Skip to content
Manufacturing Accounts for 22% of all Ransomware Victims

Manufacturing Accounts for 22% of all Ransomware Victims

Infosecurity-Magazine • September 18, 2026

Manufacturing organizations made up over a fifth (22%) of all ransomware victims in the period from April 2025 to March 2026, according to new Black Kite study.

This made the industry the most targeted by ransomware attacks for the fifth consecutive year, the analysis found.

The volume of ransomware incidents in the manufacturing sector also surged by around 40% year-over-year in the period from January 1 to July 29, 2026 – from 847 to 1183.

This growth continued a trend observed by the researchers of disclosed ransomware incidents in manufacturing rising every year since 2022.

Manufacturing is viewed as a high-value target for ransomware actors for a number of reasons. One factor is that a successful attack can result in significant downtime for victim organizations, which in turn leads to substantial financial losses, potentially making them more likely to agree to pay an extortion demand to resume operations.

The financial impact of such incidents was highlighted in the attack on UK car manufacturing giant Jaguar Land Rover (JLR) in 2025, which is estimated to have cost the UK economy £1.9bn ($2.5bn).

Another factor is growing IT-OT convergence in the sector, making it easier for threat actors to compromise industrial systems .

Read now: Körber’s CISO on Securing Manufacturing’s Expanding Cyber Attack Surface

Seismic Growth in European-Based Manufacturing Victims

The Black Kite report , published on September 17, also reported an 85.4% growth in European manufacturing ransomware victims in the first seven months of 2026 compared to the same period in 2025, from 199 to 369.

Meanwhile, the US victim count remained stable, from 443 incidents to 412. This meant the proportion of US manufacturing victims fell from 52.3% to 34.8%.

Germany, which has a large manufacturing hub comprising 20% of its economy, represented the biggest number of ransomware victims in the sector in Europe, rising from 42 to 77 year-over-year in the first seven months of 2026.

Italy made up the second highest volume of victims, at 57, followed by the UK (43) and France (40).

One factor in the enormous growth in European victims was the SafePay ransomware actor’s focus on German manufacturing targets, according to the researchers.

The Black Kite researchers also highlighted the growing activity of The Gentlemen ransomware actor in targeting manufacturing, with victims in this sector making up 23% of the group’s leak site listings.

Despite only first being observed in September 2025, The Gentlemen claimed the second highest number of ransomware victims in the first seven months of 2026, at 142. This was behind Qilin , at 178.

Read now: Three-quarters of Ransomware Attacks Target Mid-Market Firms

80% of Manufacturing Firms Have Critical Vulnerabilities News 2 October 2024

80% of Manufacturing Firms Have Critical Vulnerabilities

Manufacturing Sector Reeling From Financial Costs of Ransomware News 3 August 2023

Manufacturing Sector Reeling From Financial Costs of Ransomware

Manufacturers Struggle to Manage Cyber-Threats from New Tech Deployments News 5 December 2022

Manufacturers Struggle to Manage Cyber-Threats from New Tech Deployments

Tech Manufacturer Data I/O Hit by Ransomware News 26 August 2025

Tech Manufacturer Data I/O Hit by Ransomware

Three-quarters of Ransomware Attacks Target Mid-Market Firms News 18 August 2026

Three-quarters of Ransomware Attacks Target Mid-Market Firms

What’s Hot on Infosecurity Magazine?

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

Cisco Warns of Active Exploitation of Critical ISE Flaw

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

Anthropic Reveals Yet Another Cybersecurity Incident

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How to Manage Enterprise Cyber Resilience in the Age of AI

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities