Passwords are like a good fence on the farm: they protect what is important.
In December 2023, a California dairy producer reported that two Central Valley dairies using robotic milking systems had been hacked. According to the California Dairy Quality Assurance Program, the intruders deliberately disrupted physical farm operations. Robotic milkers were shut down, bulk-tank agitation and cooling stopped, cleaning chemicals were discharged into the waste system, and fans and misters were activated out of season.
An investigation suggested that an outside threat actor conducted the attacks. One possible explanation was that a system password had never been changed from the vendor’s default example, although the exact point of entry was not definitively established.
The incident illustrates that farm cybersecurity is not limited to protecting financial records and email. When connected equipment controls milking, ventilation, cooling, irrigation or feeding, unauthorized access can affect animals, products and day-to-day operations.
Farmers should ask equipment vendors who can remotely access a system, change every default password during installation, and use a different password for each important account. Multifactor authentication should be enabled whenever it is available. Farm business computers should also be separated from networks controlling machinery so that a compromised email account or office computer cannot provide an easy route into operational equipment.
Learn how stronger, unique passwords can help protect your farm through the CyberPest Management resource, Use Long/Unique Passwords
Citation: California Dairy Quality Assurance Program. “CDQAP Cyber-Crime Update: Robotic Milking Systems Hacked.” February 22, 2024.