Clop and BlackNevas Strike Again: Two Greenhouse Technology Companies Appear in a Fresh Ransomware Wave + Video

Listen to this Post

Featured Image

A New Day, Two New Targets

The ransomware landscape rarely stays still. On August 12, 2026, two companies connected to the agricultural technology and greenhouse industry appeared in fresh dark web ransomware intelligence: Intelligent Growth Solutions was listed in connection with the Clop operation, while Westbrook Greenhouse Systems was associated with the BlackNevas ransomware group.

The incidents were reported by the ThreatMon Threat Intelligence Team, which tracks ransomware activity, victim listings, indicators of compromise, and command-and-control infrastructure. The information places two businesses operating in an increasingly technology-dependent agricultural sector under cybersecurity scrutiny.

The significance goes beyond two company names appearing in a threat-intelligence feed. Modern agriculture is becoming deeply connected to software, automation, remote monitoring, industrial controls, cloud platforms, sensors, engineering systems, and digital supply chains. That means companies building the infrastructure behind food production can become attractive targets for cybercriminals.

Clop Targets Intelligent Growth Solutions

According to the supplied ThreatMon report, the Clop ransomware group added Intelligent Growth Solutions, or IGS, to its victim list on August 12, 2026.

The reported entry identified the target as intelligentgrowthsolutions.com and was timestamped at 18:39:02 UTC+3.

IGS is not a conventional agricultural company. The Scotland-based business develops industrial-scale vertical farming technology and controlled-environment agriculture systems. Its technology combines engineering, plant science, automation, software, lighting, irrigation, energy management, and environmental controls.

That technological profile makes the incident particularly interesting from a cybersecurity perspective.

Why Intelligent Growth Solutions Matters

IGS says it was founded in 2013 and has been working with growers since 2017. Its systems are designed to help operators maintain controlled growing environments while reducing the impact of problems such as extreme weather, labor shortages, pests, and disease.

The company describes its technology as modular, scalable, flexible, and efficient. Its systems can control factors including lighting, temperature, humidity, and nutrient delivery, while its proprietary software can remotely control aspects of vertical-farming operations.

That remote-control capability is precisely what makes cybersecurity so important.

A modern vertical farm is not simply a building containing plants. It can function as a complex cyber-physical environment in which digital systems influence physical processes. A compromised account, server, application, or management platform could potentially create consequences that extend beyond ordinary office IT.

The BlackNevas Connection

The second incident involves BlackNevas, another ransomware operation that appeared in the same ThreatMon intelligence stream.

The supplied report states that BlackNevas added Westbrook Greenhouse Systems to its victim listings at 19:23:20 UTC+3 on August 12, 2026.

The report also references an IT company associated with the victim, although the supplied source truncates that portion of the information.

Westbrook’s official website confirms that the company operates in commercial greenhouse systems, providing greenhouse structures, heating systems, benches, material-handling solutions, climate systems, and related components.

A Company Built Around Critical Infrastructure

Westbrook is not a small software vendor whose operations exist entirely online.

Its products and services support physical growing environments. The company states that it has more than 50 years of experience in the greenhouse industry and provides customized systems covering structures, heating, cooling, ventilation, material handling, and other greenhouse requirements.

Its heating division includes boilers, pumps, heat exchangers, thermal-energy storage, distribution systems, sensors, valves, and other components.

That creates an important cybersecurity lesson: companies supporting physical infrastructure do not need to be traditional critical-infrastructure operators to become operationally important targets.

Two Victims, One Larger Pattern

At first glance, the Clop and BlackNevas incidents might appear unrelated.

One company specializes in vertical farming technology. The other specializes in commercial greenhouse systems.

But the underlying pattern is remarkably similar.

Both organizations operate at the intersection of agriculture and technology. Both depend on digital systems to support physical processes. Both potentially interact with customers, suppliers, engineering teams, contractors, service providers, and remote infrastructure.

This convergence creates a much larger attack surface than many organizations realize.

The Agricultural Technology Attack Surface

The agricultural sector has undergone a quiet digital transformation.

Sensors collect environmental information. Cameras monitor facilities. Controllers regulate temperature and humidity. Software manages production schedules. Cloud platforms store operational information. Remote-access tools allow engineers and technicians to troubleshoot equipment. Vendors maintain systems from outside the physical facility.

Every additional connection can introduce another potential pathway for attackers.

The result is a new generation of cyber-physical risk.

Why Remote Access Deserves Special Attention

Remote access is particularly important in environments like vertical farms and greenhouses.

