Sandhills Global Cyber Security After Conti: 2026 Update

- Sandhills Global and Conti in 2026: the short answer
- Timeline: from the outage to the Conti bounty
- What changed since 2021
- Risks for customers of online marketplaces after an attack
- Steps for buyers and sellers on equipment marketplaces
- What is still unknown
- Our original 2021 report
- Sites are still down while it is not determined if client data got accessed
- Conti ransomware not going to be stopped
- Related guides on 2-Spyware
Sandhills Global and Conti in 2026: the short answer
Sandhills Global survived the 2021 ransomware attack that reports tied to the Conti gang.[1][2] Its company website is online in 2026 and describes a business that connects buyers and sellers of equipment in agriculture, construction, transportation and aviation.[10] The outage our original report describes was temporary.
Two questions stay open. We found no public breach notice that confirms stolen customer data, and we found no published Sandhills Global cyber security or cloud security strategy as of 2026. The Conti group itself became a target of a US reward of up to $10 million in May 2022.[8]
| Question | Answer |
|---|---|
| Who was hit | Sandhills Global, Lincoln, Nebraska[2][10] |
| When | 2021, per our original report and local news[2] |
| Blamed group | Conti ransomware, according to reports[1] |
| Affected services | Hosted sites such as TractorHouse, Truck Paper and AuctionTime, plus phones |
| Customer data stolen? | Not confirmed in any source we found[2] |
| Status in 2026 | Company and website operating[10] |
Timeline: from the outage to the Conti bounty

| Date | Event |
|---|---|
| 2021 | Ransomware attack takes Sandhills Global sites and phones offline[1][2] |
| 2021 | Sandhills Global says it found no evidence that customer data was compromised[2] |
| January 2022 | FBI estimates over 1,000 Conti victims and payouts above $150 million[8] |
| April 2022 | Conti attacks the government of Costa Rica, hitting customs and tax systems[8] |
| May 6, 2022 | US State Department offers rewards of up to $10 million and $5 million[8][9] |
| 2026 | Sandhills Global website online with current market reports[10] |
What changed since 2021
The company came back. In 2026 the Sandhills Global website lists its brands, careers and fresh market reports, such as rising inventory of pre-owned jets and turboprops.[10] We found no public post-incident report, so we cannot say how long the full recovery took or what the company changed in its systems.
The attacker group changed more. The US State Department says Conti was responsible for hundreds of incidents in two years. The FBI estimated over 1,000 victims and payouts above $150 million as of January 2022, which the State Department called the most damaging ransomware strain ever documented.[8] In April 2022 the group attacked the government of Costa Rica.[8]
On May 6, 2022, the US offered up to $10 million for information that identifies or locates Conti leaders, and up to $5 million for information leading to arrests of anyone who took part in a Conti incident.[8][9] The offer page still carries those amounts.
Risks for customers of online marketplaces after an attack
This list is our analysis of common follow-up scams after a marketplace or auction platform suffers a breach. It is not based on a specific Sandhills Global incident.
- Fake outage emails. Criminals send messages that look like status updates and ask you to log in through a link.
- Payment change requests. A seller or a fake platform notice asks you to wire money to a new bank account.
- Fake listings. Cheap tractors, trucks or aircraft posted to collect deposits, often moved to email or chat off the platform.
- Credential reuse. If a password leaks from one site, attackers try it on your email and bank.
- Ransomware leak threats. Gangs sometimes contact customers directly and claim to hold their data.
Steps for buyers and sellers on equipment marketplaces

1. Use the official site. Type the marketplace address yourself. Do not log in through links in outage or security emails.
2. Change passwords. If you reused your marketplace password elsewhere, change it on every site and make each one unique.
3. Turn on two-factor sign-in. Where the platform or your email offers a second sign-in step, enable it.
4. Confirm payments. Before any wire transfer, call the seller or dealer on a number you found yourself, not one from the message.
5. Check for leaks. Use our leak check to see if your email appears in known breaches, and review our list of recent data breaches.
6. Report scams. Report fake listings to the platform and phishing emails through our phishing guide.
What is still unknown
- Whether any Sandhills Global customer data was taken. We found no breach notice that confirms it.
- Whether Sandhills Global paid a ransom. The company did not say so in the notice we quoted.[2]
- What security changes the company made after the attack. We found no published security or cloud strategy as of 2026.
- Whether any Conti member linked to this attack was identified. We found no such report.
Our original 2021 report
The text below is our report as first published in 2021. We keep it unchanged for the record; the sections above bring it up to date.
Conti ransomware is, allegedly, to blame for the attack on the company controlling online farm equipment and land auction service sites.[1] Sandhills Global admitted that hosted websites became inaccessible and operations got disrupted due to the ransomware attack.[2] The company is a US-based business catering to the transportation, agriculture, aircraft, heavy machinery, technology industries. For a few days, the website for Sandhills Global and other hosted publications got forced to go offline. Phones also stopped working. At the time of writing, the main site is still not accessible.
Publications related to the company like Truck paper, TractorHous, AuctionTime, HiBid, RentalYard, Motorsports Universe, CraneTrader, MarketBook, RV Universe, Oil Field Trader, Aircraft, and many more are no longer accessible. Multiple sources state that Conti ransomware[3] is the one responsible for the attack and the outage.
Ransomware took over the system early Thursday morning and caused the shut down of all IT systems. The allegedly responsible Conti virus is one of the many dangerous threats focused on a wide range of attacks on high-profile companies in various industries. This ransomware made headlines due to the attack on JVCKenwood this week too.[4]
Sites are still down while it is not determined if client data got accessed
The company hasn't revealed any details about the attack. There are no reports on whether the data got accessed or not and how the ransomware tried to get money from the company. Normally such threats encrypt networks or the system of the computer and lock data using the powerful algorithm. Then the threat actor can reveal stages of file recovery, including the payment methods, amount. The sum gets demanded in exchange to the decryption tool.
While the company works on investigations and relies on cyber security experts who can prevent IT system damage and the spreading of the attack, customers got the only email from the company:
Sandhills Global is currently responding to a ransomware attack that impacted our operations. Systems and operations have been temporarily shut down to protect data and information, and we have retained cybersecurity experts to assist us with the investigation, which is ongoing. We are working actively and diligently with the assistance of our retained experts to fully restore operations.
At this time, we are continuing to investigate whether any of our client's information has been accessed or impacted by this incident. At this time, we have not discovered evidence that confirms that customer information has been compromised. Please know that our clients are our number one priority and we are working diligently to restore operations and remediate the attack. At this time, our ability to respond to your messages may be delayed. We appreciate your patience and deeply regret any inconvenience this may cause.
We will provide updates regarding this matter and the status of our services as soon as possible.
Conti ransomware not going to be stopped
Threat actors behind the well-known Conti ransomware are gaining attention in various media because of the attack campaigns. Recently JVCKenwood suffered the attack and criminals claim to have stolen at least 1.7 TB of data from the network and asked for $7 million from the multinational electronics company. Officials disclosed that servers related to sales in Europe got breached on September 22 and various sensitive data got accessed. Such infection can end with full outages and data breaches.[5]
Conti ransomware gang already caused major issues and damaged businesses all over the world. The particular ransomware creators typically target the healthcare sector, emergency medical services.[6] However, such malware can be created to aim at any profitable target. CISA, FBI, other agencies released major reports warning about the tactics and malicious actors behind the threat.
The infection even managed to get to backups and cloud storage.[7] These options often are the only ones available for the victim of the file-locker because decryption tools take too long to get developed from scratch. Backups can be a great obstacle for ransomware because businesses manage to resume their operations using data backups instead of paying the large sums that criminals might ask for. It is not surprising that backup solutions become a common target, methods include backup damage. However, it is very dangerous and concerning that cryptocurrency-extortion-based infections become more and more advanced.
Related guides on 2-Spyware
Frequently asked questions
What happened in the Sandhills Global cyber attack?
Sandhills Global was hit by ransomware in 2021, and reports blamed the Conti gang.{1}{2} The company shut down systems to protect data, so sites such as TractorHouse, Truck Paper, AuctionTime and MarketBook went offline for days. Phones stopped working too. The company said it had hired cybersecurity experts to investigate.
Is Sandhills Global still operating in 2026?
Yes. The Sandhills Global website is online in 2026 and describes the company as an information processing business in Lincoln, Nebraska, that connects buyers and sellers in agriculture, construction, transportation and aviation.{10} It also publishes current market reports for equipment and aircraft.
What is the Sandhills Global cyber security strategy?
We found no public document that describes the Sandhills Global cyber security or cloud security strategy as of 2026. During the 2021 incident, the company said it shut systems down to protect data and hired outside experts.{2} Anything beyond that would be a guess, so treat third-party claims with care.
Was customer data stolen in the Sandhills Global attack?
We found no public confirmation that customer data was stolen. In its 2021 notice, the company said it had not found evidence that customer information was compromised and that the investigation was ongoing.{2} We found no later breach notice from the company in the sources we checked.
What happened to the Conti ransomware gang?
The US government still seeks its leaders and members. In May 2022 the State Department offered up to $10 million for information on Conti leaders and up to $5 million for information leading to arrests.{8}{9} The FBI linked over 1,000 victims and more than $150 million in payouts to Conti as of January 2022.{8}
Does Sandhills Global offer a data API or feed?
We found no public developer page for a Sandhills Global or MachineryTrader data API in the pages we checked. If you need listing data, contact Sandhills Global directly through its official site rather than third-party scrapers that may break the terms of service.
Sources
- AGweb. News and opinion
- 3newsnow. Investigations and local news
- 2-spyware. Virus removal guides and news
- Computerweekly. Computer and cybersecurity news
- Foxbusiness. Finance, economy, markets and lifestyle reports
- HealthcareITnews. Security and privacy news from healthcare industries
- Threatpost. Malware and security reports
- US Department of State
- Reuters
- Sandhills Global
Log in to comment
No comments yet. Be the first.