Reports

Black Kite’s 2026 Manufacturing & Distribution Ransomware Report: Manufacturing Remains Ransomware’s Top Target

mm
Add Unite.AI to your preferred sources on Google

Black Kite’s 2026 Manufacturing & Distribution Ransomware Report: Still the #1 Target, but the Victim Profile Moved Downmarket and Overseas finds that ransomware pressure on manufacturers is not only increasing, but changing shape. The Black Kite Research Group analyzed thousands of publicly disclosed ransomware incidents from 2023 through July 2026, alongside current external exposure data from major manufacturers and distribution companies. Its findings point to a threat landscape that is expanding geographically, shifting toward mid-sized businesses, and increasingly capable of turning a single compromised company into a much larger supply chain disruption.

Manufacturing Continues to Stand Apart

Manufacturing has remained Black Kite’s most targeted industry for five consecutive years, and the pace of attacks continues to accelerate.

The first seven months of 2026 produced 1,183 disclosed manufacturing ransomware victims, already more than were recorded during all of 2023 or 2024. Compared with the same period a year earlier, attacks increased nearly 40%.

That persistence is particularly notable because manufacturing continued to grow as a target even during periods when law enforcement action disrupted some of the ransomware ecosystem’s largest operators.

The attraction is relatively straightforward. Unlike attacks against businesses where operations can sometimes continue while IT systems are restored, a cyberattack against a manufacturer can stop physical production. Missed shipments, idle workers, contractual penalties, and disrupted customers quickly increase the financial pressure on the victim.

That same dynamic makes manufacturing especially valuable to extortion groups. Every hour a production line remains offline can strengthen an attacker’s negotiating position.

The Typical Victim Is Getting Smaller

High-profile attacks against major global manufacturers often dominate headlines, but Black Kite’s data suggests the center of ransomware activity sits much further down the market.

The median manufacturing victim in the dataset generates $42.9 million in annual revenue. Companies between $10 million and $100 million accounted for roughly 70% of victims with known revenue in 2026.

Large enterprises remain targets, but their share of overall incidents has declined as attackers reach deeper into the mid-market.

This shift matters because many of these companies are not isolated businesses. Mid-sized manufacturers often supply components, equipment, chemicals, electronics, food products, and other inputs to much larger organizations.

As a result, an attack against a relatively unknown supplier can become a business continuity problem for companies many times its size.

The pressure is also broadly distributed across manufacturing. Machinery represented the largest individual subsector in Black Kite’s dataset, but fabricated metals, transportation equipment, chemicals, electronics, and food manufacturing all accounted for meaningful portions of incidents. No single niche dominates the threat landscape.

Ransomware Is Becoming More Global

The geographic makeup of manufacturing ransomware is changing almost as quickly as the victim profile.

The United States remains a major source of disclosed incidents, but its share of global manufacturing victims fell sharply in 2026. The decline was not primarily because attacks against American companies disappeared. Instead, ransomware activity expanded much faster elsewhere.

European manufacturing victims increased more than 85% in the comparable 2026 period, with Germany recording the region’s highest total. Italy, the United Kingdom, France, Spain, Turkey, and Poland also experienced substantial increases.

This matters particularly in economies where manufacturing represents a significant share of industrial output and employment. A successful attack can therefore have consequences extending beyond one company’s balance sheet.

The geographic shift is also being influenced by newer ransomware groups. The Gentlemen, for example, only appeared in Black Kite’s dataset in late 2025 but quickly became one of the most active operators targeting manufacturers, with a particularly visible role in Europe.

The Threat Actor Landscape Is Being Rebuilt

The rapid rise of newer groups is another defining feature of the report.

Nearly half of manufacturing incidents recorded in 2026 were attributed to threat actors that had not appeared in Black Kite’s dataset during 2023 or 2024. The number of groups targeting manufacturers has also expanded substantially.

Established names have not disappeared entirely, but the hierarchy is changing.

