Manufacturing Ransomware Hits Five-Year High
Black Kite's study reports manufacturers made up 22% of ransomware victims from April 2025 to March 2026, the fifth straight year atop the sector list.
For five straight years, one industry has sat at the top of ransomware actors' target lists — and the latest tally shows no sign of that changing. Manufacturing organizations accounted for more than a fifth of all ransomware victims between April 2025 and March 2026, according to a new Black Kite study, making the sector the most attacked for the fifth consecutive year. The findings, published on September 17, also point to a sharp acceleration in incident volumes and a striking geographic shift toward Europe.
Ransomware's Most Reliable Target
Black Kite's analysis found that manufacturing organizations represented 22% of all ransomware victims across the April 2025 to March 2026 window. That share kept the sector in the top spot for a fifth year running, a consistency that speaks to how well manufacturers fit the operational profile ransomware crews look for.
The reasons are largely structural. A successful intrusion into a production environment can halt assembly lines, idle workers and delay shipments — downtime that translates directly into revenue loss. That financial pressure gives victims a strong incentive to pay quickly to get systems running again, which is precisely the leverage extortion gangs rely on.
Growing convergence between information technology and operational technology systems adds a second dimension. As industrial networks connect more deeply to enterprise IT, the researchers noted, it becomes easier for threat actors to move from a compromised business system into the industrial systems that control physical production.
Volume Climbs Roughly 40%
The aggregate victim share is only part of the picture. Black Kite recorded a surge of around 40% year-over-year in manufacturing ransomware incidents between January 1 and July 29, 2026, rising from 847 to 1183.
That jump continued a pattern the researchers tracked across disclosed incidents: manufacturing ransomware counts have climbed every year since 2022. The half-year breakdown of incidents from 2023 through 2026 shows the trend building steadily rather than spiking once and settling back.
Disclosed incidents are a lower bound on actual activity. Not every victim makes an attack public, so the numbers Black Kite compiled reflect companies whose incidents surfaced through leak site listings or public reporting rather than the full universe of attacks.
A £1.9bn Illustration
The financial stakes for manufacturers were laid out starkly in the 2025 attack on UK car manufacturing giant Jaguar Land Rover. That incident is estimated to have cost the UK economy £1.9bn ($2.5bn).
A figure of that scale helps explain why ransomware operators keep returning to manufacturing. When a single disruption can ripple through supply chains and national economies, the pressure on the directly affected company to resolve it fast — including through payment — is intense.
- 22% — share of all ransomware victims that were manufacturers, April 2025 to March 2026
- 847 to 1183 — manufacturing ransomware incidents, January 1 to July 29, year-over-year
- 85.4% — growth in European manufacturing victims in the first seven months of 2026 versus the same period in 2025
- 199 to 369 — European manufacturing victims, first seven months, year-over-year
- 52.3% to 34.8% — fall in the US share of manufacturing victims
- £1.9bn ($2.5bn) — estimated cost to the UK economy of the 2025 Jaguar Land Rover attack
Europe's Victim Count Jumps 85.4%
The most dramatic regional movement in the report came from Europe. Black Kite documented an 85.4% increase in European manufacturing ransomware victims during the first seven months of 2026 compared with the same period in 2025, climbing from 199 to 369.
Meanwhile, the United States held roughly steady, moving from 443 incidents to 412. Because Europe grew so quickly while the US stayed flat, the American share of manufacturing victims dropped from 52.3% to 34.8% — a significant rebalancing of where the pain is concentrated.
Germany led Europe by a wide margin. The country, whose manufacturing hub accounts for 20% of its economy, saw victims rise from 42 to 77 year-over-year in the first seven months of 2026. Italy recorded the second-highest volume at 57, followed by the UK at 43 and France at 40.
The researchers attributed much of Europe's growth to one actor in particular: the SafePay ransomware group, which they said focused heavily on German manufacturing targets.
SafePay and The Gentlemen Drive Growth
Black Kite's report ties the European surge to SafePay's targeting choices, but it also flags a second group reshaping the manufacturing threat picture. Researchers highlighted the growing activity of The Gentlemen ransomware actor, noting that manufacturing victims made up 23% of the group's leak site listings.
That concentration is notable given how new the group is. The Gentlemen was only first observed in September 2025, yet it claimed the second-highest number of ransomware victims overall in the first seven months of 2026, at 142. Only Qilin ranked higher, with 178.
