All sectors

Ransomware in the Agriculture and Food Production sector

The Agriculture and Food Production sector has 48 known ransomware victims in Brazil. See the groups behind the attacks and the recent trend.

48victims
31groups
3in the last 90 days
Attack trend (12 months)
11
12
02
03
04
05
06
07
Groups attacking Agriculture and Food Production the most
lockbit35 victims
ransomhub 🇷🇺3 victims
thegentlemen3 victims
coinbasecartel3 victims
ralord2 victims
sarcoma2 victims
lockbit52 victims
funksec2 victims
arcusmedia2 victims
qilin2 victims
Vulnerabilities exploited against this sector

CVEs exploited by the groups attacking the Agriculture and Food Production sector — prioritize patching these.

CVE-2021-44228Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsKEVused by ransomwareCVE-2023-22518All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This ImpropeKEVused by ransomwareCVE-2023-35078An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionaKEVused by ransomwareCVE-2023-35082An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access resKEVused by ransomwareCVE-2024-3400PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectKEVused by ransomwareCVE-2019-11510In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, anKEVused by ransomwareCVE-2017-5638The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exKEVused by ransomwareCVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services whKEVused by ransomwareCVE-2019-19781An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, anKEVused by ransomwareCVE-2020-5902In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, thKEVused by ransomwareCVE-2021-21985The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in tKEVused by ransomwareCVE-2021-22005The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actorKEVused by ransomware
Recent victims
*****.ind.brSection9 · 2026-07-26
agroprimedragonforce · 2026-06-28
Eat Saladqilin · 2026-06-03
CEAGESP / Netfeiraspmedusalocker · 2026-05-05
JBS Brazil - Sample uploadedcoinbasecartel · 2026-04-08
Marborges Agroindustriaexitium · 2026-03-23
JBS Brazil - We have 3TB of your data - Pics addedcoinbasecartel · 2026-03-11
JBS Brazil - We have 3TB of your datacoinbasecartel · 2026-03-05
brassuco.com.brlockbit5 · 2026-02-26
brassuco.com.brlockbit5 · 2026-02-24
Grupo Progressothegentlemen · 2026-02-18
Ever Green Industria e Comercio Ltdathegentlemen · 2025-12-24
Usina Sao Jose Do Pinheirothegentlemen · 2025-12-24
Empresas Maggiworldleaks · 2025-12-09
Tupiqilin · 2025-12-09