Tripod Farmers Hit by Qilin Ransomware Attack, Data Exposure Suspected
Australian fresh produce supplier Tripod Farmers Group a family-owned business supplying independent and wholesale grocers was targeted in a ransomware attack by the Qilin cybercriminal group. The incident, detected around 17 February 2026, suggests the threat actors had prolonged access to the company’s systems before being discovered.
Qilin, one of the most active ransomware operations globally, initially listed Tripod Farmers on its leak site, claiming to have exfiltrated data. While the listing has since been removed, the group previously shared samples of allegedly stolen information, though details remain unverified. Cyber Daily’s attempts to independently verify the claims were unsuccessful.
In a statement, Tripod Farmers confirmed the breach, acknowledging unauthorized access to a portion of its systems but asserting that production and customer operations remained unaffected. The company is conducting an investigation, including examining Qilin’s claims, and has implemented additional security measures to prevent further incidents.
Tripod Farmers also disclosed that personal information may have been compromised, with affected individuals being notified as the investigation progresses. The company is collaborating with cybersecurity experts and has engaged the Office of the Australian Information Commissioner (OAIC) as part of its response.
About Qilin
Operating since 2022, Qilin has claimed 1,903 victims across 98 countries, making it the most active ransomware group currently. Unlike many ransomware operations that publish stolen data quickly, Qilin and its affiliates often delay disclosure sometimes for months with some victims from early 2026 still awaiting data leaks. The group follows a ransomware-as-a-service (RaaS) model, where affiliates use its infrastructure in exchange for a share of ransom payments. Evidence shared by affiliates varies, with some providing detailed proof of stolen data while others post minimal information.
Tripod Farmers Group TPRM report: https://www.rankiteo.com/company/tripod-farmers
"id": "tri1780971971",
"linkid": "tripod-farmers",
"type": "Ransomware",
"date": "6/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'fresh produce supplier',
'location': 'Australia',
'name': 'Tripod Farmers Group',
'type': 'business'}],
'customer_advisories': 'affected individuals being notified',
'data_breach': {'data_exfiltration': 'suspected',
'personally_identifiable_information': 'yes',
'type_of_data_compromised': 'personal information'},
'date_detected': '2026-02-17',
'description': 'Australian fresh produce supplier Tripod Farmers Group was '
'targeted in a ransomware attack by the Qilin cybercriminal '
'group. The incident suggests prolonged access to the '
'company’s systems before detection. Qilin initially listed '
'Tripod Farmers on its leak site, claiming data exfiltration, '
'though details remain unverified. Tripod Farmers confirmed '
'unauthorized access to a portion of its systems but stated '
'production and customer operations remained unaffected. '
'Personal information may have been compromised, and affected '
'individuals are being notified.',
'impact': {'data_compromised': 'personal information',
'operational_impact': 'production and customer operations remained '
'unaffected',
'systems_affected': 'a portion of its systems'},
'investigation_status': 'ongoing',
'motivation': 'financial gain',
'ransomware': {'data_exfiltration': 'suspected', 'ransomware_strain': 'Qilin'},
'references': [{'source': 'Cyber Daily'}],
'regulatory_compliance': {'regulatory_notifications': ['Office of the '
'Australian '
'Information '
'Commissioner (OAIC)']},
'response': {'communication_strategy': 'notifying affected individuals',
'containment_measures': 'additional security measures',
'third_party_assistance': 'cybersecurity experts'},
'threat_actor': 'Qilin',
'title': 'Tripod Farmers Hit by Qilin Ransomware Attack, Data Exposure '
'Suspected',
'type': 'ransomware'}