A ransomware attack on Blue Yonder, a supply chain software provider, is affecting major companies worldwide. Starbucks, Jumbo, Hema and other supermarkets worldwide are experiencing disruptions in their logistics processes.
Blue Yonder was hit by a ransomware attack on November 21, crippling the company’s managed services environment. This creates problems for companies that rely on logistics and workforce management software. Starbucks reports disruptions in managing employee time tracking and payroll. Nevertheless, stores remain operational thanks to temporary manual processes.
In the Netherlands, Jumbo and Hema are also experiencing disruptions. Hema had to shut down some systems, slowing down logistics processes. A spokesman for WarehouseTotaal emphasizes that this does not lead to empty shelves in the stores. “It’s a lot more work, but luckily we have backup systems. “We did not have to employ additional staff and there will be no empty shelves in the branches,” said the Hema spokesman.
Jumbo reports similar issues, with no impact on customers. FloraHolland and DHL, also users of Blue Yonder, say they are not experiencing any inconvenience.
According to ComputerWeekly, supermarkets such as Morrisons and Sainsbury’s are experiencing logistical disruptions in the UK. At Morrisons, suppliers had to postpone deliveries while Sainsbury’s moved to emergency measures.
The timing is no coincidence
The timing of the attack, just before Thanksgiving and the US holidays, suggests that the perpetrators wanted to cause as much unrest as possible. U.S. retailers, including major supermarket chains that use Blue Yonder, are preparing for possible impacts on supplies.
Security experts emphasize the importance of third-party risk management. Organizations must be prepared for supplier disruptions, such as through alternative approaches and simulation training. This helps minimize operational downtime in the event of future incidents.
Blue Yonder’s recovery is still underway with the support of external security specialists. A timetable for full restoration to operational status has not yet been announced. The attack highlights the vulnerability of supply chain systems and the need for robust security measures.
You can follow all of Blue Yonder’s updates live via their status page.