Refrigeration and freezer equipment at grocery stores on several U.S. military facilities broke down around the same time, prompting a military investigation. The possibility of a cyberattack targeting the equipment control systems was raised, but no evidence has been confirmed that hacking actually occurred.
Gigazine, a Japanese media outlet, reported on Sept. 21 that reports emerged of refrigeration and freezer equipment failures at 14 military facilities in 11 U.S. states on Aug. 26-27. Not all 14 sites have been officially confirmed by military authorities. The Pentagon acknowledged refrigeration equipment problems at some Defense Commissary Agency (DeCA) stores but did not disclose the overall scale of damage or the cause.
At Fort Huachuca in Arizona, an overnight equipment failure put all store freezers into defrost mode, spoiling stored frozen foods. Sales of refrigerated and frozen goods were also halted at Holloman Air Force Base in New Mexico and Fort Irwin in California, among others. The Pentagon said some items were moved to other refrigerated facilities to reduce food losses and stores remained open.
As problems occurred at multiple facilities around the same time, the possibility of outside intrusion was also discussed. Security firm Claroty announced on Aug. 9 that it had found vulnerabilities in Danfoss refrigeration controllers AK-SM 800A and Copeland's XWEB Pro. Claroty said 23 vulnerabilities were identified in XWEB Pro, with 21 classified as high severity. Researchers showed in a test environment that they could compromise controllers and physically manipulate cooling equipment.
It has not been confirmed whether the affected military stores used the equipment or whether the vulnerabilities were exploited. Possible causes also include software errors or configuration issues, communications failures, or maintenance problems.
Military investigative agencies, including the U.S. Army Criminal Investigation Division and the Air Force Office of Special Investigations, are investigating the incidents. The agencies did not disclose specific investigative details or any link to a cyberattack.