News

Whole Foods supplier cyber incident disrupts deliveries, leaves shelves bare

UNFI's cyber incident hit Whole Foods with shortages and empty shelves, and UNFI later said the breach could cut fiscal 2025 sales by up to $400 million.

Derek Washington··2 min read
Published
Listen to this article0:00 min
Whole Foods supplier cyber incident disrupts deliveries, leaves shelves bare
Source: cyberscoop.com

United Natural Foods said its core systems were back online by June 26 after a June 5 cyber incident forced some systems offline and disrupted the flow of groceries to Whole Foods Market, its primary distributor. For store workers, the damage showed up fast: out-of-stocks, substitutions, more customer questions and extra work in receiving and merchandising.

The shelves told the story in plain sight. NBC News reported empty shelves at Whole Foods stores across the country, and Forbes published photos on June 19 showing bare frozen-food cases at a Whole Foods in San Rafael, California, after the UNFI incident. In a specialty grocery chain where freshness and assortment drive the customer experience, a distribution failure quickly becomes a front-end problem for team members trying to explain missing products and keep the floor looking stocked.

AI-generated illustration
AI-generated illustration

UNFI said in its June 26 update that the incident had been contained, that core systems used by retail customers and suppliers were safely restored, and that electronic ordering and invoicing were back online. That mattered because Whole Foods has long leaned on UNFI as its main wholesale grocery distributor, and the companies extended that partnership to 2032 in 2024. When one supplier with that kind of reach goes down, store leaders and inventory teams are left leaning harder on contingency plans, safety stock and clean back-room records to keep deliveries moving.

Related stock photo
Photo by Roy Broo

The financial hit stretched beyond the immediate labor burden. Reuters reported on July 16 that UNFI expected a $350 million to $400 million hit to fiscal 2025 net sales from the unauthorized activity. CyberScoop also reported that UNFI said the cyberattack would reduce quarterly earnings. The incident fit a wider run of ransomware and extortion attacks hitting retailers, including grocery chains, and it showed how quickly a distributor’s cyber failure can become a store-level operations problem for Whole Foods workers.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More Whole Foods Market News