NSA, CISA, and FBI say that ransomware group BlackMatter is attacking critical US infrastructure, including the food sector, demanding $80K-$15M in crypto
A government advisory published Monday warned that BlackMatter ransomware attackers are going after U.S. critical infrastructure … Source: CISA .
Context & Ripple Effects
BlackMatter had presented itself as a selective operation targeting companies with $100M+ in revenue and avoiding certain sectors in an earlier public account of its targeting criteria. The new government warning places its activity against U.S. critical infrastructure, undercutting the practical value of attackers’ stated sector boundaries.
The alert follows a separate joint warning on ransomware incidents at water treatment plants, showing NSA, CISA, and the FBI treating ransomware as an operational risk across essential services rather than solely an enterprise-data problem.
First-order effects
- Food-sector and other critical-infrastructure operators are now identified by NSA, CISA, and the FBI as potential BlackMatter targets facing crypto demands ranging from $80K to $15M.
- BlackMatter’s stated preference for large-revenue victims is now paired with a public, multi-agency warning that puts its targeting of essential services under heightened scrutiny.
Second-order effects
- CISA, the FBI, and NSA are reinforcing a shared advisory model across sectors after their water-system warning, giving critical-infrastructure operators a common threat signal rather than treating incidents as isolated breaches.
- Organizations that relied on ransomware groups’ claimed exclusions from sensitive sectors have less basis to treat those statements as a meaningful risk control.
Third-order effects
- Repeated federal advisories across food and water point toward ransomware response becoming a standing critical-infrastructure coordination function, with government threat reporting linking sectors that attackers may target separately.
- If this pattern persists, the distinction between enterprise ransomware and attacks on essential services will narrow, increasing the importance of cross-sector defensive guidance from agencies such as CISA and the FBI.
The trend: Ransomware is being framed increasingly as a cross-sector critical-infrastructure threat, prompting coordinated federal warnings rather than sector-by-sector incident response.