
2026 Manufacturing & Distribution Ransomware Report
Still the #1 Target, but the Victim Profile Moved Downmarket and Overseas
Read the report in its entirety below, or download the optional PDF.
Period covered: January 2023 to July 2026
A stopped production line is a cyber story
On the last day of August 2025, Jaguar Land Rover (JLR) shut down its own global IT systems to contain a cyberattack. The decision stopped the three UK plants that together build roughly 1,000 vehicles a day, and they stayed stopped for more than five weeks.
The consequences did not stay inside the company. UK car production fell 27% year over year that September, more than 5,000 organisations sat inside the blast radius, most of them small and medium-sized parts suppliers, logistics providers and dealerships, and when the Bank of England explained why third-quarter growth had come in below its own forecast, it named the attack as one of two reasons.
That chain of events is the defining feature of cyber risk in manufacturing and distribution. The physical fragility is what draws ransomware operators to these industries.
When the systems that make goods or move goods stop, the effects do not stay inside the victim's network. It travels to everyone who was counting on those goods.
This report examines that pressure across the full chain. It draws two kinds of evidence.
- The first is a record of who was attacked. Between January 2023 and July 2026, the Black Kite Research Group™ identified 5,237 disclosed ransomware victims across these two groups.
- The second is a current map of who is exposed. Black Kite's external scans of the Top 1000 manufacturers (companies with annual revenue above $1 billion) and 2,289 monitored distribution companies show who is exposed right now.
Together they answer two questions that a victim count alone cannot, which is not only who has already been hit, but who looks, right now, like the next target. This report is your blueprint for ranking your suppliers by observable ransomware susceptibility instead of by revenue, tier, or the date of the last questionnaire.
Download the optional PDF.
Three out of four manufacturing ransomware victims were already in the critical Ransomware Susceptibility Index® (RSI™) range at disclosure.
See where you stand, and where your suppliers stand.
On This Page:
- Key Findings
- Manufacturing as the Primary Target
- Five Years of Uninterrupted Growth
- The Victim Profile
- Geography
- Subsectors
- A Rebuilt Threat Actor Ecosystem
- Spotlight: The Gentlemen
- The Distribution Leg
- Case Study: Peter Green Chilled
- Case Study: Jaguar Land Rover
- Case Study: Asahi and Fairlife
- Current Exposure, Seen From the Outside
- The Top 1000 Manufacturers
- The Distribution Fleet
- The Cascade Runs Both Directions
- The Regulatory Direction
- Methodology
- FAQs
- Related Resources
01 Key Findings From the 2026 Manufacturing and Distribution Ransomware Report
1,183 Manufacturing Victims in Seven Months, and the Climb Hasn't Paused
The first seven months of 2026 produced more manufacturing victims than all of 2024, and same-period volume is up 39.7% year over year.
49.7% of 2026 Incidents Came From Groups Absent Two Years Ago
The attacker ecosystem rebuilt itself in two years. Nearly half of 2026 manufacturing incidents came from groups absent in 2023 and 2024, and a single new entrant, The Gentlemen, accounts for 12.0% of the year's incidents on its own.
70.2% of Manufacturing Victims Sit in the $10M to $100M Revenue Band
The mid-market carries the volume. The median victim generates $42.9 million in revenue, while the largest manufacturers continue to be hit every year.
85.4% Growth in European Victims Cut the US Share to 34.8%
The map broadened in 2026. The US victim count barely moved (443 to 412), so the drop from 52.3% came entirely from growth elsewhere, led by Germany, where manufacturing carries 19.9% of the economy. Manufacturing ransomware is globalizing.
Key Stats at a Glance
02 Ransomware: Manufacturing as the Primary Target
Five Years of Uninterrupted Growth
Ransomware activity against manufacturers has risen every year since 2022, and the pace is accelerating.
The Black Kite Research Group™ tracked 540 disclosed ransomware incidents against manufacturing companies in 2022, 926 in 2023, 1,071 in 2024, and 1,600 in 2025. The first seven months of 2026 alone produced 1,183 incidents, already surpassing the full-year totals of both 2023 and 2024.
Same-Period Manufacturing Victims More Than Tripled Since 2022, From 319 to 1,183
Each year counts January 1 through July 29 only, so 2026 is directly comparable rather than a partial-year total.
Because 2026 data covers only January 1 through July 29, the cleanest comparison is the same window in each year: 505 incidents in 2023, 593 in 2024, 847 in 2025, and 1,183 in 2026.
That is a 39.7% increase over the same period of 2025, which had itself grown 42.8% over 2024. The first half of 2026 (1,020 incidents) is the highest half-year on record in this dataset, up 34.2% from the first half of 2025.
2026's First Half Set a Record at 1,020 Manufacturing Incidents
Half-year volume was nearly flat from 2023 into 2024, then climbed across four consecutive periods from 556 to 1,020.
Manufacturing's position at the top is consistent across Black Kite's broader ransomware research. Black Kite's 2026 Ransomware Report, covering April 2025 through March 2026, identified 7,551 publicly disclosed ransomware victims across all industries, and manufacturing held the top position for the fifth consecutive year with 1,660 victims, 22.0% of all disclosures. Manufacturing has remained the top target every year Black Kite has tracked ransomware activity, since 2021.
Manufacturing Accounted for 22% of All Ransomware Victims Across Every Industry
Professional and technical services followed at 18.4%, construction at 7.2%, and wholesale trade at 5.6%. Covers April 2025 through March 2026.
Ransomware's climb is visible across every sector Black Kite has studied. What separates manufacturing is that its climb never paused. In 2024, the year law enforcement dismantled LockBit and disrupted Clop, finance recorded 18.8% fewer ransomware disclosures, and mid-market victim counts across North America and Europe stayed nearly flat. Manufacturing grew 15.7% straight through the takedown year, and then accelerated 49.4% in 2025, the fastest growth across Black Kite's recent report series. Whatever slowed ransomware operators elsewhere, it did not slow them here.
The Victim Profile: Mid-Market Carries the Volume
The incidents that reach the news involve companies everyone knows: Silent breweries at Asahi, and a cybersecurity incident that halted production lines at Nucor, the biggest steel manufacturer in North America. Those stories are true, and they are exceptional. The dataset behind this report tells a quieter story. The typical manufacturing ransomware victim is a company few people outside its own supply chain have ever heard of.
This section examines the 4,780 manufacturing victims in the dataset; the 457 distribution victims are analyzed separately in the Distribution Leg section. Among the manufacturing victims, 4,077 (85%) carry annual revenue figures that can be verified. Its center of gravity is unmistakably mid-market. The median victim generates $42.9 million per year, and the concentration is deepening. Companies in the $10M-$100M revenue band accounted for 54.3% of revenue-known victims in 2023 and 70.2% in 2026, after peaking at 73.9% in 2025.
The $10M to $100M Band Grew From 54.3% to 70.2% of Manufacturing Victims
Victims under $10M also rose, from 14% to 17.3%, while both bands above $100M contracted.
The largest manufacturers have not fallen off the target list. Victims with revenues above $1 billion appear in every year of this dataset. 108 in 2023, 64 in 2024, 73 in 2025, and 45 in the first seven months of 2026. Their share of victims nonetheless declined from 13.1% to 5.3%, because the base beneath them expanded. That base expanded downward as well as into the middle. Victims under $10 million in revenue rose from 14.0% of the revenue-known pool in 2023 to 17.3% in 2026.
Because Black Kite's collection methodology remained unchanged across the period, the shift is unlikely to be an artifact of expanded observation. Instead, the data shows a growing concentration of disclosed ransomware victims in the $10M-$100M revenue band. That concentration likely reflects a combination of factors: companies in this range carry enough revenue to make extortion worthwhile, face contractual delivery obligations that increase downtime pressure, and may share technology and exposure patterns that make them more reachable during both targeted and campaign-driven attacks.
For anyone managing third-party risk, this profile is a supply chain finding as much as a victim statistic. The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products. When the mid-market is the primary target, a large manufacturer's vendor list is its attack surface.
Black Kite examines the mid-market segment in depth in its dedicated mid-market study.
Geography: 2026 Broadens the Map
The manufacturing industry in North America was the main target through 2025. In the January-July window of 2025, US companies accounted for 52.3% of manufacturing victims.
However, in the same window of 2026, that share fell to 34.8%, while the absolute US count barely moved (443 to 412). The growth came from Europe, where victims rose from 199 to 369 (up 85.4%), and victims in the rest of the world rose from 205 to 402 (up 96.1%).
Manufacturing ransomware is globalizing, and the economies most dependent on their factories are absorbing the fastest growth.
The US Share of Manufacturing Victims Fell From 43.4% in 2023 to 34.8% in 2026
Over the same period the rest of the world climbed from 24% to 34%, nearly matching the US.
The European surge is concentrated where manufacturing matters most. Germany recorded 77 victims in the first seven months of 2026 against 42 in the same period of 2025, an increase of 83.3% and the highest country total in Europe. Manufacturing generated 19.9% of Germany's gross value added in 2024, well above the EU average of 15.9%.
Part of Germany's pressure has a familiar name. SafePay, the group Black Kite's European ransomware research flagged for its concentration on German targets, accounted for 21.9% of German manufacturing victims in 2025 and remains among the country's most active groups in 2026.
Italy, Europe's second country by victim volume across the full period, grew from 37 to 57.
Italy carries a similar structural weight. Manufacturing generates 16.6% of its gross value added, also above the EU average.
France nearly tripled its same-period count (14 to 40), Turkey more than quadrupled (7 to 32), Spain rose from 7 to 31, The United Kingdom rose from 24 to 43, and Poland from 1 to 11.
Switzerland is the one series that dips before it climbs, falling from 15 same-period victims in 2023 to 4 in 2024 before returning to 14 in 2026. The 2023 figure requires context. Clop alone accounted for one-third of the total, while seven other groups each posted a single victim, suggesting a concentration of one-off postings rather than a sustained country-level pattern.
Germany Led Europe With 77 Manufacturing Victims in Seven Months, Up From 42
Italy reached 57, the United Kingdom 43, France 40, Turkey 32, and Spain 31.
The mid-market concentration described above is a global average, and it varies widely from one country to the next.
- In the United Kingdom, 79.1% of revenue-known victims fall in the $10M-$100M band, the highest concentration of any major country in the dataset and well above the 66.3% global average.
- Canada follows at 76.8% and is climbing the fastest. Canadian mid-market victims rose from 11 in 2023 to 71 in 2025.
- Japan sits at the other extreme, with only 37.0% of its victims in that band and a pool skewed toward large enterprises.
Subsectors: Machinery Leads a Broad-Based Surge
The climb in manufacturing victims over the years is not the work of any single corner of the industry.
Machinery Manufacturing leads the full period with 701 victims (15.2% of subsector-classified victims), followed by Fabricated Metal Products with 515 (11.2%), Transportation Equipment with 425 (9.2%), Chemical Manufacturing with 423 (9.2%), Computer and Electronic Products with 407 (8.8%), and Food Manufacturing with 361 (7.8%).
Together, the top five account for just over half of all classified victims.
