In 2025, the U.S. media reported on a sabotage attempt on a poultry processing facility allegedly perpetrated by a former employee of the facility’s cleaning contractor. The case was before the courts and details were emerging.
This is a rare example of a cyberattack on a food facility that has been described in public documents and I’m delighted to be able to unpack the details here for food safety professionals, policy makers and purveyors.
The former cleaning company worker pleaded not guilty to charges related to unauthorised access to computers at the poultry processor, a facility where he had designed and maintained the chemical cleaning systems on behalf of his employer.
Prosecutors allege he used computer access to threaten the safety and integrity of the poultry plant, its workers, customers and consumers by altering flow rates and concentrations of cleaning chemicals and sanitisers in the facility.
The man, a senior electronics customer service support employee at the cleaning company, was responsible for designing and maintaining chemical dosing systems for the clients of the cleaning services provider, including the poultry plant. This gave him in-depth insider knowledge of the cleaning and sanitation systems, hardware and protocols used in the facility.
He also had access to the computer network that connected the chemical company to the onsite controls at the poultry facility.
It’s alleged the man illegally accessed the cleaning chemical system at the poultry plant with the intention of causing harm in August 2023, three months after his employment at the cleaning company was terminated.
They allege that over a period of six days he:
Disabled safety alarms;
Redirected alert/warning emails; and
Changed doses, flow rates and distributions of peracetic acid and sodium hydroxide through multiple stages of poultry processing.
“There were times that he increased the amount, there were times where he decreased that amount of chemicals, but he did that after he was fired”, said acting U.S Attorney, District of South Carolina.
In documents presented to the court during his indictment, prosecutors said that when the man’s employment was terminated in May 2023, he handed back his company credit card, keys, alarm codes and ‘password sheet’, but somehow maintained access to certain network and login capabilities.
He appeared to be motivated to get his former employer into trouble with their customer, said the prosecutor.
“There were times that he increased the amount, there were times where he decreased that amount of chemicals… he did that after he was fired” Brook Andrews, acting U.S Attorney, District of South Carolina (via Wis10)
None of the court documents or proceedings have revealed whether any physical harm was caused to the facility, its workers, products or customers. It is not known how the sabotage was discovered, but the acting U.S Attorney revealed the FBI was involved in the investigation and was responsible for the man being caught. The use of computers, after authorised access had been revoked, to try to create threats to public health makes this case a federal crime under U.S. law.
My guess: the alleged crime was discovered when someone at the poultry plant realised the chemical control system was operating in an unexpected way and alerted the chemical company or authorities, with the FBI ultimately getting involved.
Root causes
The cleaning company had the ability to remotely access and control the cleaning chemicals at poultry plants in two U.S states.
The cybersecurity systems at the cleaning company allowed a former employee to access those systems without authorisation. He was allegedly able to make unauthorised changes to chemical usage and override alarms and alerts that would have notified poultry company employees of the changes.
We do not know how the man regained or maintained access to the computer system after his employment ceased, though one cybersecurity expert I talked to said it was likely that the cleaning company simply did not think to remove his access credentials from their system.
The human resources people at the cleaning company, who collected the man’s ‘password sheet’ when he was fired, almost certainly had no idea that he could pose a threat to public health if he somehow retained access to their computer systems.
Could it really be that the oversight or ignorance of a human resources worker at a cleaning company allowed a near miss or actual food sabotage event? Unfortunately, it seems so.
Other possible points of access include…
easily guessable passwords – for example, the man could have guessed a co-worker’s password and logged in with their credentials;
weak firewalling for the computer network at the poultry processing facility or the chemical company;
knowledge about the login credentials of poultry company employees, obtained perhaps during training or commissioning of the chemical dosing system;
shared or generic logins known to multiple chemical company or poultry company employees.
Comments
There are so many people talking about the threats to food safety from cyberattacks, but very few examples of actual food safety impacts from cyberattacks.
The most well-known example of a cyberattack on a food company is the JBS ransomware attack of 2021, which caused disruptions to every JBS processing facility in the USA and to JBS supply chains in Australia. It caused supply chain chaos and huge economic losses, but consumers were not exposed to any food safety risk.