IGS explicitly describes its technology as remotely controlled through a proprietary software suite.

That does not mean the ransomware incident affected those systems. There is currently no evidence in the supplied material establishing that operational technology was compromised.

However, remote administration should always be treated as a high-value security boundary.

If an attacker obtains privileged credentials, steals session tokens, compromises a remote-management server, or abuses a vulnerable VPN, the consequences can extend far beyond the employee workstation where the intrusion began.

Ransomware Is No Longer Just About Encryption

Modern ransomware operations increasingly treat data as an asset for extortion.

Attackers can steal sensitive documents before encrypting systems, threaten publication, disrupt operations, and use stolen information to increase pressure on victims.

For engineering and agricultural technology companies, potentially valuable information could include technical drawings, software documentation, customer information, contracts, equipment configurations, internal research, employee records, credentials, and proprietary designs.

Again, the available information does not establish which, if any, of these categories were accessed in these incidents.

That distinction matters.

A victim listing tells defenders that an organization is being associated with a ransomware operation. It does not automatically prove the complete scope of compromise.

What the IGS Incident Could Mean

IGS operates internationally and says it has customers across Europe, the Middle East, and North America.

Its systems are designed for large-scale controlled-environment agriculture, while the company also works in areas including nurseries, seed-to-harvest production, pharmaceuticals, forestry, and energy-related applications.

This broad ecosystem increases the potential importance of corporate data and third-party relationships.

If an attacker successfully compromised internal systems, investigators would need to determine whether the incident remained confined to corporate IT or crossed into customer-support systems, engineering environments, development infrastructure, or remotely managed assets.

There is currently no verified public evidence in the supplied material showing such a crossover.

What the Westbrook Incident Could Mean

Westbrook’s business model creates a different but equally interesting risk profile.

The company designs, manufactures, installs, and supports systems used by commercial growers. Its website highlights engineering, manufacturing, heating, climate control, and specialized greenhouse infrastructure.

A ransomware intrusion could therefore potentially create disruption across multiple business functions, including engineering, sales, customer support, procurement, manufacturing, and field service.

Whether any of those areas were actually affected has not been established by the information provided.

The Third-Party Risk Problem

The supplied BlackNevas entry is especially notable because it references an IT company servicing Westbrook.

That detail highlights one of the most persistent ransomware problems: third-party access.

Managed service providers can possess elevated privileges because they need to administer endpoints, servers, networks, cloud accounts, backups, and security tools.

An attacker who compromises an MSP account may therefore gain an indirect route into multiple organizations.

This is why organizations must treat suppliers and IT service providers as part of their security perimeter rather than as completely external entities.

Why Threat Intelligence Matters

Threat intelligence provides an early-warning mechanism.

A company may not yet know that its name has appeared in a ransomware ecosystem, while researchers monitoring underground activity can identify the listing first.

That information can trigger incident-response procedures.

Security teams should immediately investigate authentication logs, privileged accounts, remote-access activity, endpoint telemetry, unusual data transfers, suspicious persistence mechanisms, and backup infrastructure.

Threat intelligence becomes most valuable when it changes defensive behavior quickly.

The First 24 Hours Matter

If an organization discovers that it has been listed by a ransomware group, the first response should be disciplined rather than chaotic.

Security teams should preserve evidence.

They should identify potentially compromised credentials.

They should isolate suspicious systems where appropriate.

They should review authentication events.

They should protect backups.

They should determine whether attackers remain inside the environment.

And they should establish a clear timeline.

Deleting suspicious files or immediately rebuilding systems without preserving evidence can destroy information investigators need to understand the intrusion.

What Organizations Should Check

Companies in technology-heavy agricultural environments should review several security boundaries immediately.

Identity providers should be examined for abnormal login activity.

Privileged accounts should be audited.

VPN and remote-management infrastructure should receive special attention.

Cloud administrative activity should be reviewed.

Endpoint detection alerts should be correlated with authentication logs.

Backup systems should be checked for unauthorized access or deletion attempts.

Third-party accounts should be reviewed.

Finally, organizations should search for signs of data staging or unusual outbound transfers.

A Simple Linux Investigation Workflow

Deep Analysis

For Linux servers, defenders can begin with basic authentication and process investigations.

sudo journalctl --since "24 hours ago" | grep -Ei "ssh|sudo|authentication|failed|accepted"

Review recent successful and failed SSH activity:

sudo grep -Ei "Accepted|Failed|Invalid user" /var/log/auth.log

Inspect recently created or modified files:

sudo find /var/www /opt /srv -type f -mtime -2 -ls 2>/dev/null

Review active network connections:

sudo ss -tulpn

Look for unexpected processes:

ps aux --sort=-%cpu | head -30

Inspect scheduled tasks:

sudo crontab -l
sudo ls -la /etc/cron.

