites — full recovery in 11 days from detection. KFC resumed normal operations at all stores on July 22, covering in-store sales, mobile order, web order, delivery, delivery agents and coupons. No impact from this outage remains at KFC stores.
Q. Was personal data leaked?
In its sixth report on August 14, Nichirei said it had confirmed the possibility that some employee data at its domestic group companies leaked: names, dates of birth, company email addresses, employee numbers and other HR/labor-management information. The count is still under investigation, and no misuse has been confirmed at this time. This concerns Nichirei group employees; it is not an announcement that end-customer member data at KFC or other clients leaked. Separately, on August 10 the attacker group RansomHouse published data it claims to have stolen, and reporting citing a security firm put it at more than 200,000 files. That is an attacker claim plus third-party observation: Nichirei says it is aware of it but will refrain from commenting, and has not officially acknowledged the data as its own.
Sources
- ▸KFC Japan - On the impact to some stores from a logistics contractor's system failure (official, July 14, 2026)
- ▸ITmedia NEWS - KFC faces nationwide shortages and closures; cause is unauthorized access at Nichirei
- ▸Nichirei - On the unauthorized access to our servers (2nd report, official, July 15, 2026)
- ▸ITmedia NEWS - Nichirei confirms cyberattack; operations to resume in stages from the 17th; impact also at Plenus and Imuraya
- ▸ITmedia NEWS - Unauthorized access at Nichirei disrupts frozen-food shipping
- ▸ITmedia NEWS - Kura Sushi hit by delivery trouble; cause is unauthorized access at a supplier
- ▸TV Asahi (ANN) - Nichirei breach impact: shortages at AEON, shorter KFC hours
- ▸LOGISTICS TODAY - Unauthorized access to Nichirei's systems affects cold-storage handling
- ▸Nichirei - System Failure at Our Group (6th report, official, August 14, 2026)
- ▸Nichirei - System Failure at Our Group (5th report, official, July 24, 2026)
- ▸Nichirei - Consolidated Financial Results for Q1 FY2026 (official PDF, August 7, 2026)
- ▸Nikkei - Hacker group publishes data stolen in the Nichirei cyberattack
- ▸Nikkei - Nichirei says employee information may have leaked
- ▸ITmedia NEWS - Nichirei: possible leak of group employees' names and company email addresses
- ▸LOGI-BIZ online - Nichirei expects a 5.0 bn yen revenue hit and books a 1.0 bn yen extraordinary loss
- ▸piyolog - A running timeline of the Nichirei Group system failure caused by a cyberattack
- ▸Related: A cyberattack halted warehouses and frozen-food flows — why an IT outage stops physical goods (this site)

Makoto Horikawa
Backend Engineer / AWS / Django