Connect with us

Cybersecurity

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Published

on

Ransomware attacks targeting the manufacturing sector increased sharply during the first seven months of 2026, with new incidents rising 40% compared with the same period last year. Security researchers warn that manufacturers and distribution companies remain attractive targets because disrupting their operations can create consequences far beyond the directly compromised organization.

According to Black Kite’s 2026 Manufacturing & Distribution Ransomware Report, attackers are increasingly exploiting the interconnected nature of modern supply chains to increase operational disruption and strengthen their leverage during ransom negotiations.

Manufacturing Emerges as a Major Ransomware Target

Black Kite identified 1,183 ransomware incidents involving the manufacturing sector during the first seven months of 2026, representing a 40% increase year over year.

The research firm identified 5,237 publicly disclosed ransomware victims across manufacturing and distribution between January 2023 and July 2026. It said mid-sized manufacturers are particularly significant because many serve as suppliers to larger enterprises.

This creates a broader attack surface for organizations further up the supply chain. A compromise at one supplier can potentially interrupt production, deliveries and other operations at much larger companies.

Ferhat Dikbiyik, Black Kite’s chief research and intelligence officer, said manufacturing is particularly attractive to ransomware groups because successful attacks can bring production lines to a halt and interfere with delivery commitments.

Attackers can also use publicly visible weaknesses—including unpatched systems, exposed services, leaked credentials and poorly configured security controls—to identify potential targets.

New Ransomware Groups Drive the Increase

The ransomware ecosystem is also becoming more crowded. Black Kite found that approximately half of the manufacturing attacks recorded in the first seven months of 2026 were attributed to groups that had not been identified two years earlier.

The Gentlemen emerged as one of the most prominent new players. First identified by Black Kite in September 2025, the group had claimed 142 manufacturing victims by the middle of 2026 and accounted for 12% of the attacks recorded this year.

The leading ransomware groups targeting the sector were Qilin, The Gentlemen, Akira, DragonForce and INC Ransom.

Europe Sees Significant Growth in Attacks

Although the number of attacks against US manufacturers remained broadly similar to 2025, Europe experienced an 85% increase during the period covered by the report.

The United States accounted for 412 attacks, or 35% of the total, compared with 52% during the previous period. Europe recorded 369 incidents, while the rest of the world reached 402 attacks, nearly twice its previous level.

Germany was the most heavily targeted European country, with 77 reported attacks. Italy followed with 57, the United Kingdom with 43 and France with 40.

Germany’s manufacturing sector is particularly significant to its economy, accounting for around 20% of national economic output in 2024. Black Kite also identified SafePay as one of the country’s most active ransomware groups, noting that the group was responsible for 22% of attacks in Germany during 2025.

Distribution Companies Also Face Supply Chain Exposure

The distribution industry faces a different threat profile from manufacturing but remains an important part of the ransomware supply chain.

Trucking companies, freight coordinators and warehouse operators can become high-value targets because large quantities of goods may pass through their systems and facilities. Disrupting these businesses can therefore affect multiple organizations simultaneously.

Distribution-sector ransomware incidents totaled 95 during the first seven months of 2026, compared with 196 for all of 2025.

The 2025 figure was significantly influenced by a Clop campaign during January and February that affected 52 victims, accounting for more than one-quarter of the year’s reported incidents. Excluding that campaign, incidents still increased from 75 during the comparable period in 2025 to 95 in 2026.

Supply Chain Attacks Can Multiply the Damage

The broader concern is that ransomware against a manufacturer or distributor can affect companies that were never directly compromised.

The 2025 cyberattack that forced Jaguar Land Rover to halt production in the UK demonstrated the potential scale of such disruption. The shutdown affected thousands of other businesses connected to the automotive supply chain.

Similarly, the Clop campaign targeting Cleo software resulted in hundreds of disclosed victims, demonstrating how a single compromise can spread across interconnected organizations.

Companies downstream from a compromised supplier may also have limited ability to address the original vulnerability because they do not own or control the affected infrastructure.

Governments Look to Strengthen Supply Chain Security

The growing supply chain risk is also attracting regulatory attention. In the UK, the proposed Cyber Security and Resilience Bill seeks to strengthen protections for critical infrastructure from risks originating within technology and service supply chains.

Among other measures, the framework could allow ministers to restrict downstream access to providers considered high risk, creating additional pressure on suppliers to improve their cybersecurity practices.

Black Kite’s findings indicate that the combination of growing ransomware activity, an expanding number of threat groups and increasingly interconnected supply chains is creating a persistent challenge for manufacturers and distributors.

For organizations operating within these sectors, protecting externally exposed systems, securing credentials, monitoring third-party risks and maintaining effective vulnerability management are becoming increasingly important as attackers continue to target the weakest links in complex supply networks.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO