RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 30 May 2021 event · prepared 16 September 2026

JBS paid its ransom after most plants were already running

JBS said it paid $11 million to prevent risk to customers, after restoring the bulk of its plants from its own defences.

Visual for this record: JBS paid its ransom after most plants were already running
Visual published by images.wsj.net, shown for identification of the record. Credit: images.wsj.net · source page ↗ Rights: owner-review-pending.

What happened

On 30 May 2021, JBS USA, one of the world's largest meat processors, was forced to halt operations at plants in the United States, Canada and Australia after a ransomware attack. In a statement issued on 9 June, the company said it paid the equivalent of $11 million in ransom, a decision it described as difficult, made to prevent any risk to customers even though, by the company's own account, the vast majority of its facilities were already back in operation by the time the payment was made. Preliminary forensic work, JBS said, found no evidence that customer, employee or company data had been compromised. Contemporaneous reporting that quotes the FBI directly records that the bureau attributed the intrusion to the group behind REvil, also known as Sodinokibi.

Confidence and limits

The ransom amount, the timing of the decision relative to plant restoration, and the data-compromise finding all come from JBS's own statement, a company disclosure rather than an independently audited account. The REvil attribution is known through a report that quotes an on-record FBI statement rather than from an FBI document opened directly for this article, and should be read as the bureau's assessment at the time rather than a confirmed, court-tested finding. Neither source establishes exactly how the attackers first gained access to JBS's network.

Why it mattered

The case became a reference point in the argument that recovery capability, not payment, should determine ransomware response, because JBS paid after most of its operations were already restored from its own defences rather than while still down. That sequence complicates a simple story in which ransom payment buys back availability: here the company's account suggests the payment was made to manage a different risk, the threat of stolen data being exposed or misused, after operational recovery had already largely happened. It arrived within weeks of the Colonial Pipeline payment, reinforcing a sense among policymakers that ransomware had become a threat to physical supply chains, not only to data.

Defensive takeaway

Separate your recovery planning from your ransom-payment decision: build the capability to restore operations from backups regardless of whether a ransom is ever paid, and treat any payment decision as a response to data-exposure risk rather than as the mechanism for getting systems back.

  • Could your organisation restore critical operations from backups without needing a decryption key at all?
  • If attackers claim to hold stolen data, who decides how that risk is weighed against the cost and legality of payment?
  • Do your incident playbooks distinguish between paying for decryption and paying to prevent disclosure?

JBS's own account describes a company that recovered operationally before it decided whether to pay, which is a more common and more useful pattern to plan for than the simpler assumption that payment is what restores service.

Defensive takeaway

Build the capability to restore operations from backups independent of any ransom decision, and treat a payment decision as a response to data-exposure risk rather than as your recovery mechanism.

JBS's own statement establishes the ransom amount and the timing of its decision relative to plant recovery. The REvil attribution comes from reporting that quotes an on-record FBI statement rather than from an FBI document opened directly, and should be read as an assessment.

Sources & reading trail

JBS USA Cyberattack Media Statement, June 9 ↗

JBS's own account of the $11 million ransom decision, the state of plant operations at the time of payment, and the preliminary data-compromise finding.

company-primary · Source published: 9 June 2021 · Retrieved: 16 September 2026

FBI Confirms REvil Ransomware Involved in JBS Attack ↗

Quotes the FBI's on-record statement attributing the attack to REvil, also known as Sodinokibi.

reputable-original-reporting · Source published: 3 June 2021 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.