Desk live·
ForensicPost
Ransomware/Third party/File 24-1121

The Software That Tells the Supermarket What to Order

Blue Yonder runs supply-chain and workforce systems for retailers and manufacturers. When it went down in November 2024, the disruption surfaced in shops on two continents.

Constructed geometry · not a chart of case data
JurisdictionUSAScottsdale, Arizonathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBlue Yonder
ActorTermite
D. Kennedy13 min readConfidence: high3 sources reviewed

On 21 November 2024 Blue Yonder, a supply-chain software provider used by retailers and manufacturers worldwide, was hit by ransomware. Reporting placed Starbucks, Sainsbury’s and Morrisons among the customers affected.

The company sells the systems that plan replenishment, route warehouse work and schedule staff — the layer between a shop’s shelves and everything that fills them.

The Affected Population Is Nobody The Vendor Sold To

A shopper who found a gap on a shelf, or a barista whose shift was worked out by hand that week, had no relationship with Blue Yonder and no way to know it existed.

That is the concentration theme in its ordinary form, and the corpus records it repeatedly. What makes this file useful is how far the consequence travelled: an American software vendor’s outage changed what was on sale in British supermarkets.

A Logistics Outage Is Availability Harm With No Data Attached

No notification obligation attaches to a delayed pallet. The corpus filed at 24-1231 that four large 2024 incidents did most of their damage by stopping things and none produced an availability figure anybody had to file; Blue Yonder is a fifth.

Data was taken as well — filed at 24-1205 — and that half will produce counts and notifications. The half that emptied shelves will produce nothing.

Concentration In Planning Software Is Rarely Modelled

Retailers audit their suppliers of goods. The software that decides which goods to order sits at a different layer, is bought by a different function, and tends not to appear in a resilience review as a single point of failure across an entire sector.

This desk has no figure for how many retailers depend on the same planning vendor, and has seen none published. The absence is the finding — the exposure is concentrated to a degree nobody outside the industry can measure.

How we reported this

Compiled from contemporaneous reporting and customer statements, listed below. The named customers are those that publicly acknowledged disruption; the full affected customer base is not established and this desk has seen no figure for it. Attribution to the Termite group is dealt with at 24-1205. Corrections: corrections@forensicpost.com.

Sources
  1. Blue Yonder SaaS giant breached by Termite ransomware gangBleepingComputer
  2. Ransomware meets retail: Sainsbury's, Starbucks and Morrisons feel the heatBlackFog
  3. New Termite ransomware group claims responsibility for Blue Yonder cyberattackCyberScoop
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary