Desk live·
ForensicPost
Ransomware/Availability/File 23-0412

Ransomware at One NCR Data Centre Stopped Restaurants Running Their Own Back Office

Aloha powers ordering and back-office work for thousands of restaurants. When a single NCR data centre went down, operators could not manage payroll or online orders — and the people affected were franchisees with no relationship to the compromised system.

Constructed geometry · not a chart of case data
TargetNCR Aloha customers
ActorALPHV/BlackCat
S. Rosler10 min readConfidence: high2 sources reviewed

NCR reported an outage affecting point-of-sale systems on 12 April 2023 and determined the following day that the cause was ransomware in one of its data centres. The company stated the affected facility did not store customer financial information.

The disruption reached Aloha point-of-sale applications supporting online ordering and back-office functions including payroll. Reporting named affected restaurant brands and described effects primarily in the US, with some online ordering services affected in Europe and Asia Pacific.

The Loss Was Operational, Not Informational

No customer financial data is recorded as taken here. What restaurants lost was the ability to run themselves — to take online orders, to process payroll, to do the administrative work a shift depends on.

The corpus argues at 24-1231 that availability harm goes unrecorded because no notification regime asks for it. A restaurant that cannot run payroll has staff who are not paid on time, and there is no filing anywhere that captures that.

One Data Centre, Thousands Of Businesses

NCR stated only one data centre was affected. That is a small blast radius by the company’s own architecture and an enormous one by every other measure, because what sat in it was a service thousands of independent businesses run on.

This is the concentration argument the corpus files at 23-0110 for a single postal distribution centre and 26-0704 for shared airport platforms. The unit that matters is not the facility; it is the number of organisations that stop when it does.

The Affected Party Has No Standing

A franchisee running one restaurant did not select NCR, cannot audit it, has no contractual visibility of its recovery time and receives no notification because no personal data of theirs was involved.

The corpus records the same standing problem at 24-1125 for Blue Yonder’s customers and 25-1003c for the JLR supply chain. Small businesses downstream of a supplier outage are the least protected population this database records and the one it can say least about.

How we reported this

Built on contemporaneous reporting of NCR’s statements and of the outage. The 12 April outage, the 13 April determination that ransomware was the cause, the single–data centre scope and the statement that the facility held no customer financial information are NCR’s own as reported. The affected product lines, named restaurant brands and geographic spread are from reporting. A ransomware group publicly claimed the attack and claimed to hold stolen credentials; that claim is not carried in the record. No outage duration is asserted — none was established in a form this desk can cite. Graded high on the incident and the company statements. Corrections: corrections@forensicpost.com.

Sources
  1. NCR in recovery as ransomware disrupts widely used point-of-sale systemCybersecurity Dive
  2. NCR suffers Aloha POS outage after BlackCat ransomware attackBleepingComputer
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary