Skip to content
HOME / CYBERSECURITY / MACKAY SUGAR RANSOMWARE ATTACK 1 month AGO

Cybersecurity

Mackay Sugar Ransomware Attack – Another Cyber Attack

Mackay Sugar Ransomware Attack – Another Cyber Attack

Last Updated on June 17, 2026 by Arnav Sharma

The Mackay Sugar ransomware attack became public on 10 June 2026, just days after the company’s mills had started rolling for the annual cane crushing season. Mackay Sugar Limited, australia’s second-largest raw sugar producer and a major australian sugar manufacturer, disclosed that it was responding to a cybersecurity incident affecting some of its operations, forcing two of its three mills in Queensland to shut down and bringing cane harvesting across roughly 1,300 family farms to an immediate halt. As of 17 June, the company remains in active recovery, with The Gentlemen ransomware group having claimed responsibility and set a countdown timer for the release of allegedly stolen data.

This article covers the confirmed incident timeline, the operational impact on growers and cane supply chains, the technical profile of The Gentlemen ransomware group, and what the attack reveals about the cybersecurity posture of Australia’s food and agri-industrial sector.


What Happened: The Mackay Sugar Cyber Security Incident

On the morning of 10 June 2026, Mackay Sugar issued a public statement confirming it was responding to a cyber security incident affecting some of its operations. Mackay Sugar is responding to a cybersecurity incident that struck its major sugar mills and disrupted the wider cane supply chain. The company said it had engaged specialist cyber security experts and notified relevant authorities to investigate the breach. The company’s statement described its immediate focus as the safety of its people, protecting operational systems, and maintaining business continuity. Interim processes were stood up to support critical business functions.

The cyber attack immediately forced two of its three mills in Queensland offline: the Farleigh and Racecourse mills, both of which had recently commenced the 2026 crushing season. Canegrowers Mackay, the grower representative body for the region, confirmed that Mackay Sugar had instructed all harvesting to cease immediately and not resume until further communication came directly from the company. Sugar milling and cane haulage at both locations were suspended.

By 12 June, Mackay Sugar announced it had recommenced a limited manual crushing operation at Farleigh Mill, processing cane harvested prior to the incident. The recovery was deliberately narrow: the mill processed existing cut cane only, and no new cane was being accepted at any mills. Key cane supply and logistics systems remained under restoration. The June 12 statement made clear that while some operations had resumed in a controlled manner, the digital systems underpinning the full supply chain were not yet operational.

On 15 June, The Gentlemen ransomware group named Mackay Sugar on its Tor-based data leak site and set a countdown timer for the release of allegedly stolen data. The same day, Mackay Sugar said in an updated statement that significant progress had been made over the weekend in restoring the systems that support cane supply, harvesting, and mill operations. Steam trials were underway at the mills, with harvesting expected to recommence during the week in preparation for a staged restart of crushing operations.

As of 17 June 2026, the situation remains active.


A Timeline of the Incident

DateEvent
4 June 2026Farleigh Mill begins 2026 crushing season
9 June 2026Racecourse Mill begins 2026 crushing season
10 June 2026Mackay Sugar discloses cyber security incident; Farleigh and Racecourse mills shut down; growers ordered to cease harvesting
11 June 2026Marian Mill scheduled start (unaffected at time of disclosure)
12 June 2026Limited manual crushing operation restarts at Farleigh; no new cane accepted at any mill
15 June 2026Gentlemen ransomware group adds Mackay Sugar to leak site; company publishes recovery update; steam trials underway
17 June 2026Staged restart of crushing operations in preparation; no data leaked yet

Why the Timing of This Ransomware Attack Matters

The 2026 crush for the Mackay-Isaac region had only just begun when the cyberattack struck. Mackay Sugar had scheduled its three mills to start progressively from 4 June, with Farleigh leading, Racecourse following on 9 June, and Marian on 11 June. The company’s initial crop estimate for the season was 5.1 million tonnes of cane with a starting CCS (Commercial Cane Sugar) of 13.2.

That context matters for understanding the severity of the disruption. Sugar cane must be processed within a narrow window after cutting. Once cane is harvested, its sucrose content begins to degrade in the field and in transport. For the approximately 1,300 predominantly family-owned farms supplying Mackay Sugar’s mills, a halt in harvest operations is not simply a scheduling inconvenience: it represents direct financial loss through degraded CCS, sunk harvesting costs with nowhere to bill, and deferred income for what is often the entirety of a farm’s annual revenue.

