Ransomware’s Industrial Leverage Is Spreading Beyond the Factory Floor
Manufacturing ransomware rose 40% in 2026 with 1,183 victims. JLR's £1.9B loss shows impact as new groups target Europe's supply chain.
Text generated by artificial intelligence, published without human review. AI transparency
Illustrative image generated with AI
Manufacturing attacks rise sharply in 2026
Ransomware activity against manufacturers accelerated during the first seven months of 2026, producing 1,183 disclosed incidents. That represents a 40% increase over the comparable period in 2025.
The broader dataset is equally significant. Black Kite’s 2026 Manufacturing & Distribution Ransomware Report counted 5,237 disclosed victims across manufacturing and distribution from January 2023 through July 2026.
The increase reflects more than a preference for large industrial brands. Manufacturers are attractive because their production schedules, delivery commitments and supplier relationships leave little tolerance for extended downtime. A breach at a mid-sized component maker can interrupt much larger businesses that were never directly compromised.
Attackers can also evaluate potential targets before attempting an intrusion. Publicly observable weaknesses—including unpatched internet-facing systems, exposed services, leaked credentials and misconfigured security controls—can reveal which organizations are both accessible and likely to face severe operational pressure.
This creates a favorable negotiating environment for ransomware operators. If a production line stops, financial damage accumulates by the hour, while missed deliveries transfer disruption to customers and partners.
The trend is not tied to one disclosed vulnerability, software product or vendor. No specific CVE, affected version range, patch or confirmed technical remediation has been identified for the incidents counted in the report.
Jaguar Land Rover shows the potential economic scale
The attack against Jaguar Land Rover demonstrates how ransomware-related disruption can move from one manufacturer into the wider economy.
Throughout September 2025, the company shut down its UK plants following the incident. The stoppage halted production of approximately 1,000 luxury vehicles each day and affected more than 5,000 other companies.
The consequences extended beyond the directly connected suppliers and service providers. The Bank of England identified the incident as a factor contributing to slower national growth figures. Jaguar Land Rover later said it would eliminate 4,000 jobs and attributed the reductions to the cyberattack.
The UK’s Cyber Monitoring Centre estimated the total financial impact at £1.9 billion. It characterized the event as the most economically damaging cyberattack in UK history, surpassing the impact of the 2017 WannaCry outbreak.
That scale of damage explains why manufacturers provide unusually strong leverage to extortion groups. Restoring corporate IT may not immediately restart a plant. Production machinery, inventory systems, quality-control processes, supplier communications and delivery scheduling can remain disrupted after the initial containment work.
The costs also continue outside the victim’s network. Suppliers may lose orders, logistics companies may have nothing to transport, and customers may be unable to complete their own products.
New ransomware groups are capturing industrial victims quickly
The expansion in attack volume has been accompanied by rapid turnover among ransomware operators. Approximately half of the manufacturing attacks recorded in 2026 were attributed to groups that had not existed two years earlier.
The Gentlemen provides a clear example of this acceleration. Black Kite first observed the group in September 2025. By mid-2026, it had claimed 142 manufacturing victims and accounted for 12% of attacks during the year.
The reported ranking of the leading ransomware groups was:
- Qilin
- The Gentlemen
- Akira
- DragonForce
- INC Ransom
Black Kite chief research and intelligence officer Ferhat Dikbiyik connected the sector’s appeal to the immediate effect intrusions can have on production and delivery obligations. The longer a plant remains idle, the greater the pressure to negotiate.
The emergence of new groups also complicates defensive planning. Organizations cannot focus exclusively on a small set of established ransomware brands, especially when newer operators can acquire victims rapidly. The relevant exposure is the accessible infrastructure and operational consequence, not merely the name attached to a leak-site claim.
Europe absorbs a growing share of industrial targeting
The geographic distribution shifted substantially toward Europe. Attacks in the region increased by 85%, while the US total was described as almost unchanged from 2025.
The United States remained the most targeted region with 412 attacks, but its share of reported activity fell from 52% to 35%. Europe recorded 369 attacks, while the rest of the world accounted for 402—nearly twice its previous volume.
Germany was the main focus of the European increase, recording 77 attacks. The potential national impact is considerable because manufacturing represented 20% of Germany’s economy in 2024.
SafePay accounted for 22% of attacks in Germany during 2025 and remained among the country’s most active ransomware groups in 2026. Other heavily affected European countries included Italy with 57 incidents, the United Kingdom with 43 and France with 40.
The figures do not indicate that the US has become strategically unimportant. Instead, they show that ransomware operators are expanding toward other industrial concentrations where production stoppages can create comparable leverage.
Europe’s tightly connected manufacturing base can amplify that effect. A compromised organization in one country may supply manufacturers, distributors or customers across several others.
Distribution companies create concentrated points of failure
Distribution has fewer disclosed victims than manufacturing, and affected companies are generally smaller. Its position in the supply chain nevertheless makes the sector strategically valuable to attackers.
Trucking businesses, freight arrangers and warehouse operators handle goods belonging to multiple organizations. Compromising one provider can therefore interfere with several customers at once, even if those customers’ own systems remain secure.
Distribution recorded 196 incidents during 2025. The first half of 2026 produced 95 incidents.
Those totals require context. A Clop campaign during January and February 2025 generated 52 victims, more than one-quarter of the sector’s annual count. Excluding that campaign, the comparable underlying total increased from 75 incidents in 2025 to 95 in 2026.
Supply-chain propagation can work in both directions. Downstream, the Jaguar Land Rover incident affected more than 5,000 other organizations. Upstream, Clop’s attack against technology provider Cleo ultimately resulted in nearly 400 disclosed victims.
In both cases, dependent organizations may be unable to fix the original problem. The vulnerable system can belong to a supplier or technology provider outside their administrative control.
This means that supplier inventories form part of a manufacturer’s effective attack surface. A business may have strong internal controls yet still lose production capacity when a critical component supplier, warehouse operator or freight company becomes unavailable.
Defenses must cover exposed systems and operational dependencies
There is no single patch for the broader campaign activity described in the manufacturing and distribution ransomware findings. Defensive work must address both direct intrusion paths and the external dependencies that convert a breach into a prolonged shutdown.
Manufacturers and distributors should prioritize:
- Finding and remediating unpatched internet-facing systems.
- Removing externally accessible services that are not operationally necessary.
- Identifying leaked credentials, rotating them and monitoring for subsequent misuse.
- Reviewing exposed management interfaces and incorrectly configured security controls.
- Testing whether production, warehouse and corporate networks can be isolated during an intrusion.
- Continuously monitoring the security exposure of suppliers and logistics providers.
- Mapping third parties whose failure could halt production or delivery commitments.
- Requiring suppliers to maintain defined security controls and report incidents.
- Preparing for extended plant closures, logistics interruptions and supplier unavailability.
These measures need operational testing. A network-isolation plan is of limited value if activating it also disables essential safety, inventory or recovery processes. Contingency planning should identify which operations can continue manually, how long reserves will last and which suppliers have viable alternatives.
The UK’s Cyber Security and Resilience Bill points toward a parallel regulatory response. The proposal would allow ministers to block downstream supply from providers considered high risk. Suppliers could consequently face a choice between improving security and losing access to customers covered by the restrictions.
Ransomware risk in manufacturing is no longer confined to the organization whose systems are encrypted or disrupted. The growing incident count, the rapid emergence of new groups and the concentration of dependencies mean that comparatively small compromises can generate disproportionately large economic consequences.
Sources
This article is an original reworking based on the sources below.
