
Hacked commissary freezers? A researcher weighs the evidence
An investigation links near-simultaneous refrigeration failures at US military commissaries with known flaws in commercial refrigeration controllers, while stressing that no cyberattack has been proven.
On August 28, 2026, the newsletter Signal and Silence published an investigation arguing that something unusual happened to the refrigeration systems of US military commissaries. Its author, M. Elizabeth, writes that she believes "there is a nonzero chance someone has hacked the commissary freezers" — while stressing that she has no evidence the Defense Commissary Agency was breached.
At least six installations confirmed failures
Between August 26 and 27 she collected 14 reports of refrigeration outages at commissaries on bases in 11 states and confirmed at least six through official sources. Fort Huachuca, Arizona, said in an August 27 post that an overnight equipment failure had caused all of the commissary's freezers to enter defrost mode, spoiling the food inside; the base said the power had not gone out and defrost actively heated the food. Similar notices came from F.E. Warren AFB, Fort Irwin, Columbus AFB, Dyess AFB, Holloman AFB, Robins AFB and Naval Station Newport, which announced restrictions on August 26. DeCA's store page for Travis AFB reported "refrigeration issues".
Why attention turned to the control system
Commissaries — roughly 235 worldwide — are not run by the bases they sit on but by the Defense Commissary Agency, an agency inside the Department of Defense. In March 2026 DeCA sought support for "Facilities Maintenance, Call Center Support, and Remote Monitoring Control System (RMCS) Management" covering about 182 of its locations, and its refrigeration engineering specification states that "defrost shall be controlled through the RMCS". A 2020 contract describes RMCS alarms monitored around the clock by a master control system. The author notes this does not mean headquarters can press a remote defrost button, though networked refrigeration control is normal in modern supermarkets.
Known vulnerabilities, and the caveats
On August 9, 2026, Claroty's Team82 published research titled "Freeze the Controller, Defrost the Food" describing vulnerabilities in the Danfoss AK-SM 800A, a supervisory controller for commercial refrigeration. The same day a second investigation found 23 vulnerabilities, 21 of them rated high severity, in the Copeland XWEB Pro controller, and demonstrated physical control of refrigeration equipment after compromising the device. Copeland issued a bulletin advising customers never to expose the control system or its web interface to the internet. The author did not establish that Fort Huachuca uses a Danfoss controller; she found a DeCA equipment inventory listing a Danfoss AK-SM880 at NAF El Centro, which was not among the affected stores.
She concludes that a cyberattack is not proven: ageing equipment, a faulty update, a communications failure or routine maintenance could all explain the outages. After publication, Stars and Stripes, Military Times and other outlets reported on the failures, and the Pentagon acknowledged a "possible refrigeration disruption" at numerous DeCA commissaries.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.