Machinery Manufacturing Leads All Subsectors at 15.2% of Classified Victims
No subsector exceeds 16%, which shows pressure spread across the production economy rather than concentrated in one niche.
At the finer level of detail, industrial machinery and general purpose machinery makers top the list, with pharmaceutical manufacturers close behind at 194 victims. These are the subsectors where a stopped line converts most directly into missed shipments and contractual penalties, and that conversion is precisely the pressure ransomware operators monetize.
The trajectories beneath the totals differ, and they suggest a wave that rotates rather than parks.
Fabricated Metal Products absorbed the earliest and steepest climb, more than tripling from 64 victims in 2023 to 210 in 2025, then cooled to 16.4% same-period growth in 2026 while everything around it accelerated.
Seven of the eight largest subsectors grew by more than 55% in the 2026 same-period comparison, led by Electrical Equipment (up 96.6%), Computer and Electronics (up 90.5%), and Chemicals (up 74.2%). Even Transportation Equipment, the flattest series through 2025, joined the acceleration at 57.9%.
Machinery Victims Rose From 109 to 179 in the 2026 Same-Period Comparison
Electrical equipment grew fastest in percentage terms, from 29 to 57. Fabricated metal products grew slowest, from 116 to 135.
The shift toward mid-sized victims runs through nearly every subsector, with one exception.
Comparing 2023-2024 with 2025-2026, the share of victims with revenues above $1 billion fell from 9.5% to 5.2% across the dataset, and it fell in seven of the eight largest subsectors.
Transportation Equipment moved the other way. Its billion-dollar victim share rose from 13.2% to 15.7%, making it the one subsector where enterprise targeting intensified while the rest of the industry's attackers moved downmarket.
The reason matters for what follows. This is the subsector of automotive and aerospace supply chains, where the largest companies sit at the center of the deepest supplier networks.
A Rebuilt Threat Actor Ecosystem
Across the full 2023-2026 period, four groups dominate the manufacturing victim count. Qilin (455 incidents), Akira (385), LockBit 3.0 (355), and Play (335), together responsible for 32.0% of all incidents in the dataset. That full-period ranking, however, describes a hierarchy that no longer exists. In the first seven months of 2026, the leaderboard reads Qilin (178), The Gentlemen (142), Akira (96), DragonForce (70), and INC Ransom (65), and one of those five, The Gentlemen, did not exist in the dataset before September 2025, while DragonForce and INC Ransom entered it with single-digit counts in 2023.
The decline side of that leaderboard is just as sharp. Play ranks fourth across the full period with 335 incidents and recorded only 39 in 2026. Medusa fell to 4. SafePay, the group concentrating on German targets, posted 29, and Clop registered 9, which is what a mass exploitation specialist looks like between campaigns.
The risers set the pace.
- Qilin accounted for 8 manufacturing incidents in 2023, 245 in 2025, and 178 in the first seven months of 2026, making it the most active group in the sector across every recent period. Barracuda's analysis of Qilin's 2025 activity found manufacturing was its most attacked sector, accounting for roughly 23% of the group's leak site listings.
- The Gentlemen went from its first appearance in September 2025 to second place in 2026.
- Behind them, DragonForce grew from 6 incidents in 2023 to 70 in seven months of 2026, and INC Ransom from 9 to 65.
Qilin Led Manufacturing With 178 Victims in Seven Months, The Gentlemen Second at 142
Akira followed with 96, DragonForce with 70, INC Ransom with 65, and LockBit 5.0 with 56. Play fell to 39 and Medusa to 4, both down sharply from their 2023 levels.
Not every group operates the same way. Clop, described as a mass exploitation specialist, produced two distinct victim waves in 2025 and was nearly dormant between campaigns. 11 manufacturing incidents in all of 2024 and 2 between March and September 2025. Its activity arrived in two pulses that align with its documented campaigns.
- The January-February 2025 pulse, matching the Cleo file transfer campaign that Black Kite's 2025 Ransomware Report counted at 131 manufacturing victims, produced 128 publication-ready manufacturing victims in this dataset and skewed mid-market. 76.8% of its revenue-known victims sat in the $10M-$100M band, well above the 66.3% baseline, and the same pulse produced 52 distribution victims.
- The October-November 2025 pulse, matching the Oracle E-Business Suite campaign, ran the other way. 28.3% of victims had revenues above $1 billion, four times the dataset baseline, against 7.1% across the full four-year dataset, because an enterprise application's customer base is an enterprise victim pool.
In campaign-driven ransomware, victim size stops being the attacker's choice and becomes a property of the exploited product's customer base.
Departures in the ransomware ecosystem are equally important to comprehend the dynamics.
- LockBit 3.0 led the sector with 212 incidents in 2023, fell to 7 in 2025, and recorded none in 2026, although a successor brand operating as LockBit 5.0 surfaced in late 2025 and has claimed 56 manufacturing victims in 2026.
- ALPHV (BlackCat) went from 94 incidents in 2023 to zero by 2025. RansomHub went from 90 incidents in 2024 to zero in 2026. Black Basta and 8Base followed the same trajectory. Add the arrivals and departures together, and the scale of the churn becomes visible.
Nearly half of 2026 incidents (49.7%, or 588 of 1,183) were claimed by actors that did not appear in this dataset at all in 2023 or 2024, and the number of distinct groups active against manufacturers grew from 55 in 2023 to 91 in just the first seven months of 2026.
Black Kite counted 61 new groups entering the entire ransomware ecosystem in a single year, more than one per week, and found they added volume on top of the incumbents rather than replacing them. Manufacturing, as the largest victim pool, received the largest share of that new capacity.
