zgba 站群
I think the military commissary s freezers were hacked

I think the military commissary’s freezers were hacked

Originally published: Aug. 28, 2026 at 1:18 p.m. PT.

Last Updated: Aug. 29, 7:27 PT

Since publication, Stars and Stripes, Military Times/Navy Times, and multiple others have independently reported on the multi-base refrigeration failures, with the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries.

Near-simultaneous refrigeration failures or significant issues impacting at least six military installations have now been confirmed through official sources during the last few days, with additional independent confirmation of multiple other incidents.

Self-aware enough to know this sounds insane, but I need you to stick with me.

Not one freezer, not one grocery store, not just ANY grocery store, either.

The refrigeration systems at military commissaries (tax-free grocery stores for military personnel and their families located on bases across the country) appear to be under some type of siege; either their own aging fleet of equipment is deciding to seppuku in perfect harmony, or by something (or someone) more nefarious.

Flipping through my normal rotation of social media, I started seeing scattered posts lamenting the commissary suddenly losing their entire refrigerated & frozen sections.

All cold food spoiled, or removed from shelves.

Unfortunate and wasteful, I thought, but inconsequential to me personally. I don’t shop there, I have no stake in the availability of my frozen favs, plus the commissary is not exactly known for smoothly functioning operations, thus, moving on.

But then I saw another post, and another… with a chorus of comments

huh, how odd, the same thing is happening here.

What are the chances!

The pattern caught my attention, and what followed was a deep dive into military social-media chatter, commercial refrigeration, defense procurement contracts, and network security refreshers in an attempt to resurrect the rudimentary cybersecurity knowledge my degrees required.

‘Twas never my strongest subject. When would I ever need to use this, I distinctly remember thinking. (Freezers didn’t have networks, in the olden days)

At the time of initial publication, I identified 14 commissary refrigeration/freezer outage reports attributed to the following military installations across 11 states on August 26–27. Subsequent additions denoted by asterisk, Reports later determined to be unsupported/unrelated remain struck through for transparency.

Fort Huachuca (Confirmed)

F.E. Warren AFB (Confirmed)

Fort Irwin (Confirmed)

Columbus AFB (Confirmed)

Naval Station Newport (Confirmed Aug. 26; Restored Aug. 29)

*Travis AFB (Confirmed)

NAS Lemoore (Independently Confirmed; Restored Aug. 28 per Commissary employee)

*Port Hueneme (Independently Confirmed)

Dyess AFB (Independently Confirmed; Restored Aug. 29 per Commissary employee)

Fort Meade (Removed; operating normally per local as of Aug. 28)

Camp Lejeune (Removed: official outage notice initially identified as current was actually from 2025)

To be very clear: I do not have evidence that the Defense Commissary Agency was hacked.

What does exist is evidence that something odd is happening, plus a whole lotta explanations for how a cyber incident of this magnitude is technologically possible, and that there may be much larger implications than a dearth of cold veggies.

Unfamiliar to me prior, and I say that intending no offense to you (lovely, I’m sure) Fort Huachucans; the Cochise County, Arizona base has captured my attention today.

On August 27th, the official U.S. Army Fort Huachuca Facebook account announced that an overnight equipment failure caused ALL of the commissary’s freezers to enter defrost mode, spoiling everything inside.

This wasn’t a case of simply a power flickering and ice cream melting, because someone commented just that. Fort Huachuca responded from its verified account:

“the power didn’t go out”

Another questioned whether all of the food was really “spoiled” if the freezers had simply stopped working.

The installation clarified that, no, the freezers hadn’t just shut off. They had entered defrost mode, which heated the food.

That is a very different problem and I’m fully invested at this point. Buried in the largely useless comments, I unearthed what felt like a gem:

“I was told that it was a network issue.”

This commenter claimed that Huachuca’s cold-storage equipment had been replaced relatively recently, and that refrigeration and HVAC were remotely controlled through DeCA.

That is a random Facebook comment, from an unverified individual. It is not evidence that this was a network problem. But naturally, I absolutely had to know whether the second part was even possible.

Unfortunately for my productivity, it is.

I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.

They’re run by the Defense Commissary Agency (DeCA), an agency seated within the Department of Defense.

DeCA, as expected, has a whole refrigeration-control infrastructure.

In March 2026, DeCA issued procurement documents seeking support for “Facilities Maintenance, Call Center Support, and Remote Monitoring Control System (RMCS) Management.”

It covers approximately 182 DeCA locations, encompassing all 14 on my original list.

That alone doesn’t mean anything, however. They’re DeCA stores… of course they’re in a DeCA facilities document.

What matters is what the system actually does.

With some cursory control+F digging through DeCA’s titillating refrigeration engineering specifications, bingo.

“Defrost shall be controlled through the RMCS”

Which brings us back to Fort Huachuca.

Every freezer entered defrost mode.

The installation itself says the power didn’t fail, and that defrost actually heated the food.

DeCA’s own engineering documentation says defrost is controlled through its refrigeration monitoring/control system.

Another DeCA refrigeration contract describes Refrigeration Monitoring and Control Systems (RMCS) located at individual commissaries whose refrigeration and HVAC alarms are monitored remotely 24/7.

Per the contract, the contractor was required to maintain a “master control system for all of the RMCS” somewhere in the continental United States.

