EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/jbs-foods-ransomware-2021
183/430

File EL-0248CriticalResolvedCyberattack / Ransomware / Critical Infrastructure

JBS Foods Ransomware Attack (2021)

Also filed as JBS REvil Ransomware · Meat Supply Chain Cyberattack

REvil ransomware group attacked JBS Foods, the world's largest meat processor, disrupting operations across the US, Canada, and Australia. The attack forced the shutdown of all JBS beef plants in the US, threatening the national meat supply chain. JBS paid an $11 million ransom to restore operations.

  • #jbs
  • #revil
  • #ransomware
  • #food-supply-chain
  • #critical-infrastructure
  • #2021
Notoriety9/10
Event
30 May 2021
Disclosed
30 May 2021
Target
JBS Foods
Actor
REvil
Status
Resolved

01Summary

On May 30, 2021, JBS Foods was hit by a sophisticated ransomware attack attributed to the REvil (Sodinokibi) group. The attack encrypted servers and systems across JBS's global operations, forcing the shutdown of all JBS-owned beef processing plants in the United States, as well as facilities in Canada and Australia. The disruption threatened a significant portion of the US meat supply, as JBS processes approximately 20% of the nation's meat. After negotiations with the attackers, JBS USA ultimately paid an $11 million ransom in Bitcoin to restore affected systems. The attack highlighted the vulnerability of critical food infrastructure to ransomware and triggered a White House response.

02Background

JBS is the world's largest meat processing company, headquartered in Brazil with major operations in the US, Australia, Canada, and Europe. The company processes beef, pork, and lamb for global distribution. The ransomware attack came just weeks after the Colonial Pipeline ransomware attack, heightening concerns about critical infrastructure vulnerabilities.

03Key revelations

  1. 01Critical food infrastructure is vulnerable to ransomware attacks.
  2. 02JBS paid $11M ransom, becoming the second major infrastructure company to pay after Colonial Pipeline.
  3. 03The attack demonstrated the global reach of Russian-speaking ransomware groups.

04Technical analysis

The REvil group gained access to JBS's network through compromised credentials or exploited vulnerabilities. Ransomware was deployed to encrypt file servers and backup systems. The group used a combination of encryption and data exfiltration to maximize leverage.

Attack vector
Unknown (likely compromised credentials or vulnerability exploitation)
Attack method
Ransomware deployment and data exfiltration
Exfiltration
Data theft prior to encryption
Tool / malware
REvil Ransomware (Sodinokibi)
Malware family
REvil
Malware type
Ransomware

MITRE ATT&CK techniques

  • T1486

05Threat actor

REvil (Sodinokibi) was one of the most prolific Russian-speaking ransomware groups, operating a ransomware-as-a-service (RaaS) model. The group targeted large enterprises globally, demanding multimillion-dollar ransoms.

Aliases

  • Sodinokibi

Attribution sources

  • FBI Confirmation
  • JBS USA Statement
  • Media Reports

06Victims and impact

Additional victims

  • US Meat Supply Chain
  • Australian Meat Processing Plants
  • Canadian Meat Processing Plants

Countries affected

  • United States
  • Australia
  • Canada
  • Brazil

07Data exposed

Data types

  • Corporate Data
  • Operational Systems
  • Financial Records

08Financial damage

$11M ransom paid; additional costs for recovery, lost production, and security upgrades.

09Timeline

  1. 2021-05-30REvil ransomware attack hits JBS Foods; US beef plants shut down.
  2. 2021-06-02JBS USA resumes operations after paying $11M ransom.
  3. 2021-06-09JBS confirms ransom payment in a public statement.

10Key figures

  • Andre NogueiraCEO JBS USA · JBS USABrazilianApproved ransom payment of $11M.

11On the record

This was a very difficult decision to make — for our company, our team members, and our customers.

Andre Nogueira (JBS USA CEO), Statement regarding the ransom payment.

12Reaction and fallout

Public reaction

The attack caused panic buying and supply concerns in the US. It intensified the national debate about ransomware payments and critical infrastructure protection.

Political impact

The White House directly addressed the attack, and President Biden raised the issue of ransomware with Russian President Putin. It led to increased government focus on food sector cybersecurity.

Geopolitical consequences

The attack strained US-Russia relations as the FBI attributed REvil to Russian-speaking actors. It contributed to the broader diplomatic crisis over ransomware safe havens.

13Legal

No arrests were made. The FBI investigated but REvil's Russian-based operators were outside US jurisdiction.

14Aftermath

Policy changes

  • Increased federal cybersecurity requirements for the food and agriculture sector.

Regulatory changes

  • TSA issued security directives for pipeline operators similar to those later considered for food processors.

Security improvements

  • JBS implemented enhanced network segmentation and backup systems.

15Significance and legacy

Significance

The JBS attack, following Colonial Pipeline, demonstrated that ransomware could disrupt critical food supply chains and force multimillion-dollar ransom payments from essential infrastructure companies.

Legacy

The attack was a wake-up call for the agriculture sector and contributed to the US government's broader crackdown on ransomware groups.

16Disclosure and media

Authentication
JBS disclosure and media reporting

Publishing organisations

  • JBS USA

17Related files

Related events

  • Colonial Pipeline DarkSide attack (2021)
  • Kaseya REvil attack (2021)

Inspired by

  • Colonial Pipeline attack (2021)

18Field notes

  1. 01JBS processes about 20% of all US meat, making the attack a national security concern.
  2. 02The $11M ransom was paid in Bitcoin, which was then worth significantly less after the crypto crash.
  3. 03The attack occurred just weeks after DarkSide targeted Colonial Pipeline, creating a 'ransomware spring' crisis.

19Resolution

Ransom paid. Systems restored over several days. Production resumed.

20Sources

Official documents

  • JBS USA statement (June 2021)

References

  1. [1]JBS USA corporate statements
  2. [2]FBI confirmation
  3. [3]Media reports (Reuters, Bloomberg, CNN)
Fact sheetEL-0248

Dates

Event
30 May 2021
Started
30 May 2021
Ended
2 Jun 2021
Duration
11 days
Discovered
30 May 2021
Disclosed
30 May 2021
Resolved
9 Jun 2021
Ongoing
No

Target

Organisation
JBS S.A. (global meat processing company)
Type
Corporation
Sector
Food Processing / Agriculture
Country
Brazil

Actor

Name
REvil
Type
Criminal Gang
Nationality
Likely Russian
Affiliation
Russian-speaking ransomware group
Motivation
Financial gain through ransom payment.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Confidential
Published
No
Sold (dark web)
No

Money

Ransom asked
$11,000,000
Ransom paid
$11,000,000
Damage
$11,000,000
Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.