Threat Actor Spotlight: The Gentlemen
Among the new arrivals, The Gentlemen stands out for how quickly it found its footing in manufacturing. The group first appeared in this dataset in September 2025 and claimed 20 manufacturing victims before the year closed. In the first seven months of 2026 it recorded 142 more, enough for second place behind Qilin.
By mid-2026 The Gentlemen had claimed 615 victims worldwide in this dataset, 142 of them in manufacturing, meaning the sector accounts for 23.1% of the group's activity, a heavier manufacturing concentration than almost any other major group. Within manufacturing it trailed only Qilin over the first seven months of the year, a position that took the sector's established groups several years to reach.
The group's clearest fingerprint is on the European numbers. European manufacturing victims grew by 170 incidents in the same-period comparison, from 199 to 369, and The Gentlemen accounts for 61 of them. No other actor comes close. Qilin added 40, and the next two contributors, Deadlock and LockBit 5.0, are themselves newcomers. Deadlock added 23 and LockBit 5.0 added 22. Every other group combined moved the opposite way, falling from 171 European victims to 159. The entire regional increase came from actors that were absent or marginal a year earlier.
The Gentlemen Alone Added 61 of Europe's 170 Additional Manufacturing Victims
Incumbent actors declined over the same window, from 171 European victims to 159. Every bit of Europe's growth came from groups that were absent or marginal in 2025.
The country detail sharpens the picture further as half of France's increase (13 of 26 additional victims) and roughly a third of Germany's (11 of 35) trace back to this one group, while only 15 of its 142 manufacturing victims in 2026 are US-based.
03 The Distribution Leg: The Industry That Moves What Manufacturing Makes
Distribution is not an appendix to the manufacturing story. Trucking companies, freight arrangers, and warehouse operators form their own industry with their own attack surface, and they occupy a distinct position in the supply chain. They are the layer where many companies' goods concentrate in one place, which is precisely what makes the sector consequential beyond its size.
The victim numbers are smaller than manufacturing's, and the victims themselves are smaller still. The Black Kite Research Group™ identified 457 disclosed ransomware victims across trucking, freight arrangement, and warehousing between January 2023 and July 2026: 63 incidents in 2023, 103 in 2024, 196 in 2025, and 95 in the first seven months of 2026.
Distribution Victims Grew 26.7% in 2026 Once the Clop Campaign Is Set Aside
The 2026 bar covers January through July only, and the 2025 total includes 52 victims from a single eight-week Clop campaign.
The 2025 spike and the lower 2026 count are two halves of the same story. A single Clop campaign in January and February 2025 produced 52 distribution victims, 26.5% of the year's total, in eight weeks. Set that campaign aside, and the same-period baseline actually grew 26.7% in 2026, from 75 to 95 incidents. Distribution risk did not recede after 2025. The campaign wave receded, and the underlying growth continued underneath it. General freight trucking carries the largest share with 210 victims, followed by freight arrangement with 127, warehousing with 80, and specialized freight with 40.
General Freight Trucking Accounts for 46% of Distribution Ransomware Victims
Freight transportation arrangement follows at 27.8%, warehousing and storage at 17.5%, and specialized freight trucking at 8.8%.
The median revenue-known victim generates $28.7 million per year, well below manufacturing's $42.9 million, and 68.6% sit in the $10M-$100M band. This is an industry of thin margins and contractual delivery windows, attacked at the size where a week of downtime threatens the business itself.
04 Case Study: The Peter Green Chilled Cyber Attack That Stalled Eight Supermarket Chains
Peter Green Chilled, the UK company that has moved chilled and frozen food since 1963, runs temperature-controlled warehousing and transport for Tesco, Sainsbury's, Aldi, M&S, Waitrose, Asda, Co-op and Morrisons. It generates $79.5 million a year, placing it inside the revenue band that carries most of this sector's attacks.
On the evening of Wednesday, May 14, 2025, attackers encrypted the company's data and locked it out of its systems. Customers were notified by email the following day. Managing director Tom Binks confirmed that transport activities continued unchanged while new orders went unprocessed. The fleet kept moving what was already in the system. Nothing new could enter it.
The cost landed downstream within days. Wilfred Emmanuel-Jones, founder of The Black Farmer and a Peter Green customer, told BBC Radio 5 Live that thousands of packets of his meat products were sitting in limbo, already delivered into the warehouse with no route out to retailers. A further shipment from Sweden was stuck at a port because the company had stopped accepting inbound stock. Fresh products undelivered within a few days would have to be discarded, and he put the potential loss to his business at up to £100,000.
One mid-sized haulier stood between the suppliers who had already handed over their stock and the eight supermarket chains waiting to receive it. When its order processing stopped, neither end could move.
05 Case Study: Jaguar Land Rover, the Costliest Cyberattack in UK History
Jaguar Land Rover (JLR), the UK's largest automaker, confirmed a breach on September 2, 2025, and shut down its global IT systems to contain it. Production stopped for more than five weeks across the three UK plants that together build roughly 1,000 vehicles a day, at a weekly cost near £50 million. The UK government stepped in with a £1.5 billion loan guarantee to support JLR and its suppliers through the shutdown.
The UK's Cyber Monitoring Centre rated the incident a Category 3 systemic event, estimating a £1.9 billion financial impact and more than 5,000 affected organizations, most of them small and medium-sized suppliers. It called the incident the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak.
The disruption was large enough to move a national economic indicator. The Bank of England's November 2025 Monetary Policy Report cited the JLR cyberattack as a factor behind UK GDP growing 0.2% in Q3 2025 instead of the 0.3% it had projected, a small shortfall to trace back to a single company's cyber incident.
