Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.

Industrial OT AI

Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year.

Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack.

The UK’s Cyber Monitoring Centre estimated a £1.9 billion financial impact and described the incident as the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak. It is a vivid example of the potential consequence of ransomware incidents within the manufacturing sector.

The Black Kite 2026 Manufacturing & Distribution Ransomware Report believes this long tail of severe consequence is a primary reason for manufacturing continuing to be a primary ransomware target. 

Manufacturing

“The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products. When the mid-market is the primary target, a large manufacturer’s vendor list is its attack surface,” says the report. From January 2023 to July 2026, the firm identified 5,237 disclosed ransomware victims across the two associated groups. 

“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” adds Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses.”

Advertisement. Scroll to continue reading.

The first seven months of 2026 recorded 1,183 new incidents – a 40% increase over the same period in 2025. The number of ransomware groups is also climbing: half of these attacks were performed by groups that didn’t exist two years ago. A single new group (The Gentlemen) was responsible for 12% of this year’s attacks.

The Gentlemen was first noticed by Black Kite in September 2025 and had claimed 142 manufacturing victims by mid-2026. The current hierarchy of ransomware actors is Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom.

Europe is increasingly targeted. While the number of US attacks this year was almost identical to that of 2025; there was an 85% growth in European targets. As a result, the volume of attacks in the US dropped from the previous 52% to a current 35%. Despite the shift in percentages, the US remains the most targeted region with 412 attacks. Europe totaled 369 attacks, and attacks against the rest of the world almost doubled to 402.

The surge in European attacks focused on Germany (77 attacks), where manufacturing in 2024 accounted for 20% of the national economy. The SafePay group accounted for 22% of 2025 attacks and remains among the country’s most active groups in 2026. Other primary European ransomware victim nations include Italy (57), UK (43) and France (40).

Distribution

The distribution sector is distinct from the manufacturing sector. “Trucking companies, freight arrangers, and warehouse operators form their own industry with their own attack surface, and they occupy a distinct position in the supply chain. They are the layer where many companies’ goods concentrate in one place, which is precisely what makes the sector consequential beyond its size.”

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

The attacks against distribution are lower in volume while the victims are smaller in size than in the manufacturing sector. The volume peaked in 2025 following a Clop campaign in January and February of that year, accounting for 52 victims and more than 25% of the year’s total. This distorts the underlying growth in attacks: 95 in the first half of 2026 against 196 for 2025. But without the Clop campaign, the underlying growth pattern continues, from 75 to 95 incidents during the same period in 2025 and 2026. 

The attraction of these two sectors is that they both provide supply chain potential to the attackers, thus magnifying the impact and potential negotiating power. Downstream, the Jaguar Land Rover incident affected 5,000 other organizations. Upstream, the Clop attack against Cleo ultimately produced nearly 400 disclosed victims. But supply chain victims are innocent – they do not own and cannot patch the vulnerabilities that lead to their victimization. Lawmakers are recognizing this and attempting to break the chain.

The UK’s Cyber Security and Resilience Bill (CSRB) provides an example. It seeks to protect the critical infrastructure from supply chain effects by allowing ministers to block downstream supply from providers it considers high risk. This forces the supply chain to improve its security or lose its customer.

The underlying problem remains and is forcefully illustrated by Black Kite’s report: ransomware attacks are consistently increasing in volume, and the number of attackers continues to grow. At the same time, the evermore complex interconnectivity of expanding economies grows the attack surface and increases the risk. If Black Kite’s figures are correct, there is little indication that anything will change in the foreseeable future.

ICS Cybersecurity Conference

Related: Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping

Related: Masimo Manufacturing Facilities Hit by Cyberattack

Related: Cyberattack Disrupts Microchip Technology Manufacturing Facilities

Related: Simpson Manufacturing Takes Systems Offline Following Cyberattack

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.