Back Infosecurity-Magazine Manufacturing Accounts for 22% of all Ransomware Victims
Manufacturing organizations made up over a fifth (22%) of all ransomware victims in the period from April 2025 to March 2026, according to new Black Kite study.
This made the industry the most targeted by ransomware attacks for the fifth consecutive year, the analysis found.
The volume of ransomware incidents in the manufacturing sector also surged by around 40% year-over-year in the period from January 1 to July 29, 2026 – from 847 to 1183.
This growth continued a trend observed by the researchers of disclosed ransomware incidents in manufacturing rising every year since 2022.
Manufacturing is viewed as a high-value target for ransomware actors for a number of reasons. One factor is that a successful attack can result in significant downtime for victim organizations, which in turn leads to substantial financial losses, potentially making them more likely to agree to pay an extortion demand to resume operations.
The financial impact of such incidents was highlighted in the attack on UK car manufacturing giant Jaguar Land Rover (JLR) in 2025, which is estimated to have cost the UK economy £1.9bn ($2.5bn).
Another factor is growing IT-OT convergence in the sector, making it easier for threat actors to compromise industrial systems .
Read now: Körber’s CISO on Securing Manufacturing’s Expanding Cyber Attack Surface
Seismic Growth in European-Based Manufacturing Victims
The Black Kite report , published on September 17, also reported an 85.4% growth in European manufacturing ransomware victims in the first seven months of 2026 compared to the same period in 2025, from 199 to 369.
Meanwhile, the US victim count remained stable, from 443 incidents to 412. This meant the proportion of US manufacturing victims fell from 52.3% to 34.8%.
Germany, which has a large manufacturing hub comprising 20% of its economy, represented the biggest number of ransomware victims in the sector in Europe, rising from 42 to 77 year-over-year in the first seven months of 2026.
Italy made up the second highest volume of victims, at 57, followed by the UK (43) and France (40).
One factor in the enormous growth in European victims was the SafePay ransomware actor’s focus on German manufacturing targets, according to the researchers.
The Black Kite researchers also highlighted the growing activity of The Gentlemen ransomware actor in targeting manufacturing, with victims in this sector making up 23% of the group’s leak site listings.
Despite only first being observed in September 2025, The Gentlemen claimed the second highest number of ransomware victims in the first seven months of 2026, at 142. This was behind Qilin , at 178.
Read now: Three-quarters of Ransomware Attacks Target Mid-Market Firms
80% of Manufacturing Firms Have Critical Vulnerabilities News 2 October 2024
80% of Manufacturing Firms Have Critical Vulnerabilities
Manufacturing Sector Reeling From Financial Costs of Ransomware News 3 August 2023
Manufacturing Sector Reeling From Financial Costs of Ransomware
Manufacturers Struggle to Manage Cyber-Threats from New Tech Deployments News 5 December 2022
Manufacturers Struggle to Manage Cyber-Threats from New Tech Deployments
Tech Manufacturer Data I/O Hit by Ransomware News 26 August 2025
Tech Manufacturer Data I/O Hit by Ransomware
Three-quarters of Ransomware Attacks Target Mid-Market Firms News 18 August 2026
Three-quarters of Ransomware Attacks Target Mid-Market Firms
What’s Hot on Infosecurity Magazine?
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
Cisco Warns of Active Exploitation of Critical ISE Flaw
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Anthropic Reveals Yet Another Cybersecurity Incident
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How to Manage Enterprise Cyber Resilience in the Age of AI
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
