CSIDB logo
Incident

Mackay Sugar

Incident posture

Attack window
Jun 2026
Location
Australia
Status
Unknown
CIA posture
Available to members
Updated
2026-08-11 13:00

Linked entities

Victim
Mackay Sugar
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

Mackay Sugar, Australia’s second-largest raw sugar producer, disclosed a cyberattack that halted milling and cane haulage at two of its three Queensland mills, with one mill resuming limited manual crushing shortly thereafter. The Gentlemen ransomware group subsequently posted the victim on its leak site, while Dragos analysis found no indication the intruders reached industrial control systems or directly manipulated operational technology, assessing with low confidence that the disruption primarily impacted enterprise IT and remained uncertain whether the production stoppage stemmed from the attack or subsequent containment actions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Mackay Sugar, Australia’s second-largest raw sugar producer, disclosed a cyberattack on June 10 that stopped milling and cane haulage at two of its three Queensland mills. Two days after the initial disclosure, one of the impacted mills resumed limited manual crushing operations. The company did not provide further details on the extent of the disruption beyond the resumption of limited activity. Containment measures were undertaken after detection.

The Gentlemen ransomware group later posted Mackay Sugar on its data leak site, claiming responsibility for the intrusion. Dragos analysts investigated the incident and found no evidence that the threat actors had reached industrial control systems or directly manipulated operational technology. Researchers assessed with low confidence that the primary impact was on enterprise IT systems rather than on the production floor. They also noted that it remained unclear whether the observed shutdown resulted from the ransomware activity itself or from containment measures undertaken after detection.

The Mackay Sugar incident was counted among the 1,140 ransomware events involving industrial organizations reported by Dragos for the second quarter of 2026. This contribution reflects the broader trend of increasing ransomware activity against industrial sectors during that period. The case illustrates how disruption to enterprise IT can propagate to operational processes even without direct compromise of control systems.

Sources

Sources available to members: 1 source.

CSIDB