The combination of an established crew like Qilin and a fast-rising newcomer like The Gentlemen illustrates how quickly the ransomware ecosystem can reorder itself. A group that did not exist publicly a year earlier can, within months, become one of the most prolific operations targeting manufacturers.
Why OT Connections Widen the Blast Radius
The IT-OT convergence problem is not new, but its consequences for manufacturers are cumulative. Every additional link between business networks and industrial control systems creates another potential path for an attacker who has already established a foothold in email, endpoints or remote access infrastructure.
Downtime risk is what makes those paths valuable to extortion crews. Unlike a data theft that may go unnoticed for weeks, a production stoppage is immediately visible and immediately expensive — a dynamic that shapes both how quickly victims respond and how much they may be willing to pay.
The researchers' broader point is that manufacturing's appeal to ransomware actors is not accidental or temporary. It combines high downtime costs, growing connectivity between IT and OT, and a global footprint that gives attackers a deep pool of potential targets across multiple regions.
The US Remains a Major Target
Europe's rapid growth should not obscure the fact that the United States still accounts for the largest single national share of manufacturing victims. Even after falling from 52.3% to 34.8%, the US figure of 412 incidents in the first seven months of 2026 remains higher than any individual European country's total.
The difference is one of trajectory rather than scale. While US incident counts held roughly level year-over-year, European counts nearly doubled — a pace that, if sustained, would continue to shift the geographic balance of the sector's ransomware problem.
Germany's position illustrates how concentrated the European risk has become. With manufacturing representing a fifth of its economy, the country offers attackers both a dense cluster of potential targets and, through supply chain relationships, a way to affect companies well beyond its borders.
What the Numbers Suggest for Defenders
For manufacturers, the report's findings point to several areas that warrant attention. The first is visibility: understanding which systems bridge IT and OT environments, and how an attacker moving laterally from a business network could reach production controls.
The second is recovery capability. The cost figures associated with major incidents, including the estimated £1.9bn ($2.5bn) impact of the Jaguar Land Rover attack, reflect how expensive extended downtime can be — and why shortening recovery time matters as much as preventing initial access.
The third is threat awareness specific to the sector. The prominence of SafePay in German targets and The Gentlemen's 23% concentration on manufacturing victims suggests that certain actors are deliberately specializing in this industry rather than treating it as one option among many.
Supply chain relationships add a layer that individual companies cannot fully control. A manufacturer's own defenses may be strong while a critical supplier's are not, and the report's data on concentrated national hubs like Germany's suggests that regional clusters can amplify that exposure.
Why It Matters Beyond the Factory Floor
The fifth consecutive year atop the ransomware victim list is not simply a manufacturing problem; it suggests a persistent gap between the value attackers place on industrial disruption and the defenses many firms have in place. Because manufacturing sits underneath so much else — automotive, aerospace, electronics, consumer goods — a sustained attack campaign against the sector can propagate into supply chains and pricing well beyond the directly affected plants.
The European growth figures in particular could mean that attackers are reweighting their target selection toward regions where they perceive weaker defenses or higher willingness to pay. If that pattern continues, European manufacturers may face a threat environment closer to what their US counterparts have experienced, rather than the relatively stable counts of the past year.
The rise of The Gentlemen, from first observation in September 2025 to the second-highest victim count in the first seven months of 2026, also suggests that the barrier to becoming a major ransomware operation targeting manufacturers is low enough that new entrants can scale quickly. For defenders, that implies monitoring should extend beyond well-known groups to newer actors whose leak site activity is still ramping up.
None of this is a prediction that the trend will continue indefinitely, but the combination of structural incentives and demonstrated actor interest makes a near-term reversal look unlikely on the current evidence.
Sources
- Infosecurity Magazine Original source
- estimated Also reporting
Continue Reading
npm stealer tied to bounty hunter
CrowdStrike says a claimed bug bounty hunter likely built the PhantomRaven npm stealer with an LLM, active since November 2022.
Brevo Breach Turns CDN Edge Into Attack Path
A hardcoded Cloudflare key let attackers rewrite Brevo's sites and customer scripts for hours, pushing ClickFix malware at scale.
Gyazo Breach Exposes 23.6 Million Records
Helpfeel reports a September 11 cyberattack that compromised 23.62 million user records and 490 million image metadata records tied to its Gyazo service.