BlackMatter demands $5.9 million ransom from Iowa farm cooperative
BlackMatter is demanding the ransom so the cooperative can unlock its systems right before the harvest season is set to begin


New Cooperative, an Iowa-based cooperative that operates grain storage elevators and buys crops from farmers, has been hit by a $5.9 million (£4.3 million) ransom demand after being hit by the BlackMatter group.
The BlackMatter ransomware leak page shows the gang has obtained financial documents, network information for multiple companies associated with New Cooperative, social security numbers and personal information of employees, and source code for Soil Map, a farmer technology platform, ransomware expert Allan Liska told ZDNet.
The group claims to have 1TB of data and has set a timer it says will expire at midday on 25 September. It's also demanding a $5.9 million ransom payment from New Cooperative.
"We have proactively taken our systems offline to contain the threat, and we can confirm it has been successfully contained," New Cooperative said in a statement to Reuters. "We also quickly notified law enforcement and are working closely with data security experts to investigate and remediate the situation."
On social media, there are screenshots of chat logs which appear to be between the ransomware group and New Cooperative. The farming group states that it is critical infrastructure as it is intertwined with the food supply chain in the US, and is asking why it was attacked if BlackMatter claims to not attack critical infrastructure.
RELATED RESOURCE
“About 40% of grain production runs on our software, and 11 million animals feed schedules rely on us,” said New Cooperative, before adding that CISA would be demanding answers from the group in the next 12 hours and “we are going to have to tell them exactly what happened and why the food supply chain is disrupted”.
BlackMatter refused to back down, replying to the company that “you do not fall under the rules, everyone will only incur losses,” before saying the company should come to an agreement with them and solve everything quickly.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Don Roose, the president of US Commodities in West Des Moines, Iowa, told Reuters that the timing of the attack is making it crucial that NEW Cooperative get its systems back online as soon as it can as many farmers will start their combines this week and begin delivering crops to NEW’s elevators across the state.
“They have got you boxed into a corner,” Roose said. “Harvest is right now. This is the week that we are just starting to ramp up harvest, particularly for soybeans.”
IT Pro has contacted New Cooperative for comment. CISA declined to comment on the story.
In June, JBS Foods paid an $11 million (£7.8 million) ransom to hackers who compromised its IT system. The meat processing company fell victim to a ransomware attack in May and was forced to suspend its systems and, in some areas, shut down production for 24 hours. The company confirmed it made the ransom payment to the attackers, totalling $11 million in Bitcoin.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Ransomware attacks are rising — but quiet payouts could mean there's more than actually reported
News Ransomware attacks continue to climb, but they may be even higher than official figures show as companies choose to quietly pay to make such incidents go away.
By Nicole Kobie
-
Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won't be the last
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott
-
Healthcare systems are rife with exploits — and ransomware gangs have noticed
News Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
By Nicole Kobie
-
Alleged LockBit developer extradited to the US
News A Russian-Israeli man has been extradited to the US amid accusations of being a key LockBit ransomware developer.
By Emma Woollacott
-
February was the worst month on record for ransomware attacks – and one threat group had a field day
News February 2025 was the worst month on record for the number of ransomware attacks, according to new research from Bitdefender.
By Emma Woollacott
-
CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted
News The Medusa ransomware as a Service operation compromised twice as many organizations at the start of 2025 compared to 2024
By Solomon Klappholz
-
Warning issued over prolific 'Ghost' ransomware group
News The Ghost ransomware group is known to act fast and exploit vulnerabilities in public-facing appliances
By Solomon Klappholz