Mystery freezer failures hit 14+ US military commissaries, hacking unproven

Mystery freezer failures hit 14+ US military commissaries, hacking unproven

Starting on August 26, 2026, refrigeration and freezer systems began failing at commissaries, tax free grocery stores for US military families, on bases across the country. A Substack post by a blogger writing as Signal and Silence tracked 14 outage reports across 11 states over August 26 to 27, based on official base announcements, local news and social media posts from people at the affected stores. By the time the post was updated on August 29, Stars and Stripes, Military Times and Navy Times had independently reported on the failures too, and the Pentagon had acknowledged a "possible refrigeration disruption" at numerous Defense Commissary Agency (DeCA) stores. Separately, at least six installations were confirmed through official sources.

The author's case for something more than equipment age rests on how the outages happened, not just that they happened. At Fort Huachuca in Arizona, the base's official Facebook account said an overnight failure put every commissary freezer into defrost mode, spoiling the contents; when a commenter suggested a simple power flicker, the account replied "the power didn't go out." Commissaries are not run independently by each base. They are operated by DeCA, which oversees roughly 235 commissaries worldwide, and DeCA's own refrigeration engineering documents state that "Defrost shall be controlled through the RMCS," its Remote Monitoring Control System. A March 2026 DeCA procurement document for RMCS management covers about 182 locations, including all 14 on the author's original list. A separate DeCA contract requires a contractor to maintain a "master control system for all of the RMCS" somewhere in the continental United States, and a contractor description of the Robins AFB commissary, one of the affected sites, describes centralized controls running its refrigeration and HVAC. The author is careful to note this shows centralized monitoring exists, not that anyone could remotely trigger every freezer's defrost at once, and that centralized control is itself normal for modern supermarkets.

Other reports add color without adding proof. At Little Rock AFB, a local community page said the commissary's systems failed around 2 a.m., and an anonymous post to a large Air Force community page claimed "I overheard employees discussing that the system was hacked last night," a claim the author says he cannot verify came from real employees or that those employees would know the cause. An anonymous poster claiming to work at F.E. Warren AFB said its freezers and those at 14 other bases "quit working or reversed to heating," and claimed one deli freezer read 180 degrees and another 160, figures the author says he cannot interpret and is not reporting as confirmed food temperatures. Holloman AFB, Fort Irwin, Columbus AFB, Travis AFB, Dyess AFB and Robins AFB all posted their own notices or signage about refrigeration failures and empty cases; NAS Lemoore was reported restored on August 28 and Dyess AFB on August 29.

The timing the author flags is that on August 9, 2026, industrial cybersecurity researchers at Claroty's Team82 published research on vulnerabilities in the Danfoss AK-SM 800A supervisory refrigeration controller, and a second piece the same day on the Copeland XWEB Pro controller, in which Team82 found 23 vulnerabilities, 21 rated high severity, and demonstrated that compromising the controller let them physically manipulate connected refrigeration equipment. Copeland has issued a security bulletin acknowledging the vulnerabilities and advising customers never to expose the control system or its web interface to the internet. The author found a DeCA equipment inventory listing a Danfoss AK-SM880 controller at NAF El Centro, which is not one of the affected bases, and states plainly that he has not established which controller model Fort Huachuca or any affected site actually runs. The stored text of the post ends mid sentence before reaching its own conclusion.

Key facts

  • Refrigeration and freezer failures hit at least 14 US military commissaries across 11 states starting August 26, 2026; at least six were confirmed through official sources, and the Pentagon acknowledged a "possible refrigeration disruption."
  • Commissaries are run through DeCA's centralized Remote Monitoring Control System (RMCS), whose own engineering documents state that defrost is controlled through the RMCS; a March 2026 DeCA procurement covers about 182 of roughly 235 commissaries worldwide.
  • Fort Huachuca's official account said an overnight failure put all its freezers into defrost mode and specifically denied a power outage; other bases including Holloman, Fort Irwin, Columbus AFB, Travis AFB, Dyess AFB and Robins AFB reported their own refrigeration outages.
  • Industrial cybersecurity researchers at Claroty's Team82 published research on August 9, 2026 finding 23 vulnerabilities (21 high severity) in the Copeland XWEB Pro refrigeration controller and separate flaws in the Danfoss AK-SM 800A, showing an attacker who compromised such a controller could physically manipulate refrigeration equipment.
  • The author repeatedly states there is no evidence DeCA was hacked and has not confirmed which controller model any affected commissary uses; the source text cuts off before reaching its own conclusion.

Why it matters

A wave of near simultaneous refrigeration failures across military bases, sitting on top of a centralized control system that is documented to run defrost remotely, is exactly the shape of incident that industrial control system security exists to prevent: not a single point of failure, but a shared one across many physical sites. The story lands days after independent researchers published working attacks against two of the controller families used in commercial and government refrigeration, which is what turns a string of broken freezers into a security question rather than a maintenance one.

Who it affects

Directly, military service members and families who shop at DeCA's roughly 235 commissaries, several of which lost their entire chilled and frozen sections for days. More broadly, anyone operating the same class of equipment: Copeland's own security bulletin is addressed to customers of the XWEB Pro controller generally, and Claroty's research covers the Danfoss AK-SM 800A independently of the military context, so the exposure is not specific to DeCA.

How to use it

Copeland's guidance, cited in the post, is to never expose the refrigeration control system or its web interface to the broader internet, which is the immediate, concrete action available to any operator running this class of controller. For everyone else, the piece is useful as a case study in how to read a cluster of outages: check for a shared control system before assuming either coincidence or attack, and separate what officials have confirmed from what commenters claim.

How solid is it

The outages themselves are well documented: multiple bases posted their own notices, Stars and Stripes and Military Times covered them independently, and the Pentagon acknowledged a possible disruption. The cyberattack theory is not: the author states outright that he has no evidence DeCA was hacked, has not confirmed any affected base's specific controller model, and built the case from public procurement and engineering documents plus unverified social media comments. The source text itself is cut off before its own conclusion, so this is a mid investigation account rather than a finished finding.

Risks and caveats

The central claims that would confirm a cyberattack, that a specific vulnerable controller was actually used at an affected base and that it was actually exploited, are both unconfirmed by the author's own account. Several supporting details come from anonymous, unverifiable social media posts, including the claimed 180 and 160 degree freezer readings and the secondhand report of employees discussing a hack. Correlation between a widely deployed centralized control system and a cluster of outages is not evidence that the system was compromised, a point the author himself makes.

“I overheard employees discussing that the system was hacked last night”

— anonymous submission to an Air Force community page, quoted in the post