Canegrowers Mackay confirmed the halt order on 10 June and described the broader context in terms of cautious optimism heading into a season that the industry was approaching with determination. That determination ran directly into a cyber attack timed, whether deliberately or coincidentally, to hit at the moment of maximum operational dependency.

The attack also struck when the cane supply chain was running at full intensity. Cane haulage, mill logistics, and harvest scheduling are coordinated through interconnected digital systems. When those systems went down, the entire supply network froze, not just the mills themselves.


Who Is The Gentlemen Ransomware Group?

The attack has been claimed by The Gentlemen ransomware group, tracked by Microsoft as Storm-2697. The group surfaced as a closed ransomware operation in mid-2025 and opened its ransomware-as-a-service (RaaS) model to affiliates in September 2025. By 13 June 2026, the group had listed 483 victims on its dark-web leak site, with 380 of those added in 2026 alone. That volume places The Gentlemen as the second most prolific ransomware brand by published victim count in 2026, behind only Qilin.

Microsoft’s threat research, published in May 2026, documented the group’s Go-based encryptor as a technically sophisticated tool that combines per-file ephemeral key encryption using Curve25519 and XChaCha20 with aggressive self-propagation across Windows networks. When deployed with its spread argument enabled, the malware functions as a self-propagating worm that attempts to reach and encrypt every reachable system on the network simultaneously. This worm-like lateral movement capability is what drew researchers’ particular attention.

The Gentlemen Attack Chain

Based on research from Microsoft, Check Point, and KELA, the group’s typical attack chain proceeds through the following stages:

Initial Access: The group primarily gains entry through unpatched edge devices, exploiting known CVEs including CVE-2024-55591 (Fortinet FortiGate), CVE-2025-32433, and CVE-2025-33073 (NTLM relay). A significant portion of initial access is also purchased from third-party brokers using credentials harvested by commodity infostealer malware.

Lateral Movement and Privilege Escalation: Once inside, operators enumerate Active Directory, conduct NTLM relay attacks, disable EDR solutions, and harvest browser session tokens to access Microsoft 365 and identity provider accounts.

Data Exfiltration and Encryption: Data is exfiltrated before encryption. The domain-wide ransomware payload is deployed via Group Policy, hitting every connected endpoint simultaneously.

Extortion: The group operates a dual-extortion model: encrypted systems plus a threat to publish stolen data on the leak site. A countdown timer is set after the victim is listed. The group also reportedly uses email and phone-based pressure tactics.

The affiliate model is structured to attract volume. External operators keep 90% of each ransom, which is a notably generous split even against current ransomware industry norms. A core team of approximately nine members builds and maintains the ransomware, the negotiation panel, and the infrastructure.

A May 2026 leak of the group’s internal Rocket.Chat database, covering November 2025 to April 2026, provided researchers at KELA and Check Point with a detailed view of internal operations. The leaked material revealed AI-assisted tooling, including the use of DeepSeek and Qwen models for data analysis and code development, and a small team operating with clear role divisions. The group’s administrator, tracked under the alias hastalamuerte, was identified as a former Qilin affiliate who built a competing operation after leaving that programme.

Whether this specific attack chain was used against Mackay Sugar has not been confirmed publicly. Mackay Sugar’s statements have not disclosed the initial access vector or the scope of systems affected.


The IT vs OT Recovery Problem: What the Steam Trials Tell Us

The most significant detail in Mackay Sugar’s 15 June recovery update, from a security architecture perspective, is the mention of steam trials.

Steam trials are the process by which a sugar mill tests its boilers and processing equipment to confirm they can operate safely before recommencing a full crush. They are the final operational validation step before cane goes back into the rollers. Mackay Sugar said steam trials were underway and that harvesting was expected to recommence in preparation for the staged restart of crushing operations.

This phrasing carries important implications. It means the company’s recovery timeline is not simply a matter of restoring IT systems. The organisation must also verify that mill operations themselves, including the systems that control boilers, conveyors, processing equipment, and rail logistics, are functioning correctly and safely before committing to a full restart.

Mackay Sugar’s statements have not confirmed whether industrial control systems (ICS) or operational technology (OT) were directly compromised, or whether those systems were affected as a downstream consequence of IT systems going offline. That distinction matters significantly for recovery timelines. IT recovery and OT recovery are different engineering disciplines with different verification requirements. A mill that has restored its business applications and email infrastructure is not necessarily a mill whose process control systems have been validated for safe operation.

The fact that steam trials are the gate before full resumption suggests the company is treating the OT environment with appropriate caution, running controlled tests before committing cane to the rollers. From a security architecture standpoint, this is the correct posture: assuming that IT-layer compromise could have created integrity risks in connected OT environments, and validating each layer before resuming production.


Australia’s Agri-Industrial Cybersecurity Gap

The Mackay Sugar incident surfaces a broader structural issue in Australian critical infrastructure protection. The Security of Critical Infrastructure Act 2018 (SOCI Act) and its 2021-22 amendments define 11 critical infrastructure sectors including electricity, water, communications, and financial services. Food and agriculture is not among the current designated asset classes.

Mackay Sugar is not, by current regulatory definition, a critical infrastructure operator. It has no mandatory incident reporting obligations to the Australian Cyber Security Centre (ACSC) under SOCI Act frameworks. Yet the operational impact of this attack, which halted sugar milling across two major mills in queensland, suspended harvesting for approximately 1,300 farms, and disrupted a supply chain feeding domestic and export markets, is functionally indistinguishable from the kind of disruption that would trigger critical infrastructure response protocols in a regulated sector.

The Mackay Sugar cyber attack follows a pattern of increasing ransomware targeting of Australian food and agricultural operators. Ransomware groups are actively working to compromise australian sugar operations and other food-sector targets. Earlier in 2026, Tripod Farmers, an Australian vegetable and salad producer, was listed by the Qilin ransomware group following alleged unauthorised access dating to February 2026. That incident received far less attention, but it demonstrates that the food and agriculture sector is not being treated as a secondary target by financially motivated threat actors.

For security architects and CISOs responsible for OT environments in food processing, resources, mining, and logistics, the Mackay incident offers several concrete observations:

  • Supply chain dependency mapping is an OT risk, not just a business continuity risk. The cane supply systems that coordinate farm-to-mill logistics were among the last systems to be restored, suggesting they were tightly coupled to the affected IT environment. OT and IT segmentation controls need to account for these operational dependencies explicitly.
  • Seasonal timing is a targeting window. Attackers who time their deployments to coincide with peak operational periods maximise pressure on the victim. Agricultural operators, utilities, and manufacturers with defined peak seasons should treat those windows as elevated threat periods requiring heightened monitoring.
  • Manual fallback capability has a narrow scope. The limited manual crushing operation at Farleigh was possible only because cut cane was available from before the attack. Once that pre-incident inventory was exhausted, manual operations would have become unsustainable. Resilience planning must account for how long manual fallback remains viable before operational losses become unrecoverable.

What Mackay Sugar Said and What Comes Next

Mackay Sugar Limited’s public communications have been measured and have avoided disclosure of the technical details of the attack or the scope of data potentially taken. The company continues to restore systems and bring its major sugar mills back to full operational capacity. The company’s 15 June update stated that significant progress had been made in restoring the systems that support cane supply, harvesting, and mill operations, that steam trials were underway, and that the company had taken the responsible course of action in advising growers and harvesters not to recommence harvesting until it advised them to do so.

The company said it recognised the impact the incident was having on growers and that it was doing everything it could to support them and safely resume full operations as soon as possible.

Mackay Sugar said it had engaged specialist cyber security experts and was working with relevant authorities to investigate the incident.

As of 17 June, The Gentlemen ransomware group had listed Mackay Sugar on its leak site but had not yet published any data. The absence of a data leak at this stage typically indicates that negotiations are ongoing or that the victim has not refused to engage. The Gentlemen group has set a countdown timer, which the group was reported to have set at just under 10 days from 15 June. That timeline places the data release deadline at approximately 24-25 June if the countdown was not extended or paused.

Whether data was exfiltrated, and if so what categories of data were taken, has not been publicly confirmed. Mackay Sugar’s customer-facing and supplier-facing operations involve significant volumes of financial, logistics, and supplier data, in addition to whatever corporate and operational data resides in the affected systems.

The broader context is an active and aggressive threat actor that had claimed 483 victims by 13 June 2026, is backed by a capable RaaS infrastructure, and has demonstrated willingness to apply escalating pressure tactics against organisations that resist or delay. Security practitioners monitoring this incident should track the Gentlemen leak site for any publication of Mackay Sugar data as an indicator of negotiation breakdown.

Arnav Sharma
Arnav Sharma Microsoft MVPMCT
Microsoft Certified Trainer · Cloud · Cybersecurity · AI

I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.

Frequently Asked Questions

KEEP READING

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.