In The Dark, Brands Await UNFI Cyberattack Fallout

United Natural Foods, Inc. (UNFI) appears to be back up and running after a cyberattack hobbled the distributor’s national network earlier this month, but the cleanup and aftermath are still shaking out even as systems operations are restored and customers have resumed ordering.

UNFI – which is the primary supplier to Whole Foods Market – locked down its entire network following the discovery of “unauthorized activity” in its information technology systems on June 5. The outage resulted in empty grocery store shelves across the country in the days that followed.

On Thursday, the company confirmed the incident has been “contained” and that it was delivering products to grocery stores across its network at “more normalized levels.”

Still, brand operators are anticipating continued disruption for some time, and many remain in the dark about the ongoing impact, despite the company stating it has “focused on proactively and transparently engaging with its customers and suppliers to support their unique business needs” throughout the process.

Several suppliers say they were unaware of where out-of-stock issues may have occurred and how promotions or new product launches were affected during the period. While systems were down, some shared that the distributor and its retail partners reverted to manually printing pages and using spreadsheets to process orders.

One founder said the attack coincided with a category reset when new items were slated to hit shelves at Whole Foods, noting her team received conflicting communications from the retailer and distributor on the timing of a resolution. The founder, who spoke to Nosh under the condition of anonymity, reported not knowing whether her brand’s product was sitting in a warehouse, stuck in transit or discarded. She said she resorted to calling stores directly to track the inventory.

Dinos Stamoulis, co-founder of grain-free granola brand Paleonola, told Nosh he doesn’t expect he will understand the full impact on his company for another month or two. He described the size of his business through UNFI as “not massive, but not small.”

Stamoulis said while communication with the company’s buying and logistics teams had resumed, individual supplier data was still offline as of last Wednesday.

Still, he acknowledged “UNFI did a really good job getting back up and running considering how bad it could have been.”

“I can only speak on what we experienced, and luckily it wasn’t too bad,” he added.

Gregory Esslinger, head of business development for deduction management software company Floret, advises suppliers to be extra cautious when reviewing shipment information in the wake of the attack.

“I’m honestly telling brands that anything that happens between say June 1, and the next two months, put an asterisk next to it as something you need to look more deeply into,” he told Nosh.

Esslinger, who previously held purchasing and supplier management roles during a decade-long career at UNFI, noted many suppliers have already experienced unexpected losses in revenue in the two weeks following the incident and are likely to face charges related to potential spoilage and audits in the future.

The event ultimately compounds an already fraught relationship many emerging brands have reported with the distributor – while exposing cracks in the system. One founder, speaking anonymously to Nosh, said in many cases brands are left to absorb the financial and reputational damage of such a disruption.

In a June 26 filing with the U.S. Securities and Exchange Commission, UNFI said it continues to closely monitor the effect of the incident on its business and operating results. The company also indicated the attack involved no breach of security on consumers’ personal information.

Explore the Nombase CPG Database

Head to Nombase to learn more about the tagged companies and their offerings.