The Food and Ag-ISAC has released its State of the Threat: Food and Agriculture Sector Cyber Trends report, identifying six trends shaping the sector’s cyber risk landscape in 2026. The report draws on the organization’s threat intelligence, member collaboration and partner reporting covering more than 330 tracked adversaries, highlighting growing risks from artificial intelligence, ransomware, nation-state activity, hacktivism, typosquatting and social engineering. This comes as these organizations face a rapidly expanding cyber threat landscape in the first half of 2026, with attackers targeting everything from OT (operational technology) and supply chains to employees and digital infrastructure.
The report found that ransomware incidents targeting the food and agriculture sector increased 62% through July 2026 compared with the same period last year, while ClickFix social engineering attacks surged 108% during the first half of 2026. It also warned that AI is accelerating vulnerability discovery and shortening the time between disclosure and exploitation to hours, while state-sponsored actors are pre-positioning in OT environments and cybercriminals are using fraudulent lookalike domains to target supply chains.
The Food and Ag-ISAC, in partnership with the IT-ISAC, identified six trends based on ongoing threat intelligence, member collaboration and partner reporting, highlighting the growing pressure on defenders to adapt as attacks become faster, more targeted and increasingly destructive.
Artificial intelligence is accelerating both vulnerability discovery and exploitation, leaving defenders with less time to assess and address newly disclosed flaws. Ransomware also continued to intensify, with the sector recording 227 incidents through July 2026, up 62% from the same period in 2025. Meanwhile, nation-state actors are expanding beyond traditional espionage by positioning themselves inside critical infrastructure and using fraudulent remote IT hiring schemes to gain access to organizations.
Hacktivist groups are also becoming more closely tied to geopolitical conflicts, shifting from website defacement and denial-of-service campaigns toward destructive attacks targeting operational environments. Cybercriminals are exploiting typosquatted domains that imitate food and agriculture companies and suppliers to facilitate business email compromise, redirect payments and steal credentials across the farm-to-table supply chain.
ClickFix has emerged as another prominent initial-access technique, with attackers using fake error messages to persuade users to copy and execute malicious commands. Together, these developments point to a threat environment requiring network defenders to maintain constant vigilance and make near-real-time adjustments as adversaries continue to evolve their tools and tactics.
“Farm and processing equipment is growing more autonomous, from GPS-guided tractors and robotic harvesters to automated feed mills and self-adjusting cold storage systems,” according to the Food and Ag-ISAC report. “The attack surface is growing faster than most teams can inventory. Every networked grain silo sensor, automated feeder, and cold chain thermometer is a potential entry point for lateral movement, part of what can be referenced as a ‘shadow operational technology (OT)’ problem. These operational devices are added for efficiency and often go unseen by traditional IT asset management.”
Moreover, AI-assisted monitoring helps surface that shadow inventory and flag when one of those devices starts behaving abnormally, something a team relying on manual log review would likely miss until too late. “In addition, AI-assisted vulnerability discoveries are driving a surge in disclosed vulnerabilities. For example, CVE disclosures are on pace to hit 66,000 in 2026, running 46.3% ahead of projections released by FIRST. In 2025, of the roughly 48,000 CVEs disclosed, only about 1% were actually exploited. Whether that gap between disclosure and exploitation will hold in 2026 and beyond remains to be seen.”
However, the Food and Ag-ISAC report highlighted that for a sector where OT, including PLCs (programmable logic controllers) that run processing lines, irrigation, and grain handling equipment, is increasingly internet-connected, this trend is especially consequential. Compounding this, the same tooling that surfaces vulnerabilities is compressing the time to weaponize them. Proof-of-concept exploit code that once took days to develop can now be generated in hours. Exploitation remains narrow, but arrives fast, and that combination of volume and velocity is what makes triage, not coverage, the defining patch management challenge. Network defenders cannot treat every new CVE as equally urgent, and exposed OT and ICS (industrial control system) components deserve heightened scrutiny.
The report observed that the ‘patch everything, patch now’ approach that often works for other organizations, such as a cloud-native IT shop, is not realistic in the food and agriculture sector. A processing line cannot be taken offline mid-harvest to apply an update, and many of the PLCs and sensors running that line may be years old, possibly running firmware that may not have a patch available. Most security teams lack the bandwidth to chase every CVE that crosses their feeds. Instead, they need to know which vulnerabilities in their environment are actually likely to be exploited. They can then prioritize those and wait until the next scheduled maintenance window for lower-risk vulnerabilities.
The Food and Ag-ISAC revealed that ransomware remains the most consistent and costly threat facing the food and agriculture sector. Unfortunately, 2026 is on pace to be one of the highest-volume ransomware years on record. Through July, the Food and Ag-ISAC, in partnership with the IT-ISAC, tracked 4,272 successful ransomware attacks across 108 unique threat groups, up 22.7% over the same period in 2025 (4,381 attacks) and 219.5% over the same period in 2024 (1,337 attacks).
“Through July, the food and agriculture sector accounted for 227 ransomware incidents, a 62% increase from the 140 attacks recorded during the same period in 2025,” according to the report. “The Qilin ransomware group was the most active toward the sector with 47 listed attacks, followed by The Gentlemen (31) and Akira (14). These incidents represented roughly 5% of all attacks tracked into July, ranking food and agriculture as the eighth most-targeted sector.”
It added that while some attacks are targeting food and agriculture companies specifically, overall ransomware attacks remain largely opportunistic. Most campaigns scan for exposed systems, acquire access through brokers, and rely on phishing and social engineering to compromise the first vulnerable organization that surfaces. Food and agriculture entities are swept up in that high-volume, indiscriminate activity as much as they are deliberately singled out.
