Ransomware attacks on food and ag expected to rise, possible ‘cascading impacts’ on the trade
Food and ag continues to be a target for ransomware attacks, per to a new report from threat intelligence agency the Food. Ag-ISAC (Information Sharing and Analysis Centers).
“We strongly encourage organizations to implement multi-factor authentication (MFA), network segmentation, regular system updates, and end-user training to reduce vulnerabilities and protect themselves from threats.”
Per to More than half of all attacks on food and ag are ransomware,, the Food and Ag-ISAC, which partners with the IT-ISAC to monitor ransomware incidents , Ransomware in food and agriculture now accounts for 5.5% of total ransomware attacks across industries. Of the 11 sectors monitored by ISAC, food and ag ranked sixth for ransomware attack volume. ‘Cascading impacts’ on the whole sector Ransomware attacks put the company as well as its suppliers and partners at risk, notes the report, and a single disruption can have “cascading impacts” on the whole trade.
As an example, the report highlights ransomware attacks impacting agricultural production lines: “Any downtime caused by an attack could lead to a chain reaction of delays, potentially causing late planting or harvesting windows. As a result, harvests may need to be palletized and moved to other regions during an active growing season.
This is already done in cases of severe climate, such as droughts or flooding, but it is an dear. Taxing process that strains limited resources.” The report in addition highlights the additional stressor of health and human protection being at risk when food and ag production are put at risk. Intellectual property — particularly where genetics are concerned — is also at risk, though the Food and Ag-ISAC notes that at this point, financial gain is the primary motivation for attacks on the industry. RansomHub — a comparatively young ransomware group, having emerged in 2024 — carried out the most attacks on the food and ag trade last year.
The group uses the “ ransomware-as-a-service ” model, where an operator recruits affiliates who pay to use the ransomware service. LockBit (see below) was previously the world’s most active RaaS group; law enforcement officials from 10 different countries disrupted the operation in 2024.
The Food and Ag-ISAC suggests this disruption (amongst others) likely boosted RansomHub’s ability to recruit affiliates. RansomHub usually targets larger organizations, per to the report.
Akira had the second-highest number of attacks on food and ag in 2024, with 16 attributed to the group. Akira emerged in 2023 and has since taken over an reckoned $42 million in ransom payments. The group uses double extortion tactics, which ISAC explains involves “infecting the target with ransomware, exfiltrating sensitive information. Then threatening to sell the information unless a ransom is paid.” According to the report, the group commonly exploits “vulnerable, public-facing systems” and targets “known vulnerabilities” in virtual private networks (VPNs).
Despite global law enforcement disruptions in 2024, LockBit still took the number three spot for ransomware attacks in food and ag, followed by Play, which as well uses double extortion, and RaaS group Hunters International. Threat landscape is ‘ever changing’ ISAC notes that attacks in food and ag tend to be opportunistic, rather than on specific firms. “For initial access, threat actors will search for organizations with publicly exposed and vulnerable systems, leverage phishing and social engineering attacks, or employ initial access brokers – cybercriminals and insiders who sell access to vulnerable networks,” states the report.




