
Agriculture has become agritech. Over the past few years, technology has eased into everything from yield monitors to climate monitoring to soil sensors and irrigation. Precision agriculture practices, for example, were found to have adoption rates as high as 43% according to a Stellenbosch University Agronomy Department study, while soil sensors are currently, says Ken Research, the IoT category with the highest adoption among South African farmers. The latter market is currently valued at $1,1 billion in the country, with 60% of farms integrating IoT solutions across key areas such as crop and resource management.
These technologies are bringing improvements across yield, performance and optimisation, but they are also introducing unexpected risk. The biggest risk does not sit where you would expect – on the farms and within their systems. It sits with the third-party service provider. In logistics and in small- to medium-sized enterprises (SMEs) that provide the connections between the farm and the fork.
Of course, the farm's technology infrastructure is not immune to the threats. Research from ESET has found that a significant number of South African agritech operators and farmers continue to believe their companies are not attractive targets for cybercriminals. Unfortunately, that belief is precisely what makes them one. That belief is also playing out in the most vulnerable part of the supply chain, where smaller companies have no cybersecurity infrastructure, monitoring devices, or patch management, and no understanding of the risk at all.
Across the commercial farming and food logistics sectors, devices are transmitting data about soil conditions, temperature, humidity, livestock health, cold chain integrity and more. From verified temperature readings through to GPS-tracked logistics and point-of-origin records, the data travels from sensors and systems through the logistics operator, into a distribution centre and eventually informs the procurement and shelf-life decisions of a major retailer. This data is currency. It is precisely what the threat actors want, especially if the data provides insights into the operations of a large agritech company. They can sell how and where the entire farm operates.
From supply chain to security chain
At each step of the chain, there is security. Farms, retailers and distribution centres have invested in enterprise-grade security, endpoint systems or sophisticated solutions that ensure data is protected as it moves through the chain. However, small-scale operators without cybersecurity infrastructure have created an analogue gap that makes them prime targets for a man-in-the-middle attack.
The moment the data leaves the sophistication of the farm and enters the small logistics operator’s hands, it crosses an analogue boundary. The threat actor does not need to breach the farm systems or spend hours hacking the distributor; they need only inject false data in the middle, where security is often not even a consideration.
The mechanism of this type of attack is not high-level; all it needs is access to a vulnerable IoT device without endpoint security, and then the door is wide open. The attackers then inject errors into the data that the device reports. The sensor continues to function as if nothing is wrong; the distribution centre and retailer continue to receive data, but it is false. The temperature reading could suggest the products are in the safe range when they are not, for example, which means the point-of-origin record will validate a consignment it should reject, or that a shelf-life indicator will provide insights that are entirely off base because the data foundation was compromised.
The consequences of this type of attack are twofold. First, there are the commercial impacts, including production delays, spoiled inventory, customer dissatisfaction, and the costly process of tracing and replacing compromised stock. The second is regulatory; under POPIA, companies are legally required to ensure the accuracy of the data they process. When false data is injected at the analogue gap, it travels through the supply chain, informs procurement decisions, and leaves the retailer holding non-compliant records they relied on in good faith.
Financial consequences
The Transnet ransomware attack in 2021 is a clear demonstration of what happens when a logistics-adjacent system is compromised. Agricultural imports and exports came to a standstill, with significant financial consequences.
Threat actors do not need to target the high-end systems implemented by the agricultural sector, retailers, and distribution centres. They simply need to find a vulnerability in the analogue gap and poison the data when nobody is watching.
Third-party logistics companies are facing significant complexities in digital transformation, including compliance, employee resistance, outdated systems, and more. This fragmentation, alongside infrastructure and financing limitations, is putting immense pressure on the sector’s security. South Africa’s agricultural and retail sectors operate in a country where the Information Regulator received 3219 breach notifications in the 2025/26 financial year, averaging 268 per month. The analogue gap has become a cybersecurity problem that needs to be addressed.
For more information contact ESET-SA,
© Technews Publishing (Pty) Ltd. | All Rights Reserved.