Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
gradient ecosystem background

2025 Manufacturing Report

Manufacturing Is Ransomware's #1 Target for a Fourth Consecutive Year, and 75% of Suppliers Carry Critical Vulnerabilities

2025 manufacturing report headline

(No download required)

For the fourth year running, manufacturing sits at the top of every ransomware group's target list. Between April 2024 and March 2025, the sector absorbed 1,314 confirmed attacks, 22% of every publicly disclosed ransomware incident tracked globally.

The Black Kite Research Group™ analyzed 1,042 manufacturing companies with more than $1 billion in annual revenue across 10 NAICS sub-sectors, from chemical and transportation equipment manufacturing to food, textiles, and furniture. Every company was scored using the same external, attacker's-eye telemetry that powers the Ransomware Susceptibility Index® (RSI™), giving cybersecurity leaders a view of their suppliers that matches what threat actors already see.

The data gets worse the deeper you look. 75% of manufacturers carry at least one critical vulnerability with a CVSS score of 8 or higher, and 65% have a flaw listed in CISA's Known Exploited Vulnerabilities catalog, meaning attackers are already using it against real targets.

Companies scoring in the highest RSI risk band are 96 times more likely to suffer a ransomware attack than those in the lowest band, and almost every manufacturing sub-industry now averages a score inside that high-risk zone.

This report is your blueprint for moving manufacturing third-party risk programs from reactive patching to predictive, intelligence-led defense.

(No download required)

Key Findings From the 2025 Manufacturing Report

Manufacturing Absorbed 1,314 Ransomware Attacks, 274 More Than the Next Closest Industry

Manufacturing has held the #1 spot for ransomware victims for four straight years, and the gap isn't closing. The sector logged 1,314 attacks against 1,040 for professional and technical services, the second-most targeted industry, a lead of 274 incidents.

Attacks weren't concentrated in one corner of the sector either. Machinery manufacturing took the largest share at 13%, followed by fabricated metal products at 12% and food and beverage manufacturing at 11%, with the remaining share spread almost evenly across every other sub-industry Black Kite tracked. Attackers care less about what a manufacturer makes than about where it sits inside a global supply chain.

38.9% of Ransomware Victims Above $1 Billion in Revenue Are Manufacturers

Bigger companies aren't buying safety. Manufacturing accounts for 38.9% of ransomware victims among companies earning more than $1 billion a year, the highest share of any industry in that revenue bracket. At the $100 million to $300 million tier, manufacturing still leads at 30% of victims.

Newer, less organized ransomware groups that emerged after LockBit and ALPHV's disruption have also started favoring smaller contractors as an entry point. They use those contractors to gain a foothold inside larger manufacturing ecosystems rather than attacking the prime target directly.

Companies With an RSI Score Above 0.8 Are 96 Times More Likely to Be Hit

Black Kite's predictive risk data shows exactly where the next attack is likely to land. Companies with an RSI value between 0.8 and 1.0 are 96 times more likely to experience a ransomware attack than companies scoring below 0.2.

Nearly every manufacturing sub-industry now averages a score of 0.4 or higher, putting the sector as a whole inside the elevated risk band. Furniture and related product manufacturing carries the highest average RSI at 0.526, while petroleum and coal products manufacturing sits lowest at 0.363, still well inside meaningfully elevated territory.

75% of Manufacturers Carry Critical Vulnerabilities Their Cyber Ratings Don't Show

Most manufacturing companies score an A or B on standard cyber ratings, a result that looks reassuring until you check what's underneath it. 75.4% have at least one critical vulnerability rated CVSS 8 or above, and 64.7% carry a flaw from the CISA Known Exploited Vulnerabilities catalog, meaning it's already being used in active attacks.

Two indicators moved sharply worse in the past year. Data breaches in the last 90 days jumped 104.4%, and companies experiencing a ransomware attack rose 9.1%. Credential exposure, by contrast, actually improved. Leaked credentials fell 78.4% year over year, though 14.8% of manufacturers still had a leak in the last 90 days.

Patch Management Failures Leave Most Sub-Industries Scoring D or F

Beneath the surface-level ratings, the sector's foundational security controls are failing at scale. Patch management is the weakest control Black Kite measured, with most sub-industries scoring D or F. 

Roughly 30% of manufacturers sit in the critical zone for application security, and stealer log exposure runs even higher in specific pockets. 73% of computer and electronic product manufacturers show critical stealer log findings, meaning employee credentials tied to their domains are already circulating on the dark web, exactly the blind spot dark web monitoring is built to catch.

Key Stats:

0
ransomware attacks on manufacturing in one year
0%
of every publicly disclosed ransomware victim, worldwide
0.0%
of $1B+ revenue ransomware victims are manufacturers
0x
higher attack likelihood at an RSI score above 0.8
0%
carry a critical CVSS 8+ vulnerability
0%
carry an actively exploited CISA KEV vulnerability
0%
of computer and electronic product manufacturers have exposed credentials in stealer logs

Ransomware's Fourth Straight Year Targeting Manufacturing's Supply Chain

Machinery, Fabricated Metal, and Food and Beverage Manufacturers Take the Brunt of the Attacks

Within manufacturing, no single sub-industry is safe. Machinery manufacturing absorbed the largest share of attacks at 13%, with fabricated metal products close behind at 12% and food and beverage manufacturing at 11%.

