01Summary
On May 30, 2021, JBS Foods was hit by a sophisticated ransomware attack attributed to the REvil (Sodinokibi) group. The attack encrypted servers and systems across JBS's global operations, forcing the shutdown of all JBS-owned beef processing plants in the United States, as well as facilities in Canada and Australia. The disruption threatened a significant portion of the US meat supply, as JBS processes approximately 20% of the nation's meat. After negotiations with the attackers, JBS USA ultimately paid an $11 million ransom in Bitcoin to restore affected systems. The attack highlighted the vulnerability of critical food infrastructure to ransomware and triggered a White House response.
02Background
JBS is the world's largest meat processing company, headquartered in Brazil with major operations in the US, Australia, Canada, and Europe. The company processes beef, pork, and lamb for global distribution. The ransomware attack came just weeks after the Colonial Pipeline ransomware attack, heightening concerns about critical infrastructure vulnerabilities.
03Key revelations
- 01Critical food infrastructure is vulnerable to ransomware attacks.
- 02JBS paid $11M ransom, becoming the second major infrastructure company to pay after Colonial Pipeline.
- 03The attack demonstrated the global reach of Russian-speaking ransomware groups.
04Technical analysis
The REvil group gained access to JBS's network through compromised credentials or exploited vulnerabilities. Ransomware was deployed to encrypt file servers and backup systems. The group used a combination of encryption and data exfiltration to maximize leverage.
- Attack vector
- Unknown (likely compromised credentials or vulnerability exploitation)
- Attack method
- Ransomware deployment and data exfiltration
- Exfiltration
- Data theft prior to encryption
- Tool / malware
- REvil Ransomware (Sodinokibi)
- Malware family
- REvil
- Malware type
- Ransomware
MITRE ATT&CK techniques
- T1486
05Threat actor
REvil (Sodinokibi) was one of the most prolific Russian-speaking ransomware groups, operating a ransomware-as-a-service (RaaS) model. The group targeted large enterprises globally, demanding multimillion-dollar ransoms.
Aliases
- Sodinokibi
Attribution sources
- FBI Confirmation
- JBS USA Statement
- Media Reports
06Victims and impact
Additional victims
- US Meat Supply Chain
- Australian Meat Processing Plants
- Canadian Meat Processing Plants
Countries affected
- United States
- Australia
- Canada
- Brazil
07Data exposed
Data types
- Corporate Data
- Operational Systems
- Financial Records
08Financial damage
$11M ransom paid; additional costs for recovery, lost production, and security upgrades.
09Timeline
- 2021-05-30REvil ransomware attack hits JBS Foods; US beef plants shut down.
- 2021-06-02JBS USA resumes operations after paying $11M ransom.
- 2021-06-09JBS confirms ransom payment in a public statement.
10Key figures
- Andre NogueiraCEO JBS USA · JBS USABrazilianApproved ransom payment of $11M.
11On the record
This was a very difficult decision to make — for our company, our team members, and our customers.
12Reaction and fallout
Public reaction
The attack caused panic buying and supply concerns in the US. It intensified the national debate about ransomware payments and critical infrastructure protection.
Political impact
The White House directly addressed the attack, and President Biden raised the issue of ransomware with Russian President Putin. It led to increased government focus on food sector cybersecurity.
Geopolitical consequences
The attack strained US-Russia relations as the FBI attributed REvil to Russian-speaking actors. It contributed to the broader diplomatic crisis over ransomware safe havens.
13Legal
No arrests were made. The FBI investigated but REvil's Russian-based operators were outside US jurisdiction.
14Aftermath
Policy changes
- Increased federal cybersecurity requirements for the food and agriculture sector.
Regulatory changes
- TSA issued security directives for pipeline operators similar to those later considered for food processors.
Security improvements
- JBS implemented enhanced network segmentation and backup systems.
15Significance and legacy
Significance
The JBS attack, following Colonial Pipeline, demonstrated that ransomware could disrupt critical food supply chains and force multimillion-dollar ransom payments from essential infrastructure companies.
Legacy
The attack was a wake-up call for the agriculture sector and contributed to the US government's broader crackdown on ransomware groups.
16Disclosure and media
- Authentication
- JBS disclosure and media reporting
Publishing organisations
- JBS USA
18Field notes
- 01JBS processes about 20% of all US meat, making the attack a national security concern.
- 02The $11M ransom was paid in Bitcoin, which was then worth significantly less after the crypto crash.
- 03The attack occurred just weeks after DarkSide targeted Colonial Pipeline, creating a 'ransomware spring' crisis.
19Resolution
Ransom paid. Systems restored over several days. Production resumed.
20Sources
Official documents
- JBS USA statement (June 2021)
References
- [1]JBS USA corporate statements
- [2]FBI confirmation
- [3]Media reports (Reuters, Bloomberg, CNN)









