Cyberattack Disrupts Australian Sugar Harvest, Halts Operations
Australia's second-largest sugar producer has been crippled by a cybersecurity incident, forcing a shutdown of operations and disrupting its crucial harvest season.

A significant cybersecurity incident has brought operations to a halt at Australia's second-largest sugar producer, throwing the nation's vital sugar harvest into disarray. The company confirmed on Wednesday that it is actively responding to a "cybersecurity incident affecting parts of its operations." In response, the company has engaged external cybersecurity experts and is cooperating with local authorities to investigate the attack and safely restore its systems.
The full extent of the attack and its specific vector remain under investigation. However, the immediate impact has been severe, leading to a complete shutdown of affected systems. This disruption comes at a critical time for the sugar industry, as the harvest season is underway. The interruption threatens not only the company's production output but also potentially impacts supply chains and the broader agricultural sector in Australia.
While the company has not disclosed the nature of the attack, such incidents often involve ransomware, data breaches, or denial-of-service attacks that cripple industrial control systems (ICS) and operational technology (OT) environments. The reliance of modern agricultural operations on interconnected digital systems makes them increasingly vulnerable to sophisticated cyber threats. The shutdown of mills and processing facilities means that harvested sugarcane cannot be processed, leading to potential spoilage and significant financial losses.
This incident underscores the growing cybersecurity risks faced by critical infrastructure sectors, including agriculture. As these industries become more digitized, they become more attractive targets for threat actors seeking to cause maximum disruption or extort significant ransoms. The complexity of securing OT environments, which often involve legacy systems not designed with modern security in mind, presents unique challenges for defenders.
The company's statement indicates a measured approach to recovery, prioritizing safety and system integrity. The engagement of cybersecurity specialists and law enforcement suggests the incident is being treated with the utmost seriousness. The investigation will likely focus on identifying the initial point of compromise, understanding the scope of the intrusion, and determining the extent of any data exfiltration or system damage.
Until systems are fully restored and secured, the disruption to the sugar harvest is expected to continue. This event serves as a stark reminder for organizations in the agricultural and food production sectors to bolster their cybersecurity defenses, implement robust incident response plans, and ensure regular backups are maintained and tested. The long-term consequences for the company and the Australian sugar market will depend on the duration of the outage and the effectiveness of the recovery efforts.
Further updates are expected as the investigation progresses and the company works towards resuming normal operations. The incident highlights the need for continuous vigilance and investment in cybersecurity measures across all critical industries to protect against evolving threats.
Two days later, on June 15, Mackay Sugar reported significant progress in restoring systems that support cane supply and mill operations, with steam trials underway and harvesting expected to resume later this week. The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, has claimed responsibility on its leak site but has not yet published any stolen data. The group, active since mid-2025 and known for worm-like lateral movement capabilities, lists over 500 alleged victims, though it remains unclear if operational technology was directly impacted.
The Gentlemen ransomware group has claimed responsibility for the June 10 attack on Mackay Sugar, though the company has not confirmed ransomware use and continues to refer to the incident only as a "cyber security incident." Mackay Sugar reported progress over the weekend, including manual crushing at Farleigh Mill and steam trials, with a staged restart of crushing operations expected later this week. The group, known for self-propagating file-encrypting malware and a recent partnership with BreachForums, was profiled by Microsoft researchers last month.
The ransomware group Gentlemen has now publicly claimed responsibility for the attack, posting on its dark web leak site that it will publish allegedly stolen data unless a ransom is paid. Mackay Sugar confirmed it is aware of the claim and has found evidence of unauthorized external access to its IT environment, though it has not attributed the incident to any specific group. The company's Racecourse and Farleigh mills have remained shut since June 10, disrupting the annual sugarcane crushing season, but it expects some harvesting to resume this week as system restoration continues.