Computer and electronic product manufacturing, chemical manufacturing, and transportation equipment manufacturing each carried a meaningful share as well. The near-even distribution confirms what Black Kite's 2025 Ransomware Report found across the broader threat environment. Ransomware groups target function and centrality inside a supply chain, not a specific product line.

Large Enterprises Remain the Prime Target, but Smaller Contractors Are the New Foothold

The demise of dominant groups like LockBit and ALPHV opened a power vacuum that dozens of newer, less coordinated ransomware operators rushed to fill. These newer groups tend to favor smaller companies, but large manufacturing enterprises are still squarely in the crosshairs, accounting for the greatest share of attacks on companies earning $100 million to $1 billion or more.

That means manufacturers are getting hit from both directions at once. Established groups are still chasing high-value targets, while newer groups use smaller, less-defended contractors as a way into the larger ecosystem those contractors serve, which is exactly the blind spot Nth-party visibility is built to close.

The United States Absorbs More Than Half of Global Manufacturing Ransomware Attacks

Geography concentrates the risk further. The United States accounted for 682 of the manufacturing ransomware attacks Black Kite tracked, 52% of the global total.

Canada, Germany, and Italy followed at a fraction of that volume, each in the 60 to 75 attack range. For any manufacturer with U.S. operations or U.S.-based suppliers, that concentration should shape how third-party risk programs prioritize monitoring.

An RSI Score of 0.4 to 0.6 Already Means an 11.6x Higher Ransomware Risk

Historical attack data explains what already happened. RSI scoring is built to answer a harder question. It shows what's likely to happen next.

An RSI score between 0.4 and 0.6 already carries an 11.6x higher likelihood of a ransomware attack compared to companies below 0.2, and that multiplier keeps climbing at every band above it. With nearly every manufacturing sub-industry averaging inside that elevated zone, continuous monitoring of supplier RSI trends has become less of a nice-to-have and more of a baseline requirement.

Cyber Ratings Miss the Active Threats Hiding in Manufacturers' Networks

Most Manufacturers Score an A or B, Yet 75% Carry a Critical Vulnerability

Standard cyber ratings paint a flattering picture of the sector. Most manufacturing companies land in the A or B range, the kind of score that would make any risk team feel comfortable.

That comfort is misplaced. Key risk indicators, the forward-looking metrics that function as an early warning system, tell a very different story once you look past the letter grade and into what's actually running on a company's network.

65% of Companies Have at Least One Actively Exploited CISA KEV Vulnerability

Nearly two-thirds of manufacturers, 64.7%, carry at least one vulnerability listed in the CISA Known Exploited Vulnerabilities catalog. Every entry on that list represents a flaw confirmed to be under active exploitation, not a theoretical risk.

A company can hold a strong overall rating and still be running software with a documented, in-the-wild exploit sitting on its network. That gap between the letter grade and the underlying reality is where most breaches start.

Data Breaches in the Last 90 Days Surged 104.4% Year Over Year

Not every trend in this year's data moved in the wrong direction. Manufacturers actually cut leaked credentials by 78.4% year over year, though 14.8% still had a credential exposed in the last 90 days.

The metric that got worse, sharply, is data breaches. Companies reporting a breach in the last 90 days rose 104.4% year over year, and the share experiencing a ransomware attack climbed 9.1%. Both point the same direction. Incidents are accelerating even as some individual controls improve.

Broken SSL/TLS Encryption Still Affects More Than Half the Sector

Encryption failures remain widespread. 55.2% of manufacturers have broken cryptographic implementations in their SSL/TLS configurations, a foundational weakness that undermines the security of every transaction and communication that depends on it.

Combined with the sector's KEV exposure, it points to the same root cause across multiple controls. Basic security hygiene isn't keeping pace with how fast the threat environment is moving.

Where the Manufacturing Supply Chain Breaks Down, Control by Control

Patch Management Is the Sector's Weakest Control, With Most Sub-Industries Scoring D or F

Patch management is a foundational piece of any secure environment, and it's where manufacturing performs worst. The majority of companies across nearly every sub-industry scored D or F, evidence of outdated servers and unpatched products running in production.

Chemical, transportation equipment, and computer and electronic product manufacturing carried the largest absolute number of poor scores, though the pattern held across smaller sub-industries too. Unpatched, internet-facing assets remain one of the most direct paths into a manufacturer's network, which is exactly the gap a supply chain cyber risk management program is meant to close.

Nearly a Third of Manufacturers Sit in the Critical Zone for Application Security

Applications are a primary attack vector, often the first point of entry for attackers looking to disrupt operations or steal data. Roughly 30% of manufacturing companies fall into the critical zone, a D or F score, for application security.

