Desk live·
ForensicPost
Ransomware/Availability/File 23-0210

Dole Halted North American Production After Ransomware

Dole shut down its systems across North America in February 2023, halting production plants and shipments. What got recorded was shoppers noticing gaps where the salad kits should have been.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDole Food Company
ActorUnattributed
S. Rosler10 min readConfidence: high3 sources reviewed

In February 2023 Dole Food Company was hit by ransomware and shut down its systems throughout North America, as stated in a 10 February memo to retailers. Production plants were temporarily halted and shipments to grocery stores stopped. Shortages of Dole products were reported on shelves for more than a week. The company later disclosed that employee data had been accessed.

The Measurement Was A Customer Noticing

No regulator required a figure for interrupted production. No count exists for shipments not made or plants idle. What entered the public record was social media complaints about missing salad kits, which reporters then used as the index of severity.

We have argued at 24-1231, 22-0301 and 22-0220 that availability harm goes uncounted. Dole is the case where the only available instrument was a consumer noticing an absence, and a shortage lasting a week in a product category people substitute freely is a very weak instrument for what happened.

Food Production Is Time-Bounded

A halted vehicle line resumes and the vehicles get built later. Fresh produce does not wait for a systems restore.

We filed just-in-time fragility at 22-0301, where one supplier stopped fourteen Toyota plants, and the property is sharper here: the buffer is not merely absent by design, it is impossible. Whatever was in the field during the outage had a fixed window, and no recovery timeline changes that.

The Employee Data Was The Footnote

The disclosure that employee data had been accessed came later and attracted far less attention than the empty shelves.

That is the pattern we have recorded at 23-1219, where a studio’s leaked release plans dominated coverage while employees’ passports sat in the same dump. The visible harm and the serious harm are different, and reporting — from which this database is built — follows the visible one.

How we reported this

Built on contemporaneous reporting, including the company memo to retailers quoted at the time. The February 2023 ransomware attack, the shutdown of systems across North America, the temporary halting of production plants and shipments, the reported shelf shortages lasting more than a week, and the later disclosure that employee data was accessed are as reported. No ransomware operation is named — none was authoritatively identified. No figure for lost production, revenue or affected employees is asserted; none was published. Graded high on the operational facts. Corrections: corrections@forensicpost.com.

Sources
  1. Food producer Dole confirms ransomware attackThe Record
  2. Cyberattack on food giant Dole temporarily shuts down North America productionCNN Business
  3. Dole hit by ransomware, North America operations briefly disruptedCybersecurity Dive
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary