Agriculture rarely features in cyber security coverage, which suits attackers fine. Food producers run on tight margins and seasonal deadlines, hold valuable commercial and , and often treat security as a city problem. In 2026 two Australian producers found out otherwise, and the gap between their outcomes is the most useful thing about the story.
Two producers, two very different weeks
Tripod Farmers, a fresh produce supplier, was listed by the Qilin ransomware group after unauthorised access was detected around February. The company confirmed a breach affecting part of its systems, but said production and customer operations were not disrupted. The harvest kept moving while the incident was worked through. Whatever was reached, it was not the machinery that grows and packs the food.
Mackay Sugar had a harder time of it. In June, at the very start of the cane crushing season, a claimed by the group known as The Gentlemen forced two of its three Queensland mills offline and brought harvesting across roughly 1,300 family farms to a halt. This was not a data-theft story with an operational footnote. The plant itself stopped, at the worst possible moment in the calendar, and the company was reduced to limited manual crushing while it restored its systems.
The difference has a name: segmentation
The two outcomes trace back to one distinction. In a modern food business there are really two networks that matter. There is the IT network, which runs email, accounts, ordering and the office. And there is the operational technology, or OT, network, which runs the physical process: the crushers, the packing lines, the refrigeration, the sensors and controllers that turn cane into sugar or produce into pallets. When those two are properly separated, a compromise on the office side is a serious data problem but the plant keeps running. When they are flat, a single intrusion can reach from a straight to the machinery, and production stops.
We do not have the internal network diagrams of either company, so this is a lesson drawn from the pattern rather than a verdict on either business. But the pattern is consistent across industrial incidents everywhere: the organisations that keep producing through an attack are almost always the ones whose plant network was walled off from their office network, and the ones that grind to a halt are usually the ones where everything sat together. Segmentation is the control that decides which week you have.
Why agriculture is structurally exposed
Food and agriculture carry a few risks at once. The equipment is long-lived: a mill or a packing line may run control systems that are decades old and cannot be patched or easily replaced, because taking them offline is expensive and the season does not wait. The timing is brutal, because an attack during harvest or crushing does maximum damage with minimum effort, and attackers know it. And the sector has historically under-invested in security relative to the value it moves, which makes it a soft target with outsized importance to the food supply.
None of that is hopeless. Old equipment that cannot be patched can still be isolated, so a compromise elsewhere cannot reach it. The seasonal pressure that makes an attack so damaging is also the reason a small amount of preparation pays for itself many times over. The exposure is real, but it is addressable with structure rather than with a large budget.
What a food or agriculture business should do
- Separate the plant network from the office network, so that a compromised laptop cannot reach a controller. This single decision is what keeps you producing during an incident.
- Inventory the operational technology you run, including the old systems nobody wants to touch, and decide how each one is isolated and monitored.
- Treat the season as part of the threat model. Test your backups and your response plan before the harvest, not during it, because the worst time to discover a gap is the week the plant is meant to be at full tilt.
- Assume the office data is a target in its own right. Even when the machinery is safe, supplier terms, staff records and customer details are worth stealing, and they live on the network most likely to be phished.
The image of a hacker stopping an Australian sugar mill sounds like something from a briefing about distant infrastructure. In 2026 it was a Queensland producer at the start of the crushing season, and the thing that separated it from a competitor who kept running was not luck or sophistication. It was whether the office network and the plant network were the same network. For any business that turns raw material into product, that boundary is worth knowing about before an attacker tests it, and finding the gaps in it is what an internal penetration test does.



