www.securityweek.com 17 Sept 2026, 12:29 UTC

Ransomware Attacks on Manufacturers Surge 40% as New Groups Emerge

Ransomware Attacks on Manufacturers Surge 40% as New Groups Emerge
CyberSIXT Evidence Panel
Threat Actor

RANSOMWARE attacks against manufacturers increased sharply in the first seven months of 2026, according to Black Kite’s 2026 Manufacturing & Distribution Ransomware Report. The firm identified 1,183 incidents, 40% more than during the same period in 2025. Half involved ransomware groups that did not exist two years ago, while the newly identified The Gentlemen accounted for 12% of attacks and had claimed 142 manufacturing victims by mid-2026. The leading groups were Qilin, The Gentlemen, Akira, DragonForce and INC Ransom.

Black Kite attributes the sector’s appeal to the immediate operational impact of an intrusion: attackers can halt production and disrupt delivery commitments, increasing pressure to negotiate. Its research says criminals use externally visible indicators such as unpatched systems, exploitable services, leaked credentials and misconfigured defences to identify targets. Europe saw an 85% rise in victims, including 77 attacks in Germany, 57 in Italy, 43 in the UK and 40 in France. The US remained the most targeted region, with 412 attacks, compared with 369 in Europe and 402 elsewhere.

The report highlights the wider supply-chain consequences. Jaguar Land Rover’s September 2025 shutdown halted production of about 1,000 vehicles a day and affected more than 5,000 companies; the UK Cyber Monitoring Centre estimated the financial impact at £1.9 billion. Distribution attacks were fewer, with 95 incidents in the first half of 2026, but can similarly affect many organisations.

The article says the UK’s proposed Cyber Security and Resilience Bill aims to reduce such downstream risks by allowing ministers to block high-risk suppliers from critical infrastructure.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline