On June 10, two mills belonging to Mackay Sugar — Australia's second-largest sugar producer — went offline. Cane harvesting across more than 1,300 farms stopped. The company's cogeneration plant, which supplies power to the surrounding region, was also affected. The Gentlemen ransomware group claimed responsibility and gave the company ten days before it would publish stolen data.
The timing wasn't random. June is the start of crushing season — the narrow window when harvested cane must be processed before it deteriorates. Shutting down at that moment creates maximum financial pressure and maximum leverage for a ransom demand.
That operational awareness is what's worth paying attention to.
This Isn't Just a Technology Story
When ransomware makes the news, focus typically lands on technical mechanics — what malware was used, how it got in, what systems were affected. Those details matter for incident response teams. For executives and OT leaders, the more important question is different: how did they know when to hit?
The Gentlemen didn't pick a random Tuesday. They targeted a food production asset during its highest-value operational window. One plausible explanation is prior access used for reconnaissance; another is open-source research into the company's operational calendar. Either way, it reflects targeting sophistication that goes beyond opportunistic criminal activity.
This is the pattern emerging across ransomware groups targeting critical infrastructure — attacks that get in, look around, understand the environment, and choose their moment. Mackay Sugar is the Australian example. It won't be the last.
Who The Gentlemen Are
The Gentlemen emerged in September 2025 as a Russian-speaking ransomware-as-a-service operation. In under a year they have listed 483 victims globally — 380 in 2026 alone — making them the second most prolific ransomware operation on record this year.
They operate as a franchise. The core gang builds and maintains the tools, infrastructure, and playbook. Independent affiliates carry out the attacks, keeping 90 cents in every dollar collected. Most RaaS operations pay affiliates 70–80%. That unusually high cut attracts experienced operators capable of more sophisticated campaigns — which is consistent with what happened at Mackay Sugar.
Their toolkit includes GentleKiller, an EDR bypass framework designed to disable endpoint security software before the ransomware payload deploys. It operates at the kernel level, below where most security tools detect threats. By the time anything visible happens, the damage is already in progress.
Their targeting decisions are purely economic — any critical infrastructure asset with operational leverage and the ability to pay is a viable target.
The Double-Extortion Reality
The Gentlemen don't just encrypt data. They steal it first, then use the threat of publication as a second lever.
For critical infrastructure operators, this extends the problem beyond the immediate incident. OT environments hold network diagrams, system configurations, access credentials, and documentation of critical systems. When that information is published or sold — as The Gentlemen threatened within ten days of the Mackay Sugar attack — it provides intelligence for future attacks, whether by the same group or others who purchase it.
Restoring from backups doesn't contain that exposure.
The Clock That Starts Immediately
Under the SOCI Act, a responsible entity must report a significant cyber security incident to the Australian Signals Directorate within 12 hours of becoming aware of it.
In those first twelve hours, every team in the building is focused on containment and recovery. The reporting obligation runs in parallel — and doesn't wait for the dust to settle. Organisations that haven't rehearsed who makes the ASD notification, and at what point in the response, will find that window closes faster than expected.
What to Ask Now
Three questions from the Mackay Sugar incident are worth taking back to your own organisation.
Can an attacker identify your most operationally vulnerable window from open sources? Annual reports, industry publications, and operational schedules often contain enough to inform targeting. Understanding your own calendar as an attacker would is a useful exercise.
Has your network segmentation been tested, not just designed? A common pathway in critical infrastructure ransomware incidents runs from a compromised corporate system into OT. Whether your segmentation holds under a lateral movement attempt is a question for a penetration test, not an assumption.
Does your incident response plan name who calls ASD, and when? Compliance under pressure requires the decision to already be made. If the answer isn't documented and rehearsed, that gap will show up at the worst possible time.
James' Take
Here's what I keep coming back to with this one: the most dangerous thing The Gentlemen did wasn't the malware. It was the calendar.
Crushing season isn't confidential. It's in annual reports, industry publications, local news. Whoever planned this attack understood the operational leverage they were buying by hitting in June rather than January. That's not a technical capability — it's basic research.
Every sector under SOCI has a version of crushing season. Harvest windows. Refinery turnarounds. Peak demand periods. Maintenance shutdowns. Most of that information is publicly accessible if you know where to look.
So the question I'd be asking if I were responsible for cyber risk in an Australian critical infrastructure organisation isn't "are we a target?" It's "could someone with a search engine and a few hours figure out our most vulnerable window?" If the answer is yes — and for most organisations it probably is — that's the conversation to have with your security team this week.