Important caveat, because this is where it’s really easy to jump ahead (spoken by a professional jump-aheader): this does not mean someone at DeCA headquarters can remotely hit a proverbial DEFROST EVERY COMMISSARY button. It establishes centralized monitoring infrastructure.

Exactly how much remote control exists, where current master systems are hosted, and whether affected stores share equipment remains unclear. Publicly available information is limited here, and it’s not exactly a hotly discussed topic, as you can reasonably imagine.

But we can establish networked control at individual commissaries independently.

The contractor that allegedly built the newer commissary at Robins AFB, one of the installations with reported problems, describes the building as having RSMS controls managing all of the store’s refrigeration and HVAC systems.

Again: centralized refrigeration control is not suspicious. It’s (apparently) how modern supermarkets work.

What it does is change the options for what a “freezer failure” can mean.

At Holloman AFB, someone posted the printed notice hastily taped to the blocked off, empty refrigerated section of their commissary:

A printed note by Holloman AFB Commissary Management reads:

“Due to an unexpected refrigeration system failure, all chilled and frozen merchandise is temporarily unavailable for purchase until further notice.”

The person submitting the photographs said they’d experienced power outages there before, but this event took out all of the refrigeration systems.

The sign and empty cases are considerably harder to argue with.

Fort Irwin publicly acknowledged its refrigeration problem as well, with similar DIY signage and bare shelving visible.

Naval Station Newport also officially announced restricted commissary sales due to refrigeration-system issues, however they opted to go with a (dated?) picture of fully stocked shelves. I appreciate the variety.

Then there’s Dyess AFB, where another poster supplied a photograph taken that morning showing an entire commissary meat case emptied and closed off after someone reported that the Dyess commissary refrigeration was down.

Robins customers reported produce and meat being covered and unavailable.

Little Rock gets stranger.

A local community page reported that the commissary’s refrigerated systems went down at approximately 2 a.m., affecting chilled, refrigerated and frozen merchandise.

Then an anonymous submission to a large Air Force community page claimed:

“I overheard employees discussing that the system was hacked last night”

Do I know that those employees actually said that?

Do I know whether the employees would know the cause even if they did?

Columbus AFB issued an official notice acknowledging freezer and chillers experienced an outage.

The official DeCA page for Travis AFB posted an August 26 notice stating that “refrigeration issues” had made some frozen and chilled items unavailable and temporarily affected Click2Go operations.

Moving south, F.E. Warren AFB acknowledged a malfunction as well.

In addition to the official statement, I found an anonymous submission to a popular military social media page from someone claiming to work at the F.E. Warren commissary. They wrote that its freezers, and apparently those at 14 other bases, “quit working or reversed to heating.”

The commenter claimed one deli freezer registered 180 degrees and another 160.

I have no idea what those numbers mean. Case temperature? Defrost heater? I am emphatically not reporting that food reached 180°F, but the “14 other bases” part stuck out.

Because once I started counting, I got the same number.

On August 9, 2026, industrial cybersecurity researchers at Claroty’s Team82 published an article titled “Freeze the Controller, Defrost the Food: Uncovering Vulnerabilities in Danfoss Refrigeration Controllers.”

Yes, that is the actual title.

The researchers examined the Danfoss AK-SM 800A, a supervisory controller used to centrally manage commercial refrigeration systems. And what did they find?

Vulnerabilities capable of allowing serious unauthorized access.

Before anyone screenshots that paragraph and runs away with it:

I have not established that Fort Huachuca uses a Danfoss AK-SM 800A.

I have, however, found a searchable copy of a DeCA equipment inventory list identifying a Danfoss AK-SM880 refrigeration monitoring/control system at NAF El Centro - notably, not one of the commissaries on my affected list.

So, Danfoss AK-SM technology exists within the DeCA environment.

Interesting, but not attribution.

Claroty published a second refrigeration investigation on the same day, this time, about something called the Copeland XWEB Pro supervisory controller (5,509 + shipping, in case you’re in the market; fair warning, this isn’t exactly a glowing sales pitch).

They found 23 vulnerabilities, 21 rated ‘high severity’, and ultimately demonstrated the part I actually care about: After compromising the supervisory controller, they could physically manipulate the refrigeration equipment.

Copeland itself already issued a security bulletin acknowledging vulnerabilities and explicitly advising customers never to expose the control system or its web interface to the broader internet.

So: Can someone actually hack a commercial refrigeration controller and make it do things?

No. Too early to call it that.

And this is where I am currently stuck.

A common software or configuration problem, update-gone-wrong, a communications failure, or some boring DeCA-wide maintenance issue could explain it too.

A bunch of unrelated aging refrigeration systems deciding to off themselves during August is also not exactly unimaginable. DeCA’s own March procurement specifically identified aging infrastructure as something it is trying to manage. If you’ve ever shopped at a commissary, you can attest to the fact that the facilities are not what I would call top of the line boutique shopping experiences.

There are also historical examples of commissary refrigeration outages. Refrigeration equipment does, in fact, break.

But the thing I can’t get past is Fort Huachuca’s failure mode.

Not: the freezer compressor died.

Not: the power went out.

Not even: the refrigeration system stopped cooling.

Every freezer went into active defrost.

The function that did it, per DeCA’s own engineering documents, is controlled through the RMCS.

This is not proof of a cyberattack, but it is quite a series of coincidences.

There is still no public evidence that the affected stores share the same RMCS vendor, controller, firmware, contractor, or network.

This is where we have to talk about the Intern

View original article