Ransomware · 103 giorni fa
L’uscita dall’emergenza operativa non basta più: quando c’è prova che un esterno ha raggiunto parti dell’ambiente IT e il gruppo minaccia un leak, la risposta deve spostarsi dalla sola ripartenza alla verifica di cosa possa essere stato copiato. Il punto non è più solo rimettere in moto gli impianti, ma capire se l’incidente è già diventato estorsione con rischio di divulgazione.
Mackay Sugar ha detto di aver trovato evidenza di accesso esterno e di stare verificando la rivendicazione di Gentlemen, che ha pubblicato la minaccia di diffondere dati se non viene pagato. Il caso è al terzo giorno e resta legato al blocco di due mill in Queensland, ma la notizia nuova è proprio questa: l’azienda non sta più solo recuperando i sistemi, sta cercando di capire l’estensione dell’eventuale esfiltrazione.
Per chi gestisce siti produttivi dipendenti da IT e logistica, lo schema cambia la lettura dell’incidente: un fermo può essere seguito da una fase di pressione pubblica sui dati, e la sola ripresa operativa non chiude il problema.
4 fonti che coprono questa storia
The Record from Recorded Future
Australian sugar producer works to restore operations as ransomware group claims attack
Mackay Sugar said it was "working urgently" to verify claims that a highly active ransomware group was behind a cyberattack that shut down harvesting and milling operations.
Cyberattack sees crops kept in the ground
Bitter harvest for Australia's Mackay Sugar, attacked in peak cane crushing season
Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.
Cyberattack disrupts Mackay Sugar operations, highlighting escalating cyber threats to agri-industrial production and logistics.
The Record from Recorded Future
Cyberattack shuts down major Australian sugar mills, disrupting harvest
Australia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity experts and local authorities to investigate the attack and restore its systems safely.
Part of the PlainSec briefing for 2026-06-16