Select Page

Ransomware attack targets New Cooperative

by | Sep 21, 2021 | 5 Ag Stories, News

New Cooperative, an agriculture cooperative in Fort Dodge, Iowa, suffered a ransomware attack this past weekend, threatening operations of a key company in the agriculture supply chain.

The attack was confirmed by a New Cooperative spokesperson on Monday, stating that they “recently identified a cybersecurity incident that is impacting some of our company?s devices and systems.”

“Out of an abundance of caution, we have proactively taken our systems offline to contain the threat, and we can confirm it has been successfully contained,” the spokesperson said. “We also quickly notified law enforcement and are working closely with data security experts to investigate and remediate the situation.”

New Cooperative, one of the larger farm cooperatives in the U.S., received a ransom demand of $5.9 million from the cybercriminal group BlackMatter.

“Please know that New Cooperative is treating this matter with the utmost seriousness, and we are using every available tool and resource to quickly restore our systems,” the spokesperson said. “We appreciate the patience of our valued customers as we investigate this matter and work to restore functionality and will share additional information directly with our customers as we learn it.?

During negotiations between a New Cooperative spokesperson and the hackers, New Cooperative stated that approximately 40 percent of the nation?s grain production runs through its software, and the ransomware attack would ?break the supply chain very shortly? if the hackers did not stop.

Allan Liska, senior intelligence analyst at cybersecurity group Recorded Future and one of the security professionals tracking the ransomware attack, said it still wasn?t clear how far the attack reached.

?New Coop is the 51st largest farm cooperative in the US, so there may be regional disruptions in the food deliveries and the ransomware attack appears to have taken New Coop?s Soil Map offline,? Liska said. ?What is interesting here is the invocation of CISA by New Coop in the released chats. We know that the threat actor behind BlackMatter is a sniveling little coward who ran and hid after the Colonial Pipeline attack; the New Coop is likely invoking CISA for the same reason, we?ll see if it has the same impact.?

The attack continues more than a year of increasing cyberattacks over the duration of the COVID-19 pandemic, most of which targeted groups that are critical to several key U.S. supply chains. JBS, the second-largest meat processing facility in the U.S., suffered an attack in June and chose to pay the ransom.