Coventry-based Evtec Group, a tier-one JLR supplier, placed 900 employees on short-time work at reduced pay during the stoppage and put its own loss at £13 million, one supplier absorbing a fraction of a disruption that ran into the billions.
06 Case Study: Asahi and Coca-Cola’s Fairlife Ransomware Attacks, and What Their RSI Scores Showed Before Disclosure
When Asahi Group Holdings was compromised in late September 2025, the intrusion did not turn on a sophisticated exploit. Asahi later reported that the attackers reached its network through equipment at one of its group sites and exploited a weak password to obtain administrative privileges. What followed set it apart. Within days, 30 factories were offline, and six breweries stayed closed for a week. The direct toll passed $31 million in lost revenue before legal and incident response costs were counted.
Ten months later, Coca-Cola disclosed in a filing with the Securities and Exchange Commission (SEC) that a ransomware attack on its Fairlife dairy unit had suspended production at the company's US facilities.
Black Kite's Ransomware Susceptibility Index® (RSI™) shows what these two companies looked like from the outside before their incidents became public.
RSI scores a company from 0 to 1 on how closely its externally visible posture matches the conditions ransomware operators select for: Exposed remote access, exploitable software vulnerabilities, leaked credentials, and stealer log findings.
Companies Scoring Above 0.8 on the RSI Are 291 Times More Likely to Be Attacked

In absolute terms, 41% of companies above 0.8 experienced a ransomware attack, against 0.14% of those below 0.2. Based on 7,000+ victims in 2025 and early 2026.
Values above 0.4 fall in the critical range. At disclosure, Fairlife's scan stood at 0.58, inside the 0.4 to 0.6 band, where Black Kite's latest research finds companies 36 times more likely to experience a ransomware attack than those scoring below 0.2.
Asahi's stood at 0.778, one band higher, at 0.6 to 0.8, where that likelihood climbs to 54 times. Both readings sat well below the top band, where companies above 0.8 are 291 times more likely to be hit, and both still placed these companies squarely among the targets ransomware operators reach most often.
Both companies looked, from the outside, like the targets the sector's attackers were already finding at scale.
The dataset behind this report puts numbers on that scale. Scanned at disclosure, 74.4% of manufacturing victims carried an RSI in the critical range (above 0.4), 35.1% stood at 0.6 or higher, and the average victim scored 0.552.
At disclosure, three out of four manufacturing victims were already in the critical RSI range. Fairlife and Asahi were not exceptions; they were the pattern.
07 Visible From the Outside: Current Exposure Across Manufacturing and Distribution
Ransomware operators do not begin with the attack. They begin with reconnaissance, and the raw material of that reconnaissance is externally visible: Unpatched systems, exploitable services, leaked credentials, and misconfigured defenses.
Black Kite's platform is built on the same vantage point. Every number in this chapter was collected from the outside, the way an attacker would collect it. The result is a map of what the sector's adversaries can already see, drawn from the same signals, susceptibility scores, exploitation cycles, and social engineering at scale.
This chapter maps that visible surface across the two populations this report covers, the Top 1000 manufacturers and the 2,289 monitored distribution companies that move their output, using scan data current as of August 2026.
The Top 1000: Critical Exposure at the Strongest Tier
The Top 1000 cohort holds a particular place in this report's argument. These are the sector's largest companies, the tier with the scale and resources that mid-market manufacturers lack; whatever their scans show is close to the best case the sector has to offer. That best case still shows critical exposure as the standard condition rather than the exception.
74.8% of the Top 1000 Manufacturers Carry a Critical Vulnerability
34.3% show an active botnet infection finding and 29.8% have at least one recorded data breach. August 2026 scan data.
Read as an attack chain rather than a list, the chart describes a cohort exposed at every stage of a ransomware operation.
The entry layer is the widest. Three quarters carry at least one critical vulnerability, 61.4% carry one at the highest severity band, and more than half carry a flaw from CISA's Known Exploited Vulnerabilities catalog, which by definition lists only what attackers already use in the wild.
The access layer runs just as deep. 69.1% have employee or system credentials circulating in stealer log markets, the economy that supplies ransomware affiliates their entry points. One layer is not exposure but evidence. 34.3% of the cohort shows an active botnet infection finding, and 29.8% carries at least one recorded data breach. Those are not conditions an attacker might exploit. They are signs someone already has. The deception layer extends the exposure to trading partners. Nearly half of these companies have been impersonated in phishing infrastructure, and with 35.6% missing properly configured DMARC, a manufacturer's open email authentication becomes its suppliers' and customers' phishing problem.
Direction matters as much as level, and Black Kite measured this cohort two years ago.
The patch side is improving. Companies with critical vulnerabilities eased from 80% in 2024 to 74.8%, and KEV exposure fell thirteen points, from 67% to 54.2%, evidence that prioritizing known-exploited flaws works when the sector's largest companies commit to it.
KEV Exposure Fell 13 Points Since 2024 While Credential Exposure Didn't Move at All
Critical vulnerabilities eased from 80% to 74.8% and KEV findings from 67% to 54.2%. Credential exposure went from 69% to 69.1%.
Credential exposure refused to follow. 69% of the cohort in 2024, 69.1% today. The difference is structural because a vulnerability list is a project with an end state; credentials leak continuously through infostealer infections on employee and contractor devices, and no patch cycle drains that pool.
The victim record shows why the frozen layer is the dangerous one. Misconfiguration was the most common finding in every year, present in 83.7% of 2023 victims and still 71% in 2026. Exposed remote access ports never moved at all, sitting at 51.3% in 2023 and 51.9% in 2026. Roughly half of manufacturing victims carried exploitable software vulnerabilities at disclosure in every year from 2023 through 2026, the same persistent vulnerability layer the Top 1000 shows at higher resolution today.