The Food and Ag-ISAC report observed that nation-state cyber activity intensified in 2026 as hackers expand beyond traditional espionage to pursue strategic national objectives including intelligence collection, military preparation, revenue generation, and infrastructure disruption capabilities. These actors differ from financially motivated criminals in their longer-term approach, seeking access, intelligence, or leverage that may not require immediate exploitation. For the food and agriculture sector, nation-state actors now represent the second-largest category of adversaries, after ransomware groups, making this distinction particularly significant for defensive planning.
China’s cyber activity exemplifies strategic positioning as cyberspace dominance remains a stated pillar of their national strategy. Chinese operators are pre-positioning inside U.S. critical infrastructure to establish disruption capabilities for potential future conflict. Beyond operational systems, Chinese actors have demonstrated sustained interest in intellectual property and technologies related to seeds, agricultural chemicals, biotechnology, and food production, making the sector valuable both as critical infrastructure and as a source of economic and technological intelligence.
Russia combines traditional state-sponsored operations with a broader range of actors whose government relationships remain ambiguous. Russian state-sponsored operators continue targeting critical infrastructure and exploiting vulnerable networking equipment for persistent access and intelligence collection. A July 2026 advisory highlighted activity tied to the Russian Federal Security Service’s Center 16, associated with threat groups including Berserk Bear, Energetic Bear, Crouching Yeti, and Dragonfly, targeting vulnerable infrastructure across multiple critical sectors.
Iran blurs the line between state operations and hacktivism while showing willingness to directly target food security, with federal agencies confirming attacks on internet-exposed programmable logic controllers used in processing lines and grain handling systems. Meanwhile, North Korea dispatches thousands of skilled IT workers posing as remote employees using stolen identities and crypto payment chains to launder wages back to the regime. What began as a salary-collection scheme has evolved into more damaging activities, including data theft, source code exfiltration, extortion, and insider access sales to other threat actors.
The report highlighted that hacktivism against food and agriculture is increasingly significant, particularly during geopolitical conflict. Unlike nation-state actors, hacktivists are typically politically or ideologically motivated and operate without confirmed direct state control, representing 9.7% of tracked adversaries across more than 330 actors according to the Food and Ag-ISAC Cyber Threat Report.
Historically relying on accessible tactics such as distributed denial-of-service attacks, website defacements, and data leaks, hacktivist groups in 2026 are reaching further into operational environments, targeting internet-accessible systems including human-machine interfaces, SCADA systems, and automatic tank gauges that monitor fuel and liquid storage. Groups such as Dark Engine have demonstrated capability to target HMIs controlling automated machinery, potentially halting production lines, disrupting irrigation systems, or interfering with temperature-controlled storage.
Recent geopolitical events have shown how rapidly hacktivist activity can surge. Following Operation Epic Fury, researchers tracked 149 distributed DDoS claims against 110 organizations across 16 countries, with heavy concentration against SCADA systems that run industrial and agricultural equipment. This activity aligns with CISA’s 2025 warning that pro-Russia hacktivists are actively targeting food and agriculture’s internet-facing OT infrastructure, alongside water and energy sectors.
The distinction between hacktivism and nation-state activity has become increasingly blurred. Pro-Russia groups such as Cyber Army of Russia Reborn, NoName057(16), Z-Pentest, and Sector16 present themselves as hacktivists while advancing Russian geopolitical interests and may receive indirect government support. Iran has taken this approach further, with personas such as CyberAv3ngers and Handala using hacktivist branding despite documented links to the IRGC and Ministry of Intelligence and Security. For food and agriculture organizations, ‘hacktivist’ should not be assumed to indicate low impact or independence, particularly as politically motivated actors increasingly target exposed operational technology.
The Food and Ag-ISAC report also detailed typosquatting, referencing registering domains with intentional misspellings or close variations of legitimate company names, which has become a primary enabler of business email compromise and payment fraud in the food and agriculture sector. Attackers use these lookalike domains to impersonate suppliers, customers, or executives, timing fraudulent invoices and payment redirection requests to appear indistinguishable from routine business correspondence.
The technique extends beyond email misspellings to include cloned vendor portals and payment pages, increasingly paired with AI-generated deepfake audio or video that impersonates executive voices. The Food and Ag-ISAC has tracked these fraudulent domains and found the majority target food processing and manufacturing, where invoicing and payment volume between suppliers and buyers is highest in the supply chain.
Typosquatting is accelerating as domain registration volumes grow substantially. The Domain Name Industry Brief reported 401.6 million domain name registrations in Q2 2026, an 8.1% increase over the prior year, reflecting the scale defenders face. At this volume, identifying a single lookalike domain before it is weaponized requires automated monitoring to detect threats before they can be exploited.
The report also detailed ClickFix, which has gone from a niche technique to one of the fastest-growing initial access methods in the threat landscape. What makes ClickFix worth calling out as a genuine trend, rather than a single clever gimmick, is who has adopted it and how fast it keeps evolving.
Adopted by both state-backed and criminal actors, this technique has been folded by nation-state groups into espionage operations, while ransomware operators use it as a reliable way to get a foothold before deploying ransomware or selling access to someone who will.
At its core, ClickFix turns the victim into the execution mechanism. Rather than exploiting a software vulnerability, attackers present a fake problem, such as a failed CAPTCHA, broken video player, or other seemingly routine technical problem, and then provide instructions for the user to ‘fix’ it. Those instructions typically involve copying and pasting attacker-supplied commands into PowerShell, Windows Terminal, the Run dialog, or another legitimate system utility. Since the user initiates the command, the activity can bypass some traditional security controls and appear, at least initially, like legitimate administrative behavior.


