INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Australian sugar producer hit by ransomware attack from Lazarus
| 2026-06-18 14:20 RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
A cyberattack disrupted operations at Mackay Sugar, Australia's second-largest sugar producer, on June 10, 2026. The company is investigating claims by a ransomware group known as Gentlemen, which claimed responsibility for the incident and threatened to publish allegedly stolen data if a ransom is not paid. Gentlemen emerged in late 2025 and operates a ransomware-as-a-service model, offering affiliates up to 90% of ransom payments, employing double-extortion tactics by stealing data in addition to encrypting systems. The attack affected Mackay Sugar's operations across one of Queensland's largest cane-growing regions, with two mills suspended since June 10, while the third facility avoided disruption. As a result of Australian law requiring victims of ransomware attacks to report extortion payments made to cybercriminals on their behalf, Gentlemen is believed by security researchers to be led by an unknown Russian speaker, affecting approximately three sugar mill operations and potentially impacting $420 million in annual revenue.
Technical Mitigations AI-generated
• Block or hunt for the Gentlemen ransomware group's double-extortion tactics by monitoring for stolen data and encrypted systems.
• Patch vulnerable systems to prevent exploitation of known vulnerabilities, such as those that could be exploited by Qilin, Embargo, LockBit, Medusa, and BlackLock.
• Verify authenticity of dark web leak sites before making any payments or communicating with ransomware groups.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
TheRecord
2026-06-18