The credential front moved. The share of victims with stealer log findings at disclosure climbed from 25.0% in 2023 to 41.8% in 2026, and the median victim's stealer record count rose from 2 to 7, while older credential stuffing findings collapsed from 68.1% to 15.1% as the access economy traded recycled breach dumps for freshly harvested credentials.
Set the two populations side by side and the insight sharpens into a warning. The exposure type growing fastest among the companies that get hit is precisely the one the Top 1000 has not reduced in two years. The latter group's patching progress addresses the doors attackers have always used. Their credential exposure feeds the market attackers are moving toward.
Stealer Log Findings Among Victims Rose From 25% to 41.8% as Credential Stuffing Collapsed to 15.1%
Misconfiguration remained the most common finding in every year at 71% or above, and exposed remote access ports held near 50% throughout.
The Distribution Fleet: Stronger on Average, Exposed at the Edges
The 2,289 monitored trucking, freight arrangement, and warehousing companies present a healthier average posture than the Top 1000 manufacturers. The average RSI across the population is 0.388, just below the critical threshold, and 55.2% hold an A-range cyber rating.
The average Data Breach Index is 0.088, against 0.178 for the manufacturing tier, a gap that reflects how much less breach history accumulates around smaller companies with shallower data footprints.
The exposure signals available for this population are narrower than the Top 1000's finding set, but they point in a consistent direction. 42% of the fleet, 962 companies, sits above the critical RSI threshold, 16.3% carries at least one KEV-listed vulnerability, 11.8% holds an active campaign FocusTag®, and 21.3% has a small digital footprint, which means part of this population's healthier average reflects how little there is to scan rather than how well it is defended.
42% of the Distribution Fleet Sits Above the Critical RSI Threshold
21.3% have a small digital footprint, which means part of this population's healthier average reflects how little there is to scan.
The averages hide the edges. Those 372 companies carrying a KEV-listed vulnerability and the 270 holding an active campaign FocusTag® are the fleet's most immediate ransomware candidates, and in an industry of thin margins and contractual delivery windows, they represent the segment that warrants the closest monitoring for near-term ransomware risk.
Campaign exposure in particular does not sample the fleet at random. The 270 tagged companies average an RSI of 0.512, with 82.2% above the critical threshold, against 0.372 for the rest of the population. Each new campaign lands on the companies already carrying the most exposure.
08 The Cascade Runs Both Directions: Manufacturing in the Supply Chain
Manufacturing does not sit at the edge of the supply chain problem. It sits in the middle of it.
When a manufacturer appears on a leak site, the event does not end at its own gate. It lands, the same day, inside the vendor lists of every company that depends on its output.
Manufacturing has been the most attacked industry for five consecutive years, and its weight grows with the size of the buyer. The mid-market manufacturing companies that carry most of the attack volume, with a median revenue of $42.9 million, are precisely the tier from which larger enterprises source components, materials, and finished goods.
The Downstream Cascade: When One Manufacturer Disrupts More Than 5,000 Organizations
Jaguar Land Rover's cyberattack, covered in the case study above, is the clearest example of this pattern: a single manufacturer's August 2025 breach disrupted more than 5,000 organizations across its supply chain and measurably slowed UK GDP growth. Production stopped for more than five weeks at the three UK plants that together build roughly 1,000 vehicles a day. Weekly disruption was near £50 million.
The incident's financial impact is estimated at £1.9 billion across more than 5,000 affected organisations, most of which were small and medium-sized tier suppliers woven into JLR's production network. One supplier, Coventry-based Evtec Group, placed 900 employees on short-time work at reduced pay during the stoppage and estimated its own loss at £13 million.
JLR sits in Transportation Equipment, the one subsector where enterprise targeting intensified while the rest of the market moved downmarket. For the 5,000 organisations in the blast radius, the third party that failed was not a software vendor or a cloud platform. It was a manufacturer.
The Upstream Cascade: One Vendor, Hundreds of Manufacturers
The same dynamic works in reverse, and 2025-2026 provided the clearest demonstrations on record. Clop's campaign against Cleo, a managed file transfer platform used by thousands of companies for data exchange and system integration, began with two critical vulnerabilities identified in late 2024 and ultimately produced nearly 400 disclosed victims.
This report's dataset captured the campaign: 128 manufacturing and 52 distribution victims disclosed in eight weeks, from a group that had recorded 11 manufacturing incidents in all of 2024.
The Oracle E-Business Suite campaign extended the model upmarket. It has the same operational pattern: One platform, one vulnerability, and many organizations exposed at once.
An organization cannot patch a vulnerability it does not own and for a manufacturer, a software vendor's exposed system is part of its own ransomware surface whether or not it appears on any asset inventory.
Goods exist commercially only as a flow. Software vendors feed manufacturers, manufacturers feed logistics providers, and logistics providers feed shelves. Direct attacks have not slowed, as the first chapter documented; the cascade evidence adds a second active front rather than replacing the first.
For third-party risk teams, the operational conclusion is to map both directions of the chain, the vendors a company depends on and the customers who depend on it, and to treat a manufacturer's or carrier's visible exposure as shared exposure.
09 The Regulatory Direction: Third-Party Cyber Risk Becomes a Legal Duty
For most of the past decade, assessing the cyber posture of suppliers was a maturity marker. Something well-run security programs did, and everyone else deferred. That era is closing. Across the three largest Western regulatory blocs, lawmakers are converting third-party cyber risk management from good practice into enforceable obligation, and manufacturing and distribution companies sit inside every one of these regimes.
The EU: NIS2 Names Manufacturing in Scope With Fines up to €10 Million
- The NIS2 Directive places manufacturing in scope by name: Machinery, motor vehicles and transport equipment, computers and electronics, electrical equipment, and medical device producers, alongside postal and courier services on the distribution side.
- Supply chain security is a mandatory risk measure. Regulated companies must manage the security of their relationships with direct suppliers, with fines up to €10 million or 2% of global turnover and personal liability reaching management.
- Most member states have now written the directive into national law. Germany's implementation has applied since December 2025 with no transition period, and Italy's cybersecurity agency requires regulated companies to identify and register the suppliers relevant to their critical processes. These are not incidental examples. Germany and Italy are also the two European countries with the most manufacturing ransomware victims in this report's data.
- The Cyber Resilience Act adds product-level obligations for manufacturers of connected devices, with first reporting duties from September 2026 and full requirements in 2027.
The UK: Cyber Security and Resilience Bill Regulates JLR's Suppliers, Not JLR
- The Cyber Security and Resilience Bill was introduced in November 2025, weeks after the Jaguar Land Rover (JLR) shutdown, and is aimed squarely at the supply chain.
- Roughly a thousand managed service providers come under direct regulation for the first time; regulators gain the power to designate critical suppliers, who must then meet the same security and reporting standards as the companies they serve.
- Ransomware incidents become reportable within 24 hours, with penalties up to £17 million or 4% of global turnover.
- The gap is instructive. Manufacturers like JLR themselves remain outside the bill's direct scope, a point acknowledged in the parliamentary debate. The incident that accelerated the law is the kind of incident the law does not cover.
The US: CMMC Regulates American Manufacturing Through Procurement, Not Legislation
- The Cybersecurity Maturity Model Certification (CMMC) program, phasing into defense contracts since November 2025, makes third-party certification a condition of doing business with the Department of Defense and flows down through subcontractor tiers, regulating a large share of American manufacturing through procurement rather than legislation.
- Medical device manufacturers must now document the software components inside their products for the FDA.
- The pending CIRCIA rule names critical manufacturing and transportation systems among the sectors that will owe federal incident reports within 72 hours.
The least regulated node in the chain is the one that physically moves the goods. General freight trucking sits outside NIS2's core annexes, outside the UK bill's scope, and outside any binding US federal cyber mandate, even as couriers, ports, and rail face growing obligations.
The first part of this report showed distribution victims growing 26.7% beneath the campaign noise; the regulatory map shows almost no one is required to watch.
For manufacturers and distributors, the demanded capability converges from every direction. Know who your suppliers are, assess their security continuously rather than annually, and be able to report what happened within days or hours.
Next Steps: An Attack Surface This Active Needs Continuous Visibility
Three chapters of evidence converge on a single operational problem. The companies that make and move goods are attacked more each year, by an actor ecosystem that rebuilds itself faster than any assessment cycle, and the worst incidents no longer begin or end inside the victim's own network. A manufacturer inherits exposure from the software vendors above it and transmits its own downtime to the customers below it. Managing that reality calls for a vantage point most security programs do not have, because it sits outside the perimeter their internal controls were built to defend.
The regulatory direction reinforces the same point from a different angle. Whether through NIS2, the Cyber Resilience Act, a UK designation, or a US contract clause, the obligation to know and demonstrate a supplier's security has stopped being optional. The capabilities below are how a manufacturing or distribution company meets that obligation in practice, and each one answers a specific finding from the pages before it.
01 Rank Vendors by Risk Before Any Incident
One of the clearest findings in the report is that elevated ransomware susceptibility is common among disclosed victims. At disclosure, three out of four manufacturing victims were already in the critical RSI range. This means supplier populations can be prioritized by observable ransomware susceptibility rather than treated as uniformly risky.
Black Kite's Ransomware Susceptibility Index® (RSI™) produces that ordering. A score from 0.0 to 1.0 estimating the likelihood of a ransomware attack, built from technical exposure and intrinsic factors such as industry, location, and size, and calibrated against thousands of confirmed victims. It tells a risk team which suppliers to question first instead of spreading the same attention across all of them.
02 Measure Suppliers Against the Conditions Attackers Select for Today
This report portrayed an ecosystem that swapped out nearly half its active groups in two years. Any defense pinned to a named adversary ages quickly, because the group topping the sector this quarter may be one that did not exist twelve months ago.
Rather than track names, Black Kite's Cyber Rating monitors the conditions attackers actually select for, continuously and automatically across 20 risk categories. A supplier is measured against what makes a company reachable now, and the measurement refreshes as posture changes rather than freezing at the last review.
03 See the Vendor Ecosystem Behind Your Suppliers
The Jaguar Land Rover cascade reached more than 5,000 organizations through a single manufacturer, and the Cleo campaign reached hundreds of manufacturers through a single file transfer vendor. Concentration risk of this kind stays invisible until one shared vendor fails, and dozens of companies can sit behind a single supplier without any of them knowing it.
Black Kite's Supply Chain Module maps Nth-party dependencies, surfaces concentration risk, and identifies the shared vendors that would cascade across a peer group if compromised. Assessing what that map returns is the second problem, and Black Kite's AI-Powered Cyber Risk Assessments read vendor documentation, including SOC 2 reports and questionnaires, extract verbatim evidence, identify gaps, and map findings to the frameworks an organization is held against.
04 Reach Exposed Vendors While the Window Is Open
The exposure map found active campaign risk stacked on a few hundred companies, with each new wave landing on those already exposed to the previous one. Every disclosure opens a gap between the moment a flaw goes public and the moment anyone acts, and that gap is where attackers operate.
Black Kite's FocusTags® name the specific vendors hit by a given vulnerability or campaign the moment it is flagged, so a team can move on the exposed suppliers first, while the window still matters.
05 Replace Annual Reviews With Continuous Monitoring
Our latest Ransomware report shows that a victim's exposure rarely closes when its incident does, and that a supplier's posture shifts continuously between assessments. A point-in-time review is accurate only on the day it is taken, and the interval until the next one is exactly where new exposure appears unseen.
Continuous monitoring closes that gap by catching a supplier's decline as it happens, leaving time to engage the vendor while the problem is still contained. It is also what the NIS2 Article 21 supply chain duty assumes: An obligation that is continuous cannot be met with a point-in-time check.
06 Translate Downtime Into Terms the Board Acts On
This report measured cyber risk in stopped production lines and missed deliveries, and for manufacturers and distributors that operational cost is the real exposure. Boards and regulators act on that figure, not on technical scores.
Black Kite quantifies cyber risk through Open FAIR™ modelling, translating a vendor's posture into probable financial impact. Its business interruption view expresses a supplier outage as expected days of downtime and an annualized loss figure, which is the language a manufacturer's board already uses and the one the regulatory regimes increasingly require.
Get Ahead of Vendor Risk With Black Kite
Every exposure in this report was measured from the outside, the same vantage point available to any attacker, or any customer, right now. The manufacturers and distributors that stay resilient will be the ones that treat third-party risk as a continuous, predictive, and measurable discipline, and build the capability to act on it before the breach notification arrives. Black Kite is built to provide that baseline.
10 Methodology: How Black Kite Built the 2026 Manufacturing and Distribution Ransomware Report
1. Data Sources and Scope
The report integrates several streams of intelligence curated by the Black Kite Research Group™ between January 1, 2023 and July 29, 2026. The ransomware data covers confirmed, publicly disclosed ransomware and data extortion incidents, retained once an incident was ready for publication, with attribution to a named threat group recorded where it could be established. Population exposure data was derived from Black Kite's telemetry, assessed from the outside using non-intrusive, attacker's-perspective methods that require no questionnaires and no vendor cooperation, current as of August 2026.
2. Industry Scope and Temporal Basis
The report covers two connected industries, analysed separately throughout and combined only where explicitly noted. Manufacturing comprises the North American Industry Classification System (NAICS) sectors 31 to 33. Distribution comprises the goods-movement segments of Transportation and Warehousing: General freight trucking, specialized freight trucking, freight transportation arrangement, warehousing and storage. The working base is 5,237 disclosed victims, 4,780 in manufacturing and 457 in distribution. Because the 2026 data covers January 1 to July 29 only, every year-over-year comparison uses the same January-to-July window in each year, expressed throughout as a same-period comparison.
3. Ransomware Victim Data
Ransomware victims were identified through continuous monitoring of leak sites, extortion posts, and dark web sources, then validated against open-source intelligence and Black Kite's internal telemetry. The dataset includes only publicly disclosed victims; incidents settled privately or never disclosed are not captured, which makes this a conservative baseline rather than a complete count of all ransomware activity.
To prevent inflation of the figures, a standard incident-counting methodology was applied. Attacks against a holding company and its subsidiaries were treated as a single incident where they represented one campaign, unless distinct disclosures existed. Where a subsidiary was the named victim, revenue reflects the subsidiary rather than the parent.
4. External Exposure Data
Exposure findings were produced by Black Kite's platform, which assesses each company's security posture from the outside using non-intrusive, attacker's-perspective methods, with no questionnaires and no vendor cooperation required. Two populations were scanned, with data current as of August 2026:
- The Top 1000 comprises manufacturers with annual revenues above $1 billion drawn from ten NAICS sub-sectors.
- Chemicals (325)
- Transportation Equipment (336)
- Computer and Electronic Products (334)
- Nonmetallic Minerals (327)
- Petroleum and Coal Products (324)
- Food (311)
- Primary Metals (331)
- Plastics and Rubber (326)
- Furniture (337)
- Textile Mills (313)
The company list was verified against the Usearch company database, following the same selection criterion used in Black Kite's 2024 and 2025 manufacturing studies. The cohort held 1,049 companies at the August 2026 scan, against 1,042 in 2025 and 1,039 in 2024. "Top 1000" is a label for this cohort rather than a literal ranking of the 1,000 largest manufacturers, and because the cohort covers ten of the industry's twenty-one sub-sectors, its composition differs from the victim dataset, which spans the full sector.
- The distribution population comprises 2,289 monitored companies classified under NAICS 4841, 4842, 4885 and 4931, covering general and specialized freight trucking, freight transportation arrangement, and warehousing and storage, drawn from the platform as of the August 12, 2026 scan.
5. Limitations
The report reflects only publicly disclosed incidents and observable exposure indicators. Many breaches, particularly those involving smaller companies or resolved discreetly, go unreported, making this a conservative lower bound rather than a complete count. Threat actor attribution reflects leak-site claims and adopts each actor's self-styled name.
11 Frequently Asked Questions About Manufacturing Ransomware
Related Resources
- 2026 Ransomware Report: Cross-industry view of the same threat ecosystem, covering 7,551 victims across all sectors from April 2025 through March 2026.
- 2026 Europe Cyber Risk Report: Extends the European surge behind this report's fastest-growing geography, including SafePay's concentration on German targets.
- 2026 Mid-Market Report: Full analysis of the revenue tier that now absorbs 70.2% of manufacturing ransomware attacks.
- 2025 Supply Chain Vulnerability Report: The vulnerability prioritization research behind the upstream cascade chapter, including the Cleo campaign.
- 2026 Wholesale & Retail Cyber Risk Report: Cyber exposure across the retail and wholesale layer that receives what manufacturing and distribution produce.