ransomware
Ransomware halts crushing at Mackay Sugar mills
2026-06-16

Mackay Sugar, which operates three cane-processing mills in Queensland and ranks as Australia's second-largest raw sugar producer, spent most of a week trying to get its operations back on their feet after a ransomware attack disclosed on 10 June. Two of its three mills were affected.
By 12 June, the company had patched together a limited manual crushing operation at one site to deal with cane already harvested before the incident. It stopped accepting new cane and asked growers and harvesters to hold off. Not a small ask in the middle of a crushing season.
By 15 June, the picture had improved. Cane supply, harvesting and mill systems were being restored, steam trials were underway, and a staged restart was planned for later that week. On the same day, a ransomware crew calling itself The Gentlemen added Mackay Sugar to its Tor leak site. No data has been published so far, and the company has not commented on whether information was stolen or whether the attackers got anywhere near the industrial control systems that actually run the mills.
Who are The Gentlemen?
The Gentlemen, tracked by Microsoft as Storm-2697, only surfaced in mid-2025 and already lists more than 500 alleged victims. Researchers have flagged their malware for worm-like lateral movement, which is a polite way of saying it spreads itself across a network with very little help once it has a foothold.
That's the part worth paying attention to. A group most defenders had not heard of a year ago has racked up a victim count that would have put it in the top tier of ransomware operations a few years back. The barrier to running a credible extortion business keeps dropping, and the tooling keeps getting more capable.
Why a sugar mill is a good target
The thing that makes this incident worth a second look is how quickly an IT problem becomes a physical one when the business is a factory. Cane has a harvest window. Growers, harvesters, hauliers and the mills themselves all run on a tight schedule that nobody controls once the crop is in the ground.
A few days of downtime at a sugar mill is not the same as a few days of downtime at a marketing agency. The cane keeps arriving, or it would, if the company could accept it. Sugar content drops once cane is cut. Harvest crews sit idle on day rates. Growers further down the chain start losing money the moment the mill stops.
That time pressure is precisely the leverage ransomware crews are buying when they target industrial operators. The negotiation isn't really about whether the files come back. It's about whether the next week's worth of cane gets crushed before it spoils, and whether the relationships with hundreds of growers survive the disruption.
What's still unclear
- Whether data was stolen. The Gentlemen listed Mackay Sugar but haven't published anything. That could mean negotiations, or simply that the leak is queued.
- How the attackers got in. No public detail yet on initial access.
- Whether OT systems were touched. Mackay has not said whether the industrial control side of the mills was reached, or whether the disruption came from bringing IT systems down as a precaution.
The mills are restarting. The harder questions, about what was taken and how a worm-like intruder got across the network in the first place, will take longer to answer.