The tractors rolling across the American Midwest no longer run on diesel and muscle alone. They run on code. GPS-guided planters, drone-based crop scouts, sensor-laden irrigation systems, cloud-connected grain elevators, and machine-learning platforms that predict yields weeks before harvest have turned farms into sprawling distributed computer networks. And like every other large computer network, they can be attacked. A new Perspective published in Nature Food argues that the United States’ agricultural and food systems, one of the sixteen critical infrastructure sectors designated by the US Department of Homeland Security, are dangerously exposed to cyberattacks, and that the country needs a coordinated, university-led defense effort before a major incident turns a digital breach into a food security crisis.
The paper, authored by a large multidisciplinary team led by Feras A. Batarseh of Virginia Tech together with researchers from Iowa State University, Washington State University, the University of California Davis, and several other institutions, is the product of a workshop series that brought together more than 150 stakeholders from academia, industry, government, and farming communities. Its central claim is stark: cyberattacks across the agrifood sector are escalating, while the sector’s defenses remain fragmented, underfunded, and poorly adapted to the realities of agricultural technology. The FBI’s Internet Crime Report for 2024 documents the broader surge in cybercrime, and sector-specific reviews of food and agriculture incidents describe a steady accumulation of ransomware attacks, data breaches, and intrusions into farm and food-processing networks. The Food and Agriculture Information Sharing and Analysis Center’s assessment of the 2025 ransomware landscape suggests the trend is not abating heading into 2026.
What makes agriculture uniquely vulnerable is the sheer heterogeneity of its digital footprint. A modern smart farm may combine legacy industrial control systems in grain handling with consumer-grade Internet of Things sensors in fields, precision agriculture equipment running proprietary firmware, and cloud analytics platforms aggregating data across thousands of operations. Survey literature on smart farming documents how IoT devices, big data platforms, and Agriculture 4.0 technologies have multiplied the attack surface faster than security practices have evolved. Researchers have demonstrated attack scenarios against smart farming infrastructure, including denial-of-service attacks against connected equipment and side-channel attacks against digital agriculture systems. Security analyses of cyber-physical systems in agricultural settings, and even deliberately vulnerable sensor frameworks built for research purposes, illustrate how thin the defensive margin often is. Unlike a bank or a hospital, a farm typically has no security operations staff, no intrusion detection capability, and often no awareness that its irrigation controller or tractor telematics unit could be a target at all.
The consequences of a successful attack extend well beyond a single operation. The food supply chain is a tightly coupled network in which disruption at one node, a grain elevator, a meatpacking plant, a cold-chain logistics provider, propagates rapidly downstream. Systematic reviews of cybersecurity vulnerabilities in the food supply chain link potential intrusions directly to food security outcomes, and the US Cybersecurity and Infrastructure Security Agency has issued both a food and agriculture cybersecurity checklist and earlier alerts on threats to precision agriculture. Ransomware attacks on food processors have already forced production halts in recent years, and the sector’s dependence on just-in-time logistics means that even short outages can cascade. The Nature Food authors argue that the sector’s cyber resilience must be treated with the same seriousness as biosecurity, food safety, and weather risk, none of which farmers would dream of ignoring.
Policy momentum is beginning to build. The Farm and Food Cybersecurity Act of 2025 and the Cybersecurity in Agriculture Act of 2025, both introduced in the 119th Congress, signal federal recognition of the problem, and the National Institute of Standards and Technology’s Cybersecurity Framework 2.0 provides a general template that the sector has yet to systematically adopt. But the authors contend that legislation and voluntary frameworks alone will not close the gap. What is needed, they argue, is institutional infrastructure: a permanent, nationally coordinated Agricultural Cybersecurity Consortium led by regional land-grant universities, the institutions created by the Morrill Act of 1862 with a mandate for agricultural research, education, and extension, and with deep expertise in artificial intelligence and cybersecurity. Land-grant universities, the paper notes, are uniquely positioned because they already maintain trust relationships with farmers, extension networks in every state, and the technical faculty needed to build defenses.
The consortium roadmap is concrete. First, it calls for redoubled research, education, and workforce development in agriculture cybersecurity, including curricula designed specifically for the food and agriculture sector, building on emerging efforts such as university cybersecurity initiatives aimed at protecting farmers and rural businesses. Second, it proposes the creation of agrifood security testbeds: experimental platforms where researchers can safely replicate farm networks, connected agricultural vehicles, and food-processing control systems, and then attack them. Testbeds of this kind, including prototypes for agricultural vehicles and environments described in recent preprints, allow defensive tools to be evaluated against realistic threats before deployment, in the same way that aviation and power-grid security research relies on simulated environments. Honeypots and deliberately vulnerable systems can be embedded in these testbeds to study attacker behavior directly.
Third, the roadmap emphasizes artificial-intelligence-driven threat mitigation. Machine-learning approaches to intrusion detection for Agriculture 4.0, including deep learning models trained to recognize distributed denial-of-service attacks, have shown promise in the research literature, and the authors argue these tools should be operationalized for anomaly detection across farm and food networks, automated intrusion response, and secure assembly of agricultural equipment and software components. Formal methods from program analysis, such as graph-reachability techniques, and fault-tolerant distributed transaction systems, including blockchain-based architectures with established security reference models, could harden the data pipelines that carry everything from sensor readings to supply chain provenance records. Distributed ledger technology has already demonstrated its value in food supply chain transparency at scale, as in the well-documented Walmart case study using Hyperledger Fabric, and the authors see ontologies and semantic models, including conceptual modeling work aimed at agrifood cybersecurity ontologies, as a way to make threat intelligence machine-readable and shareable across the sector.
The fourth pillar is perhaps the most operationally significant: establishing an Agriculture Security Operations Center, a sector-wide monitoring and response capability analogous to the operations centers that protect power grids and financial networks. Such a center would aggregate threat intelligence, coordinate incident response across states and commodities, and provide the continuous situational awareness that individual farms and small food businesses cannot maintain on their own. The economics literature on information security investment, notably the classic Gordon-Loeb model, suggests that organizations systematically underinvest in security relative to expected losses, a pattern the agrifood sector exemplifies. A shared operations center spreads the cost of sophisticated monitoring across the sector, making defense economically rational for even the smallest producers. Finally, the roadmap stresses collaboration with non-university stakeholders, including equipment manufacturers, food companies, insurers, and government agencies, so that defenses reflect the actual structure of the food system rather than an academic abstraction.
The authors are careful to frame the problem as one of resiliency as much as prevention. In cyber-physical systems, perfect security is unattainable; the realistic goal is the ability to detect intrusions quickly, degrade gracefully, and recover operations without lasting harm. Resilience frameworks for cyber-physical systems, developed in the security engineering literature, provide the technical vocabulary, and the agrifood sector needs its own tailored version. There are also subtler threats to contend with: insider threats and opportunistic attacks that exploit trust relationships, and the spread of misinformation through social and online media, which systematic reviews identify as a distinct agri-food risk that can destabilize markets and consumer confidence without touching a single sensor. Generative AI adds a new dimension, with researchers warning about GPT-based malware and AI-accelerated phishing that could target rural operators with unprecedented sophistication.
What makes this Perspective resonate beyond the technical community is the stakes. Food is the one infrastructure sector where failure is felt three times a day by every person in the country. The authors’ warning is not that hackers will poison the food supply through a keyboard, but that a well-timed attack on logistics, processing, or farm equipment during a harvest window or a drought year could inflict economic and social damage on a scale the sector has never planned for. Their prescription, a consortium anchored in land-grant universities, testbeds that treat farm networks as attackable systems, AI-powered detection, a national security operations center, and a workforce trained to defend the digital farm, amounts to a proposal to give agriculture the cyber defenses that every other critical sector already takes for granted. Whether policymakers act before a landmark incident, rather than after, may determine how the story is told.
Subject of Research: Cybersecurity and resiliency of digitalized agricultural and food systems
Article Title: Cybersecurity and resiliency in agricultural and food systems
Article References: Batarseh, F. A., Govindarasu, M., Hasan, M., Hull, R., Jacobson, D., Khot, L. R., Levitt, K., Reecy, J., Sadoghi, M., Bishop, M., Goins, G., Gebremedhin, A., Kalyanaraman, A., Mallapragada, S., Sarrafzadeh, A., Xia, K., & Lange, M. C. (2026). Cybersecurity and resiliency in agricultural and food systems. Nature Food. https://doi.org/10.1038/s43016-026-01422-0
Image Credits: AI Generated
DOI: 10.1038/s43016-026-01422-0
Keywords: agriculture, cybersecurity, food systems, critical infrastructure, precision agriculture, ransomware, artificial intelligence, intrusion detection, land-grant universities, testbeds, supply chain, food security
Cite Scienmag News
Alan Morgan. (October 1, 2026). Hackers Are Coming for the Food Supply, and Scientists Have a Plan to Stop Them. Scienmag. https://scienmag.com/hackers-are-coming-for-the-food-supply-and-scientists-have-a-plan-to-stop-them/
Alan Morgan. "Hackers Are Coming for the Food Supply, and Scientists Have a Plan to Stop Them." Scienmag, 1 October 2026, https://scienmag.com/hackers-are-coming-for-the-food-supply-and-scientists-have-a-plan-to-stop-them/. Accessed 1 October 2026.
Alan Morgan. "Hackers Are Coming for the Food Supply, and Scientists Have a Plan to Stop Them." Scienmag. October 1, 2026. https://scienmag.com/hackers-are-coming-for-the-food-supply-and-scientists-have-a-plan-to-stop-them/

