First reportedJune 1, 2021
ActivityMay 30, 2021
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • JBS operations in North America and Australia
  • Suppliers and customers dependent on JBS processing capacity

Initial access

  • unknown

Impact

  • encryption
  • service_disruption
  • financial_loss
  • extortion

Attribution

unknown low confidence

Public reporting speculated about the ransomware operator; JBS statements in cited sources do not provide definitive attribution.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1486: The event is described as a ransomware attack that disrupted operations and required restoration, consistent with encryption for impact.

Mitigations

Now

  • Maintain offline/immutable backups and regularly test restoresEnables recovery without paying ransom and reduces business downtime when systems are encrypted or wiped.

Soon

  • Segment networks and restrict administrative privilegesSlows attacker movement and limits the blast radius of ransomware deployment across the enterprise.

Later

  • Harden endpoints/servers with EDR and restrict remote admin toolsImproves detection and blocking of ransomware behaviors and common lateral-movement mechanisms used to deploy payloads.

Detection ideas

Detect mass file encryption or destructive file operations

Alert on rapid renames/overwrites across many directories, creation of ransom notes, and high-entropy writes by unfamiliar processes.

Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs

Detect lateral movement and remote execution used for ransomware deployment

Look for PsExec/SMB service creation, remote scheduled tasks, or WMIC usage followed by execution of the same binary on multiple hosts.

Data sources: EDR telemetry, Windows Security Event Logs, Network flow logs

Sources