Search for suspicious persistence locations:

sudo find /etc/systemd /usr/lib/systemd -type f -mtime -7 -ls 2>/dev/null

Review recent user-account changes:

sudo awk -F: '$3 >= 1000 {print $1,$3,$6,$7}' /etc/passwd

These commands are investigative starting points, not proof of compromise. They should be combined with endpoint telemetry, centralized logging, network monitoring, forensic analysis, and organization-specific indicators.

Why Agriculture Is Becoming a Cybersecurity Target

Agriculture is increasingly dependent on technology.

The old image of farming as a mostly physical industry is becoming outdated.

Modern production can depend on automation, sensors, robotics, cloud platforms, remote monitoring, predictive analytics, specialized software, and interconnected equipment.

The more valuable the technology becomes, the more attractive it can become to financially motivated attackers.

The Clop and BlackNevas incidents illustrate how this risk can reach companies that may not immediately be associated with cybersecurity.

The Bigger Clop Lesson

Clop has repeatedly demonstrated an interest in high-value enterprise environments and data-driven extortion.

For defenders, the lesson is not simply to search for one ransomware executable.

Organizations must defend identity, applications, remote access, cloud infrastructure, third-party relationships, backups, and sensitive data simultaneously.

Ransomware defense has become an enterprise-wide discipline.

The Bigger BlackNevas Lesson

The BlackNevas listing demonstrates another important reality: ransomware ecosystems continue to diversify.

Attackers do not need to target only hospitals, banks, governments, or giant technology corporations.

A specialized engineering or greenhouse company can also become valuable because it possesses data, operational relationships, customer information, intellectual property, or access to wider networks.

That makes sector-specific cybersecurity planning increasingly important.

What Undercode Say:

1. Agriculture Has Become Digital Infrastructure

The most important lesson from these incidents is that agriculture and cybersecurity are now inseparable.

2. Physical Operations Depend on Digital Trust

A greenhouse or vertical farm can depend on software just as heavily as a conventional technology company.

  1. Remote Access Is a Major Security Boundary

Every remote-management pathway should be treated as privileged infrastructure.

4. Identity Often Matters More Than Malware

An attacker with legitimate credentials can sometimes move more quietly than an attacker deploying obvious malware.

5. Third-Party Providers Expand the Attack Surface

Managed service providers can become attractive targets because of their administrative privileges.

6. Specialized Companies Can Hold Valuable Data

Engineering designs, customer contracts, software, and operational documentation can all have significant value.

7. Ransomware Groups Follow Economics

Attackers generally care about leverage, access, and monetization rather than whether an organization is famous.

8. Vertical Farming Creates Cyber-Physical Risk

When software controls environmental conditions, cybersecurity can become connected to physical operations.

  1. A Victim Listing Is an Early Warning

A dark web listing should trigger investigation rather than simply becoming a headline.

10. Attribution Still Requires Evidence

A listing can provide valuable intelligence, but defenders still need forensic evidence to establish the actual intrusion path.

11. Incident Scope Must Be Determined

Organizations should avoid assuming that every system was compromised simply because one victim listing appeared.

12. Backups Need Their Own Security Strategy

Offline or otherwise strongly isolated backups can become critical during ransomware incidents.

13. Backup Credentials Should Be Protected

If attackers compromise backup administration, recovery can become dramatically harder.

14. MFA Is Necessary but Not Sufficient

Strong authentication reduces risk, but organizations must also monitor sessions, privileged activity, endpoints, and identity providers.

15. Privilege Reduction Matters

Service providers and administrators should receive only the access required to perform their duties.

16. Network Segmentation Can Limit Damage

Separating corporate IT from operational technology can reduce the impact of an intrusion.

17. Logging Must Be Centralized

Attackers frequently attempt to remove or manipulate evidence on compromised systems.

18. Centralized Logs Provide Resilience

External logging can preserve evidence even when a local system has been compromised.

19. Security Teams Need Threat Intelligence

Knowing that an organization has appeared in a ransomware ecosystem can accelerate response.

20. Threat Intelligence Needs Context

A raw victim listing becomes far more useful when correlated with authentication, endpoint, network, and cloud telemetry.

21. Customer Networks Deserve Attention

Technology providers should understand whether their systems can access customer environments.