For an industry where operational continuity depends on production systems staying online, that gap in cyber risk assessments coverage represents real, unmitigated exposure.

Up to 73% of Computer and Electronic Product Manufacturers Have Credentials Circulating on the Dark Web

Stealer log findings reveal how deep credential exposure runs. Black Kite's analysis counted only the most severe findings, domains detected in both the username and password fields of a stolen credential file, or in the username field alone at a still-serious severity level.

Under that strict standard, 73% of companies in computer and electronic product manufacturing show a critical stealer log finding. Chemical manufacturing follows at 69%, and transportation equipment manufacturing at 61%. Every one of those credentials represents a potential foothold an attacker doesn't need to work to find. It's already for sale.

Microsoft Vulnerabilities Account for 29 of the Manufacturing Sector's Most Exploited CVEs

Across the 1,042 companies analyzed, Black Kite identified 674 with at least one CISA KEV vulnerability, spanning 102 unique CVEs. Microsoft products accounted for 29 of those vulnerabilities, more than five times the next closest vendor, with Microsoft Windows alone tied to 16.

Seventeen of the 102 CVEs have been confirmed in use by named ransomware campaigns, including LockBit, ALPHV, Babuk, Conti, and BlackByte. The remaining 85 are confirmed active exploits that haven't yet been tied to a specific ransomware group publicly, meaning they could be weaponized by a new operator at any time.

Black Kite's Adversary Susceptibility Index™ (ASI™) maps these threat actors directly to a company's vendor ecosystem, showing which suppliers are exposed to which groups' confirmed tactics. Manufacturers evaluating CVEs at this scale can apply the same discoverability-and-exploitability framework Black Kite used in the 2026 Supply Chain Vulnerability Report to cut through vulnerability noise and focus on what's actually reachable by an attacker.

Four Shifts That Move Manufacturers From Reactive Patching to Predictive Risk Management

Replace Point-in-Time Cyber Ratings With Continuous Key Risk Indicator Monitoring

A strong letter grade isn't a safety guarantee. This report shows companies scoring A or B still carrying CVSS 8+ vulnerabilities and CISA KEV exposure at rates above 65%.

Security teams need visibility into the underlying key risk indicators, not just the aggregate score, and they need vendor risk monitoring that updates continuously rather than at the next scheduled review.

Map Every Supplier's RSI Score Before the Next Campaign Hits

With companies at the highest RSI band 96 times more likely to be hit, waiting for an attack to reveal which suppliers are exposed isn't a strategy. Manufacturers should map every third party's RSI score now.

Prioritize outreach to the highest-risk vendors first, and track how those scores trend over time rather than treating them as a one-time checkbox.

Enforce Same-Day Response Inside the Window a Disclosure Opens

Patch management and application security were this report's two weakest controls by a wide margin. Any vendor risk evaluation process that doesn't weight these two controls heavily is missing the two areas most likely to produce an actual breach.

Map the Vendor Ecosystem You Haven't Inventoried

Newer ransomware groups are deliberately using smaller, less-defended contractors as a way into larger manufacturing ecosystems. A third-party risk management solution that reserves its deepest scrutiny for the largest vendors by contract value is leaving exactly the gap these groups are exploiting.

Supply chain risk scales with a supplier's access and centrality, not its size.

How Black Kite Built the 2025 Manufacturing Report

1,042 Manufacturing Companies Analyzed Across 10 NAICS Sub-Sectors

The Black Kite Research Group analyzed 1,042 companies with annual revenues exceeding $1 billion, selected from 10 NAICS sub-sector codes spanning chemical, transportation equipment, computer and electronic product, food, primary metal, plastics and rubber, nonmetallic mineral, petroleum and coal, furniture, and textile manufacturing.

The company list was verified using the Usearch database to ensure consistency across the sample.

External, Non-Intrusive Scans Deliver an Attacker's View of Every Supplier

Every company in the sample was assessed using Black Kite's external, non-intrusive scanning method, the same approach an attacker would use to evaluate a target before striking.

That approach identifies attack surface, vulnerabilities, and overall risk level without requiring any cooperation or access from the company being assessed, enabling consistent, comparable analysis across all 1,042 organizations.

674 Companies Cross-Referenced Against the CISA KEV Catalog

Ransomware-related data spans April 2024 through March 2025 and includes only publicly disclosed attacks attributed to a known ransomware group. Vulnerability findings were cross-referenced against the CISA Known Exploited Vulnerabilities catalog, surfacing 674 companies with at least one confirmed actively exploited flaw.

A standardized incident-counting methodology treated attacks against a holding company and its subsidiaries as a single incident unless distinct disclosures existed, preventing inflated attack counts.

A Conservative Lower Bound Built From Publicly Disclosed Incidents Only

This report reflects only publicly disclosed ransomware incidents and externally observable risk indicators. Many breaches, particularly those involving smaller organizations or resolved discreetly, go unreported.

The findings represent a conservative floor for the sector's true third-party risk exposure, and because the analysis is built entirely from an external perspective, internal security controls and policies at any individual company fall outside its scope.