Editorial draft v1 · Evidence reader R3 · Evidence cutoff: July 16, 2025
Disclosures covered: Dated June 9, 11, 13, 15, and 26 statements on one retained UNFI page, followed by its July 16 business update. The June page's overall June 26 date does not redraft every earlier statement as a June 26 account.
UNFI's June 2025 incident account followed an operational recovery in stages: systems were taken offline after unauthorized activity, distribution and ordering capabilities returned gradually, and core electronic ordering and invoicing were restored by the June 26 statement. A July update then estimated the effects on several fiscal-2025 financial measures. The retained sources establish disruption and response, but do not establish a confidentiality impact or a final incident-loss total. June statements · July business update
The June progression
The June 9 statement said UNFI had identified unauthorized activity, taken some systems offline, and initiated an investigation with forensic experts. It notified law enforcement and was assessing the activity while working to bring systems back online safely. Its stated priority was minimizing disruption for customers, suppliers, and employees. The passage does not give a precise intrusion or discovery time. June statements
On June 11, UNFI said ordering and receiving capabilities were gradually coming back online, with increased capacity the goal for coming days. The June 13 update said the vast majority of distribution centers were shipping and receiving products. Electronic-order acceptance was still part of the expected capacity increase, and manual workarounds remained necessary where appropriate. The investigation was ongoing. These statements describe successive restoration stages, rather than complete recovery at the first update. June statements
The June 15 statement said UNFI was receiving orders and delivering products across North America, while still restoring electronic ordering and using alternative processes. On June 26, it said the incident was contained and the core systems used by retail customers and suppliers had been safely restored. Electronic ordering and invoicing were back online, and deliveries across the network were at more normalized levels. That wording is more specific than a blanket assertion that every consequence had ended. June statements
July estimates with different financial meanings
On July 16, UNFI revised its outlook for fiscal 2025, a 52-week year ending August 2. The revision reflected both performance in the first three quarters and estimated effects of the cyber incident. Management described operations as returning to more normalized levels. Its incident-impact estimates were forecasts for the fiscal year, not a report of final realized costs. July business update
| Fiscal-2025 measure | Estimated incident impact | Scope |
|---|---|---|
| Net sales | Approximately $350 million–$400 million | Sales effect |
| Net (loss) income | $50 million–$60 million | Includes estimated tax impact |
| Adjusted EBITDA | Approximately $40 million–$50 million | Company's adjusted earnings measure |
These are different financial measures of the incident's effect and must not be added together as separate loss components. UNFI said the estimates excluded anticipated insurance proceeds, which it expected would be adequate for the incident. That expectation is not evidence of proceeds received. It did not then expect a meaningful operational or financial impact beyond the fourth quarter of fiscal 2025, apart from insurance reimbursement. July business update
The outlook was forward-looking, based on management's estimates and subject to risks outside its control. The selected July disclosure therefore does not settle final financial effects or actual insurance recovery. Its expected lack of meaningful later impact also remains a forecast made at that time, rather than a permanent assurance. July business update
The limits of this account
Editorial interpretation: the dated statements make it possible to distinguish distribution activity, electronic ordering, and restoration of core systems instead of compressing recovery into one undated claim. The financial update adds another stage without proving facts the operational statements did not address. This evidence slice does not identify an attacker, establish exfiltration or an affected-person count, disclose a ransom, or supply a forensic root cause. The absence of those findings here is a limit on the account, not proof of no confidentiality impact. June statements · July business update
Sources
Statement page — overall page date June 26, 2025; dated sections June 9, 11, 13, 15, and 26.
Business update — July 16, 2025; fiscal-2025 outlook.