  1. Vendor Access Should Be Temporary Where Possible

Standing administrative access creates unnecessary exposure.

23. Credentials Should Be Rotated After Suspicion

Potentially compromised credentials should be treated as unsafe until investigated.

24. Incident Response Should Be Practiced

Organizations should not design their ransomware response while an active intrusion is unfolding.

25. Tabletop Exercises Expose Weaknesses

Exercises reveal communication, backup, legal, and technical gaps before criminals do.

26. Engineering Systems Need Security Controls

Specialized engineering infrastructure should not be treated as exempt from normal cybersecurity requirements.

27. Cloud Accounts Are High-Value Targets

Attackers increasingly seek identity-provider and cloud administration rather than relying solely on traditional malware.

28. Email Remains an Important Entry Point

Phishing can provide the initial credentials needed for deeper compromise.

29. Supply Chains Create Multipliers

A compromise at one provider can potentially expose several connected organizations.

30. Security Must Follow the Data

Organizations should identify where sensitive information lives and who can access it.

31. Intellectual Property Needs Protection

For technology companies, proprietary engineering information may be as valuable as customer data.

32. Operational Technology Requires Special Care

Defenders must balance security controls with availability and safety requirements.

  1. Disruption Can Be as Valuable as Encryption

Attackers can pressure victims through operational interruption even when encryption is not the only objective.

34. Ransomware Is an Enterprise Risk

The security team cannot solve the problem alone.

35. Executives Need Visibility

Leadership should understand the business consequences of losing identity systems, backups, customer data, or operational technology.

  1. Small Specialized Companies Should Not Assume They Are Invisible

Niche expertise can make an organization more valuable than its size suggests.

37. Agricultural Technology Will Become More Attractive

As farming becomes increasingly automated, its digital footprint will continue expanding.

38. Cybersecurity Must Grow With Automation

Every new connected controller, sensor, application, or remote-management feature introduces another security consideration.

39. Early Detection Can Change the Outcome

The difference between discovering an intrusion quickly and discovering it after widespread encryption can be enormous.

40. The Real Lesson Is Resilience

The goal is not simply to prevent every attack. It is to detect intrusions early, contain them, protect critical assets, recover quickly, and learn from every incident.

✅ Confirmed: Intelligent Growth Solutions Is a Real Technology Company

IGS confirms that it was founded in Scotland in 2013 and develops industrial-scale vertical farming and controlled-environment agriculture technology.

✅ Confirmed: Westbrook Greenhouse Systems Is a Real Commercial Greenhouse Business

Westbrook’s official materials confirm its work in greenhouse structures, heating, climate systems, benches, and related commercial growing infrastructure.

❌ Not Independently Established: Full Breach Scope

The supplied ThreatMon information reports the ransomware victim listings, but it does not establish the exact systems compromised, data stolen, encryption status, ransom demand, or operational impact. Those details should not be invented without additional forensic or official disclosures.

Prediction

(+1) Ransomware Targeting Will Continue Moving Toward Technology-Dependent Agriculture

As vertical farms and commercial greenhouses adopt more automation, connected control systems, remote management, and cloud services, financially motivated attackers will have more reasons to examine the sector.

(+1) Third-Party Access Will Remain a Major Weakness

Managed IT providers, contractors, vendors, and remote-support accounts are likely to remain attractive pathways because they can provide privileged access without directly attacking the final victim.

(+1) Threat Intelligence Will Become More Operational

Organizations will increasingly use ransomware listings as triggers for immediate identity, endpoint, network, and backup investigations rather than waiting for an official breach announcement.

(-1) Victim Listings Alone Will Not Reveal the Full Impact

A listing cannot reliably establish whether operational technology, customer environments, or sensitive data were compromised. The true impact will require forensic evidence and, where available, official statements.

The Final Warning

The most unsettling part of these incidents is not simply that two organizations appeared in ransomware intelligence on the same day.

It is what they represent.

Agriculture is becoming software-defined. Greenhouses are becoming automated. Vertical farms are becoming connected. Engineering companies are increasingly dependent on cloud platforms and remote support.

That transformation brings enormous benefits, but it also creates an expanding digital attack surface.

The Clop listing involving Intelligent Growth Solutions and the BlackNevas listing involving Westbrook Greenhouse Systems therefore deserve attention beyond the individual victims. They are reminders that cybersecurity is becoming part of the infrastructure of food production itself.

For organizations operating in this space, the question is no longer whether agriculture uses technology.

It is whether that technology can remain trustworthy when someone is actively trying to break it.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube