Agriculture & Food — Cyber Threat Activity
Agriculture and food is critical infrastructure that is rarely defended as such, and our log records more than 570 incidents against it across 66 countries, over 185 in the trailing 180 days. 69 groups have been attributed at least one claim, led by Qilin (79), Akira (68), LockBit (40), Play (40) and RansomHub (39). The sector's exposure is seasonal in a way that no other sector's is. Harvest, slaughter, processing and cold chain all run to biological deadlines, so an outage during a narrow window destroys perishable stock outright rather than merely deferring revenue, and attackers who understand that timing hold unusual leverage. Consolidation compounds it: a small number of processors, cooperatives and logistics operators sit between farms and retailers, so a single compromise can idle a disproportionate share of national capacity. The sector also attracts attackers with no interest in payment. CISA and partners named Food and Agriculture explicitly among the sectors where pro-Russia hacktivist groups reached internet-exposed human-machine interfaces protected by default, weak or absent passwords, then altered setpoints and locked operators out of their own controls. Those agencies assess the groups lack the engineering knowledge to predict the physical consequences of what they change, which makes the activity less predictable than a ransomware negotiation rather than less dangerous. Recorded geography is United States-led at 219 claims, then Canada, Italy, France, Spain and the United Kingdom. Only 8 groups carry a researched association with the sector at profile level, against 69 attributed through incidents, so this is a sector where the measured log, not the research graph, is the honest evidence base.
- Recorded incidents: 748
- Incidents, trailing 180 days: 237
- Tracked threat actors: 82
- Malware families: 10
Recent incidents
- Ceres Tolvas 2026-09-18
- Futuro Forestal 2026-09-18
- Bee Maid Honey 2026-09-16
- Cedars Foods 2026-09-15
- Wada Farms 2026-09-15
- Asada Sarapiqu 2026-09-15
- ADM 2026-09-15
- Rosello et Fils 2026-09-14
- CARIDRO VAL DE LOIRE 2026-09-13
- gardensalive.com, bitsandpieces.com, iselinursery.local, weeksroses.org, esm.local 2026-09-09
- Aqualogus 2026-09-09
- gayafores.es 2026-09-08
- El Carriel 2026-09-07
- Superior Ag 2026-09-03
- meccahighfeed.blogspot.com 2026-09-01
- Alphaplantes (Service d'Entretien des Plantes Alpha Inc.) 2026-09-01
- Figgins Family Wine Estates 2026-08-31
- Nutrypollo 2026-08-30
- Neogen Corporation 2026-08-29
- Servifruit 2026-08-27
Threat actors targeting Agriculture & Food
- Qilin 112 incidents
- Akira 79 incidents
- LockBit 50 incidents
- Play Ransomware 46 incidents
- Cl0p 42 incidents
- RansomHub 39 incidents
- The Gentlemen 39 incidents
- DragonForce 33 incidents
- SafePay 24 incidents
- INC Ransom 23 incidents
- Lynx Ransomware 23 incidents
- Medusa Ransomware 17 incidents
- Black Basta 16 incidents
- Meow 12 incidents
- Sarcoma 12 incidents
- Cactus 11 incidents
- 8Base 10 incidents
- Hunters International 8 incidents
- NightSpire 8 incidents
- RansomHouse 8 incidents
- Krybit 7 incidents
- APT73 6 incidents
- Fog Ransomware 6 incidents
- KillSec 6 incidents
Where these victims are
- United States 257
- Canada 46
- Italy 36
- Spain 34
- France 30
- Germany 23
- United Kingdom 21
- Brazil 17
- Argentina 15
- Japan 14
- Australia 13
- Mexico 12
Malware used against Agriculture & Food
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Metasploit Tool
- Mimikatz Tool
- PsExec Tool
- AdFind Tool
- BlackByte Ransomware Malware
- Rclone Tool
- Arp Tool
- BlackByte 2.0 Ransomware Malware
- Exbyte Malware
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.