2021 JBS — REvil ransomware; North America and Australia operations; FBI attribution; $11M ransom
Data compromised
Vendor and FBI-facing statements emphasized no confirmed theft of customer, supplier, or employee PII at the time of major press coverage—focus remained on production disruption and ransom economics
Technical writeup
Brazil-based JBS SA, the world’s largest meat processor, suffered a late-May 2021 ransomware incident that disrupted IT supporting operations in the U.S., Canada, and Australia. The FBI publicly attributed the attack to the REvil gang. JBS later confirmed paying roughly $11 million to contain fallout, while stating investigators had not found evidence that customer, supplier, or employee data was stolen—framing the event mainly as operational encryption and extortion despite multi-day plant slowdowns.
Root cause
Ransomware (REvil) against enterprise IT supporting meat-processing networks