In issue 113, I explained that even when it’s possible for a hacker to gain control of food processing equipment, or circumvent security measures – for example by disrupting CCTV monitoring of critical activities - the results would almost always be either detectable – for example, food would spoil if refrigeration systems were tampered with - or require ‘boots on the ground’ actions inside the facility to achieve intentional adulteration.
🍏 Issue 113: Are Cyberattacks (Really) a Food Safety Issue? 🍏
This cyberattack, however, which involved chemical dosing systems, certainly appears to have had the potential to cause widespread harm to public health from a remote location. Let’s explore what the impacts could have been.
I can think of two ways this attack could have posed a threat to food safety: firstly by contaminating chicken at the facility with peracetic acid or sodium hydroxide, and secondly by preventing the correct cleaning and sanitisation of food handling equipment.
Peracetic acid and sodium hydroxide are both chemicals that you most definitely wouldn’t want to consume, but they are not radically toxic. If they were super-toxic, that is, if they were toxic enough to harm consumers in the event of an undetected spill or mistake with cleaning, they wouldn’t be allowed in poultry processing.
However, if applied to chicken in huge quantities, the chemicals could certainly cause harm to consumers. But they would also be easily detectable via the smell, feel and appearance of the chicken.
So, for me, any intentional adulteration with these cleaning chemicals would either have been present in hard-to-detect quantities that would be unlikely to cause harm or present in large quantities and likely to be detected before consumption: not a significant food safety risk.
The second scenario, preventing the correct cleaning and sanitising of equipment, would cause potential microbial contamination of the chicken. However, for this to result in a significant food safety risk would also require consumers to undercook or seriously mishandle the chicken before use.
That’s not to say such events would not be serious. Workers could be harmed, brands damaged, expensive recalls undertaken, product dumped and major cleanup efforts required if either of those scenarios had unfolded. Just saying the impact on consumers would likely be low.
Key takeaways
Food businesses are vulnerable to cyberattacks perpetrated through the systems of service providers like cleaning companies. In this case, an unauthorised person was able to access the cleaning chemical dosing and flow-management systems of a poultry processor through a computer network linked to a cleaning company.
Ignorance, error or inadequate systems at the cleaning company may have allowed a disgruntled employee to retain access to the food company’s chemical control software after his employment was terminated. The exact method of access has not been shared publicly.
Food businesses can be vulnerable to malicious acts through failures in the cybersecurity protocols of suppliers like cleaning service providers. Such failures can allow access to systems that intersect with food safety, such as cleaning operations.
The personnel responsible for access to computer systems at suppliers are unlikely to understand potential food safety outcomes for customers in the event of a security breach in their systems.
Supplier approval processes and food defence programs should consider the risks posed by suppliers with poor cybersecurity protocols.
In short: A disgruntled ex-employee of a cleaning company allegedly manipulated chemical dosing systems at a poultry processing plant through unauthorised access to a computer nework 🍏 Vulnerabilities in the cybersecurity protocols at the cleaning company may have allowed the alleged attack to occur 🍏 Suppliers and their computer systems can introduce vulnerabilities to food companies 🍏 Such vulnerabilities should be considered in supplier approval processes and food defence vulnerability assessments🍏
Main sources (other sources are hyperlinked in-line):
Monk, J. (2025). ‘Disgruntled’ man sabotaged SC chicken plant, threatened public health, feds say. [online] The State. Available at: https://www.thestate.com/news/local/crime/article305396216.html [Accessed 5 May 2025].
Pilet, J. (2025). Food Safety News. [online] Food Safety News. Available at: https://www.foodsafetynews.com/2025/05/south-carolina-chicken-plant-sabotage-case-exposes-food-safety-gaps/ [Accessed 5 May 2025].
Popa, N. (2025). Grand Jury indicts Lexington man in connection with incidents at poultry plant. [online] https://www.wistv.com. Available at: https://www.wistv.com/2025/04/22/grand-jury-indicts-lexington-man-connection-with-incidents-poultry-plant/ [Accessed 5 May 2025].
This article originally appeared in Issue 187 of The Rotten Apple

