[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fr8trl8seM2IIbQSuyKsC0nTTNLEcpMju5G7fXUbkSgI":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"88d6d7d7-c499-49d6-bf91-d8b8a17569eb","Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows","ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows-263c51","Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.","Ransomware attacks targeting the manufacturing sector have increased by 40% in early 2026, with threat actors exploiting supply chain vulnerabilities. The Jaguar Land Rover incident, which caused significant production halts and job losses, highlights the severe economic impact, estimated at £1.9 billion in the UK. Mid-sized manufacturers are particularly targeted as they form a critical part of larger enterprises' supply chains.","Ransomware attacks on manufacturers surged 40% in early 2026, exploiting supply chain disruptions.","Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year. Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack. The UK’s Cyber Monitoring Centre estimated a £1.9 billion financial impact and described the incident as the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak. It is a vivid example of the potential consequence of ransomware incidents within the manufacturing sector. The Black Kite 2026 Manufacturing & Distribution Ransomware Report believes this long tail of severe consequence is a primary reason for manufacturing continuing to be a primary ransomware target. Manufacturing “The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products. When the mid-market is the primary target, a large manufacturer’s vendor list is its attack surface,” says the report. From January 2023 to July 2026, the firm identified 5,237 disclosed ransomware victims across the two associated groups. “What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” adds Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses.”Advertisement. Scroll to continue reading. The first seven months of 2026 recorded 1,183 new incidents – a 40% increase over the same period in 2025. The number of ransomware groups is also climbing: half of these attacks were performed by groups that didn’t exist two years ago. A single new group (The Gentlemen) was responsible for 12% of this year’s attacks. The Gentlemen was first noticed by Black Kite in September 2025 and had claimed 142 manufacturing victims by mid-2026. The current hierarchy of ransomware actors is Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom. Europe is increasingly targeted. While the number of US attacks this year was almost identical to that of 2025; there was an 85% growth in European targets. As a result, the volume of attacks in the US dropped from the previous 52% to a current 35%. Despite the shift in percentages, the US remains the most targeted region with 412 attacks. Europe totaled 369 attacks, and attacks against the rest of the world almost doubled to 402. The surge in European attacks focused on Germany (77 attacks), where manufacturing in 2024 accounted for 20% of the national economy. The SafePay group accounted for 22% of 2025 attacks and remains among the country’s most active groups in 2026. Other primary European ransomware victim nations include Italy (57), UK (43) and France (40). Distribution The distribution sector is distinct from the manufacturing sector. “Trucking companies, freight arrangers, and warehouse operators form their own industry with their own attack surface, and they occupy a distinct position in the supply chain. They are the layer where many companies’ goods concentrate in one place, which is precisely what makes the sector consequential beyond its size.” Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference The attacks against distribution are lower in volume while the victims are smaller in size than in the manufacturing sector. The volume peaked in 2025 following a Clop campaign in January and February of that year, accounting for 52 victims and more than 25% of the year’s total. This distorts the underlying growth in attacks: 95 in the first half of 2026 against 196 for 2025. But without the Clop campaign, the underlying growth pattern continues, from 75 to 95 incidents during the same period in 2025 and 2026. The attraction of these two sectors is that they both provide supply chain potential to the attackers, thus magnifying the impact and potential negotiating power. Downstream, the Jaguar Land Rover incident affected 5,000 other organizations. Upstream, the Clop attack against Cleo ultimately produced nearly 400 disclosed victims. But supply chain victims are innocent – they do not own and cannot patch the vulnerabilities that lead to their victimization. Lawmakers are recognizing this and attempting to break the chain. The UK’s Cyber Security and Resilience Bill (CSRB) provides an example. It seeks to protect the critical infrastructure from supply chain effects by allowing ministers to block downstream supply from providers it considers high risk. This forces the supply chain to improve its security or lose its customer. The underlying problem remains and is forcefully illustrated by Black Kite’s report: ransomware attacks are consistently increasing in volume, and the number of attackers continues to grow. At the same time, the evermore complex interconnectivity of expanding economies grows the attack surface and increases the risk. If Black Kite’s figures are correct, there is little indication that anything will change in the foreseeable future. Related: Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping Related: Masimo Manufacturing Facilities Hit by Cyberattack Related: Cyberattack Disrupts Microchip Technology Manufacturing Facilities Related: Simpson Manufacturing Takes Systems Offline Following Cyberattack Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media$1 Million Sandbox Challenge Uncovers Linux Kernel FlawsThe Race to Control AI and Protect What Makes Us HumanCISOs Race to Control AI Agents Without Destroying Their ValuePhishing Research Challenges Conventional Security Awareness TestingKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data GovernanceHacker Conversations: Vinnie Liu, Performer Turned RingmasterDeceptive Android Apps Exploit Google Play Early Access to Evade Reviews Latest News Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security UpdateCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure DefensesAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayFirst Agentic AI Data Breach Reported to Spanish Regulator Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use","https:\u002F\u002Fwww.securityweek.com\u002Fransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FAI-artificial-intelligence-industrial-OT-ICS.webp","2026-09-17T12:29:53+00:00","2026-09-17T14:00:22.378564+00:00",8,[18,21,24,27,29,31],{"name":19,"type":20},"WannaCry","product",{"name":22,"type":23},"Jaguar Land Rover","vendor",{"name":25,"type":26},"The Gentlemen","threat_actor",{"name":28,"type":26},"Qilin",{"name":30,"type":26},"Akira",{"name":32,"type":26},"DragonForce","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":33,"icon":35,"name":36,"slug":37},null,"Ransomware","ransomware",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":58,"value":19,"context":59},"malware","Mentioned as a benchmark for economic damage from cyberattacks"]