New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu

Why Manufacturing Supply Chains Are Ransomware's Favorite Target

Third Party Podcast: Five Years Running as Ransomware's Top Pick

YouTube video thumbnail

Introduction

In the latest episode of the Third Party podcast, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik lay out why manufacturing has held the number one spot on ransomware's target list for nearly five years running, and why almost none of it makes the news.

On average, roughly 1,500 manufacturing companies a year turn up on ransomware groups' leak sites, publicly named after refusing to pay. Analysts estimate the real number of successful attacks runs closer to 2,000 once you factor in the companies that quietly pay before they're ever named. Almost none of that reaches the headlines.

The Ransom Math Is a Slam Dunk, and Attackers Know It

Here is the calculation keeping ransomware groups in business: if the ransom is a million dollars and building a real cyber program costs twenty million, paying starts to look like the rational move. Attackers have done this math too, which is exactly why manufacturing stays in their crosshairs. COVID-era digitalization only made it easier, stacking a digital supply chain on top of an already sprawling physical one and handing attackers a much bigger surface to work with.

The demands themselves have gotten smaller, not bigger. Some groups skip negotiation entirely and ask for a flat $20,000, betting that volume beats sophistication. When a shutdown costs a manufacturer far more than that per day, twenty grand is an easy yes, and attackers can run that play hundreds of times a year instead of gambling on one seven-figure score.

Downtime Beats Data When There's No Regulatory Fine to Fear

Nobody panics about a data breach anymore. Everyone panics about a shutdown. In finance and healthcare, data loss still carries real teeth because regulators attach fines to it, and attackers price that into their demands. Manufacturing has no equivalent regulatory bill. What it has instead is a contract: ship this many units by this date, or pay a penalty. Miss that date because a production line is encrypted, and the penalty plus the lost revenue plus the furious customer on the phone adds up to a far bigger number than any stolen file ever would.

That dynamic played out publicly with Jaguar Land Rover, whose ransomware-driven production halt made headlines and reportedly dented UK GDP. It is also why the UK is now moving toward restricting ransom payments outright, a policy fight that raises its own question: regulate the payment without funding the defense, and companies get stuck choosing between breaking the law and staying in business.

When the Risk Stops Being Financial and Starts Being Physical

Downtime is a business problem. A manipulated turbine is a safety problem. Researchers have demonstrated exactly how thin that line is: change a single parameter on an industrial turbine remotely, and the thing vibrates itself apart. That demo is over a decade old, and the equipment it targeted almost certainly runs on an IT network today that it never touched back then. Nation-states have already shown they can sit inside critical infrastructure for years without acting, which is less reassuring than it sounds. The capability being dormant is not the same as the capability not existing.

The Patching Paradox Nobody Has Solved

Black Kite's latest manufacturing report, based on the top 1,000 companies in the sector, found that 75% carry a critical vulnerability rated CVSS 8 or higher, and 65% have a flaw already sitting on CISA's Known Exploited Vulnerabilities catalog. Those numbers are not a knowledge gap. They are a scar tissue problem: once a patch has taken down a production line, teams get hesitant to ever patch again. Some operational technology (OT) equipment is one-of-a-kind and cannot be replicated in a lab to test a fix safely, which leaves plants choosing between a known vulnerability and an unknown outage.

IT Security Speaks One Language. OT Speaks Another.

Ask an IT security team what matters and you will hear confidentiality first. Ask an OT team and you will hear availability, consistency, and flexibility instead. That mismatch is a big reason IT/OT convergence has become the single largest risk in third-party supply chain security today, not a supporting factor but the headline one.

Closing that gap starts with visibility that does not depend on a vendor telling you something is wrong. One Black Kite customer, a food manufacturer, was continuously monitoring its vendor base when the system flagged a severe ransomware indicator on one of its suppliers. The manufacturer reached out. The supplier had no idea it had been compromised until that call came in. That is the difference between finding out about a third-party incident from a headline and finding out from your own Nth-party visibility before it ever reaches you.

Pairing the Ransomware Susceptibility Index® (RSI™) that tracks real-time attacker indicators with FocusTags® that flag active threat activity turns that kind of catch from a lucky break into a repeatable process. Manufacturing was never going to be an easy vertical to secure. It can, however, be a much better-informed one.

Don't Miss an Episode!

Subscribe to Third Party on YouTube, the podcast for people who don't need to ask ChatGPT what TPCRM means. New episodes every other week.

Next time on Third Party:

Next time, we're talking about leverage, or the lack of it. You can have the contract, the scorecard, and five follow-up emails about a critical vulnerability, and still get nothing from a vendor who simply doesn't feel like responding. We dig into who actually holds the power in vendor relationships, and what to do when it isn't you.

Subscribe below.

Real Talk on Third-Party Risk.

Check out our new podcast, Third Party, where we unpack what actually works (and what doesn't) in TPRM.

Apple Podcasts
Follow Third Party on Apple Podcasts
Follow
Spotify
Follow Third Party on Spotify
Follow

Ready to get started?

Integrate risk intelligence into every part of your workflow so you can make more informed decisions with confidence.