Mackay Sugar, Australia's second-largest raw sugar producer, has suffered a significant cybersecurity incident identified as a ransomware attack. The company was forced to shut down operations at some of its cane-processing mills in Queensland, disrupting the local sugar supply chain. A threat group known as 'The Gentlemen' has claimed responsibility for the attack. The incident underscores the increasing threat of ransomware to critical infrastructure and the manufacturing sector, where operational technology (OT) and information technology (IT) convergence creates unique risks.
On June 10, 2026, Mackay Sugar acknowledged a cybersecurity incident impacting its systems. The situation escalated on June 15, when the ransomware group 'The Gentlemen' added Mackay Sugar to its list of victims on their dark web leak site. This is a common tactic in double-extortion schemes, where attackers both encrypt data and threaten to publish stolen data to pressure victims into paying.
While the company managed to restart limited manual operations at one mill, key logistics and processing systems remained offline, causing a significant bottleneck in the regional sugar production process.
The exact initial access vector has not been disclosed. However, ransomware groups like 'The Gentlemen' typically use common TTPs to infiltrate networks.
A key question in this incident is the extent of impact on the Industrial Control Systems (ICS) / Operational Technology (OT) environment. Even if the OT network was not directly hit, the shutdown of IT systems that manage logistics, scheduling, and processing can effectively halt industrial operations.
The business impact on Mackay Sugar and the surrounding region is substantial:
This attack serves as a stark reminder that the manufacturing and agriculture sectors are high-value targets for ransomware gangs due to their low tolerance for downtime.
No specific Indicators of Compromise (IPs, domains, hashes) were mentioned in the source articles.
To detect similar ransomware attacks, security teams can hunt for the following patterns:
powershell.exe, wmic.exe, nltest.exevssadmin.exe delete shadowsEnforce MFA on all remote access points and for all administrative accounts to prevent credential-based attacks.
Implement and enforce strict network segmentation between IT and OT environments to prevent ransomware from spreading to critical industrial control systems.
Maintain regular, tested, and offline/immutable backups of critical data and system configurations to enable recovery without paying a ransom.
Provide ongoing security awareness training to help users identify and report phishing attempts.
Mackay Sugar announces it is responding to a cybersecurity incident.
Mackay Sugar recommences limited manual crushing at one mill.
The ransomware group 'The Gentlemen' claims responsibility for the attack.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.