The June 2025 attack that halted a $31 billion food distributor now shows up in its annual results as a negative adjustment, because $45 million of insurance arrived in a later fiscal year than the costs it covers.
What happened
United Natural Foods, Inc. filed a Form 8-K under Items 2.02, 8.01, and 9.01 on Tuesday, September 8, 2026, accession number 0001020859-26-000022, accepted by EDGAR at 7:02:12 a.m. ET. The Item 8.01 is a $200 million share repurchase authorization and has nothing to do with security. The security content is in the Item 2.02 exhibit: the fourth-quarter and full-year earnings release for the fiscal year ended August 1, 2026.
UNFI is the largest publicly traded grocery wholesaler in North America and reported full-year net sales of $31,152 million. It disclosed a cybersecurity incident in June 2025, in the fourth quarter of its fiscal 2025, that disrupted ordering and distribution across its network. Today’s release carries the first full fiscal year of that incident’s accounting tail, and the shape of it is worth reading closely.
In the reconciliation from net income to Adjusted EBITDA, the line is labeled “Cybersecurity incident.” For fiscal 2025 it carried $26 million, all of it in the fourth quarter. For fiscal 2026 it carries $(3) million in the fourth quarter and $(21) million for the full year, shown in parentheses. The sign is not a typo. Footnote 5 explains it, and the wording is the story:
“Fiscal 2026 includes $45 million of insurance recoveries, which are included within Operating expenses in the Consolidated Statements of Operations, partially offset by $24 million of costs and charges related to the June 2025 cybersecurity incident, of which $20 million is included within Gross profit and $4 million is included within Operating expenses in the Consolidated Statements of Operations. Fiscal 2025 includes costs and charges related to the cybersecurity incident, of which $15 million is included within Gross profit and $11 million is included within Operating expenses in the Consolidated Statements of Operations.”
So: $26 million added back in fiscal 2025, $21 million subtracted out in fiscal 2026. Across the two fiscal years the “Cybersecurity incident” line nets to roughly $5 million. Full-year Adjusted EBITDA was $701 million in fiscal 2026 against $552 million in fiscal 2025, and GAAP net income was $84 million.
On sales, the release says only this: “Sales in the fourth quarter of fiscal 2025 were impacted by the previously disclosed cybersecurity incident experienced in the fourth quarter of fiscal 2025,” and elsewhere refers to “lapping last year’s cybersecurity event.” No dollar figure is attached to that impact anywhere in the document. Fourth-quarter fiscal 2026 net sales were $7,642 million, down 0.7 percent against the quarter the incident depressed. The release states no cumulative cost of the incident, and the fiscal 2027 outlook does not mention it.
Why it matters
Severity Daily reported yesterday on Ardent Health’s ransomware carve-out, where a 2023 incident’s financial consequence surfaced thirty-four months later inside a non-GAAP definition. UNFI is the same mechanism running faster, and it exposes the part that a single-year read gets wrong: the sign.
Anyone who pulls UNFI’s fiscal 2026 results and looks for the cyber line finds a negative number. Read alone, that number says the incident helped. Anyone who pulled fiscal 2025 found $26 million of pure cost. Neither year is the answer, and neither year is wrong — they are two halves of one event separated by an accounting boundary, because insurance claims settle on a slower clock than the costs they reimburse. A screen, a model, or a peer comparison that samples one fiscal year of a multi-year incident will get a number whose sign depends entirely on which year it sampled. That is not a UNFI problem. It is the structural shape of every cyber incident large enough to trigger a material insurance claim.
The second thing to hold onto is what the line is and is not. It is incremental costs and charges, net of insurance recoveries. It is not the cost of the incident. Three categories sit outside it and are visible nowhere in this document. Lost sales, which the company says occurred and does not quantify. Security spending that became ordinary course after the incident and therefore stopped being an adjustment. And customer and contract effects that show up, if at all, in the top line rather than in an add-back. The fourth-quarter number makes the point: net sales fell 0.7 percent against a quarter the company itself describes as depressed by the attack. That is a comparison flattered by a weak base and still down, and no line in the reconciliation captures whatever explains it.
Third, the disclosure is complete on its own terms and thin on the one number a reader most wants. UNFI names the incident, names its month, splits the costs between gross profit and operating expenses, and states the insurance figure. That is more granularity than most registrants give. It still does not say what the incident cost in total, and because the two fiscal years point in opposite directions, the cumulative figure is the only one that means anything — and the reader has to build it themselves from two documents filed a year apart. There is no rule requiring a cumulative disclosure, which is precisely why the absence is worth naming.
Finally, the insurance number deserves its own attention: $45 million recovered against $24 million of same-year costs and $26 million the year before. Recoveries of that size, arriving roughly a year after the event, are the strongest public evidence to date on what a large cyber policy actually pays and when. It is one data point, and the policy terms, retention, and sublimits are not public. But it is a real number attached to a named incident at a named company, which is rarer in this field than it should be, and it is a better input to a cyber-insurance conversation than any vendor survey.
What to do
If you model or benchmark cyber incident costs, take the cumulative, never the annual. For UNFI that is $26 million in fiscal 2025 less $21 million in fiscal 2026, or about $5 million net, and it is net of $45 million in insurance rather than gross of it. Any benchmark built from single-year add-backs is measuring the timing of insurance settlements, not the severity of incidents.
If you are building a business case for cyber insurance, this is a usable data point. A distribution-halting incident at a $31 billion wholesaler produced $45 million in recoveries booked in the following fiscal year. Note the lag as carefully as the amount: the costs hit one year and the recoveries the next, so the cash-flow and covenant picture in the incident year is the gross number, not the net.
If you sit in finance or FP&A at a company that has had an incident, decide now how you will present year two. The reversal in year two is arithmetically correct and reads badly if it arrives without explanation. A single sentence giving the cumulative figure costs nothing and removes the ambiguity that this filing leaves open.
If you are a UNFI customer or supplier, the operational story is over and the disclosure story is not. There is nothing to patch and nothing to act on defensively here. The open item is what the incident actually cost, which remains unstated and is not derivable from any single filing.
Sourcing note
Checked. United Natural Foods’ Form 8-K, accession number 0001020859-26-000022, read from SEC EDGAR; the acceptance timestamp of 7:02:12 a.m. ET and the item designations come from the filing index and directory. All quoted language and every figure above come from the exhibit filed with it, the fourth-quarter and fiscal-year 2026 earnings release, including footnote 5 to the non-GAAP reconciliation, quoted in full. Fiscal 2026 is the 52 weeks ended August 1, 2026; fiscal 2025 is the 52 weeks ended August 2, 2025. The Item 8.01 in this filing concerns a $200 million share repurchase authorization and is unrelated to the incident.
Could not reach. cisa.gov returns HTTP 403 to automated fetching. No agency advisory relates to this filing and none was sought beyond that.
Unresolved. The total cost of the June 2025 incident, which the company has not stated and which cannot be derived from this release alone. The dollar value of sales lost in fiscal 2025, which the release says occurred and does not quantify. The terms, retention, and limits of the insurance that produced the $45 million recovery. Whether further recoveries are expected. And whether the 0.7 percent fourth-quarter sales decline against a cyber-depressed prior-year quarter reflects any residual effect of the incident — the release does not say, and this page does not assert that it does. The $5 million two-year net figure above is arithmetic performed by this publication on the company’s two reported annual figures, not a number the company has published.

