United Natural Foods Inc. (UNFI), one of the largest food wholesalers in the US and a key partner of Amazon's Whole Foods, confirmed that it has restored its critical operating systems following a cyberattack that occurred on June 5, 2025.

According to a recent update from the company, the ordering and invoicing systems are now fully operational, while deliveries to stores are taking place at “smoother levels.” The incident appears to have been contained, although the consequences for the business are noticeable.
In an official filing with the US Securities and Exchange Commission (SEC), UNFI said the attack could have a material impact on net income and adjusted EBITDA for the fourth quarter of fiscal year 2025.
See also: Hawaiian Airlines suffers cyberattack – Flights continue
“In the weeks following the attack, we experienced a decline in sales volume and an increase in operating costsas we worked to ensure uninterrupted customers our,” the company said, adding that it also incurred significant costs to investigate and restore the affected systems.
United Natural Foods has cybersecurity insurance, which is expected to cover much of the losses, although the process is estimated to be completed within fiscal year 2026.
The incident came to light when social media users began reporting widespread problems with the company's network, shift cancellations and the inability to fulfill orders, raising questions about crisis management in the logistics industry.
See also: Ahold Delhaize breach affects 2.2 million people
The company has not yet disclosed details about the nature of the cyberattack or whether it is the work of an organized ransomware group. However, in its filing with the US Securities and Exchange Commission (SEC), it made it clear that it does not plan to send notifications to consumers, as the attack is not related to a personal data breach.

The incident puts UNFI on the list of food businesses that have been targeted by cyberattacks. In March, Sam's Club, a Walmart subsidiary, investigated a breach allegedly linked to the Clop gang, while JBS Foods, the world's largest meat producer, paid an $11 million ransom in 2021 to regain control of its systems after an attack by the REvil gang.
The incident at United Natural Foods is indicative of the increasing intensity and sophistication of cyberthreats in the supply chain, particularly when it concerns critical food supply chains. This attack did not have a direct impact on personal data, but the fact that it affected ordering, pricing and distribution systems at a company that serves tens of thousands of points of sale shows how vulnerable even large businesses with sophisticated infrastructure are.
See also: Man pleads guilty to network hacking
The good news is that UNFI responded quickly and activated external experts, showing professionalism and seriousness. However, the incident proves once again that cybersecurity is no longer an afterthought, but a core operational foundation, especially in critical areas.
If such attacks continue, we may see regulators impose stricter security requirements on the industry, as has been done with other critical infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
