I think the military commissary's freezers were hacked

382 points · 217 comments on HN · read original →

Points and comments are a snapshot, not live.

Refrigeration failures at 14+ military commissaries may stem from hacked networked control systems.

The Defense Commissary Agency (DeCA) operates ~235 commissaries worldwide. Between Aug 26-27, 2026, 14+ bases reported freezers entering defrost mode, spoiling food. Fort Huachuca confirmed power stayed on; defrost heated food. DeCA documents show defrost is controlled via a Remote Monitoring Control System (RMCS). A March 2026 contract covers RMCS support for 182 locations. On Aug 9, 2026, Claroty disclosed vulnerabilities in Danfoss and Copeland refrigeration controllers; DeCA uses Danfoss equipment. The Pentagon acknowledged a possible refrigeration disruption.

What commenters are saying

Many commenters are skeptical of a hack, citing simpler explanations: DoD operational rot after layoffs, batch equipment failure, or design flaws in networked controllers. Some note the failures match Claroty's vulnerability disclosure timing. Others argue that if this were state sabotage, attackers would waste zero-days on freezers. A commenter with DoD experience describes insecure IoT practices, including hotspots left unlocked for remote access. One camp insists "the S in IoT stands for security" and that bored teenagers are more likely culprits than foreign adversaries.