Qilin led manufacturing incidents during the first seven months of 2026, followed by The Gentlemen, Akira, DragonForce, and INC Ransom. Some previously dominant operators have declined sharply, while successor brands and entirely new groups have emerged.

For defenders, that turnover creates a practical challenge. Security strategies built around tracking a small set of recognizable ransomware groups can become outdated quickly. The underlying weaknesses attackers exploit, such as exposed remote access, unpatched vulnerabilities, stolen credentials, and misconfigured systems, may therefore be more useful indicators than the name of the group currently leading the rankings.

Distribution Creates Another Point of Failure

Black Kite extends its analysis beyond factories to the companies responsible for moving goods between them.

Trucking, freight arrangement, and warehousing companies recorded fewer ransomware incidents than manufacturers, but their position inside supply chains can make an individual disruption disproportionately important.

The report highlights the 2025 attack on UK logistics provider Peter Green Chilled. The company continued moving goods already inside its system, but new orders could no longer be processed. Because it served numerous major supermarket chains, the disruption quickly affected suppliers whose products were already sitting in warehouses or waiting to enter the network.

Distribution companies also tend to be smaller than manufacturing victims. Black Kite found a median annual revenue of $28.7 million among distribution victims with known revenue.

These businesses often operate with narrow delivery windows and limited tolerance for extended downtime, making ransomware particularly disruptive.

When a Cyberattack Becomes an Economic Event

The report uses Jaguar Land Rover’s 2025 cyberattack to demonstrate what can happen when ransomware reaches a company positioned at the center of a large industrial network.

Production stopped for more than five weeks across three UK plants, affecting facilities that collectively produce around 1,000 vehicles per day.

But the damage extended far beyond JLR.

More than 5,000 organizations were estimated to have been affected across the company’s broader ecosystem, many of them smaller suppliers. The estimated economic impact reached £1.9 billion, while the UK government introduced a £1.5 billion loan guarantee to help support JLR and its supply chain.

The disruption was significant enough to be cited by the Bank of England as one factor contributing to weaker-than-expected UK economic growth during the quarter.

It is an extreme example, but it illustrates the broader theme running throughout Black Kite’s research: manufacturing cyber risk rarely stays confined to the original victim.

Many Warning Signs Are Already Visible

One of the report’s more consequential findings is that many ransomware victims showed observable signs of elevated risk before their incidents became public.

Black Kite’s Ransomware Susceptibility Index evaluates factors including exposed services, exploitable vulnerabilities, leaked credentials, and other externally visible indicators.

Nearly three-quarters of manufacturing victims were already in the index’s critical range at the time their incidents were disclosed.

Current exposure among the world’s largest manufacturers also remains substantial. Black Kite found widespread critical vulnerabilities and leaked credentials across its monitored population, even as some measures of vulnerability management have improved.

Credential exposure stands out in particular. While organizations have made progress reducing certain software vulnerabilities, the prevalence of credentials circulating through stealer logs has remained stubbornly high.

That creates an attack surface that cannot necessarily be addressed through traditional patching alone.

Ransomware Is Now a Supply Chain Problem

The broader implication is that manufacturers can no longer treat ransomware purely as an internal cybersecurity issue.

A company inherits risk from the software providers, suppliers, and logistics firms it relies on. At the same time, its own cyber posture becomes part of the risk profile of every customer depending on its products.

Regulators are increasingly reflecting that interconnected reality. European rules such as NIS2 are placing greater emphasis on supply chain security, while UK and U.S. initiatives are expanding cybersecurity expectations across service providers, contractors, and critical suppliers.

For manufacturers, this means annual vendor questionnaires and isolated internal assessments may no longer be sufficient. The attack surface changes too quickly, as do the ransomware groups exploiting it.

Black Kite’s report ultimately describes a threat that is becoming broader rather than simply larger. Attacks are moving toward mid-sized companies, expanding internationally, and increasingly exploiting the connections between manufacturers, technology providers, logistics networks, and customers. The result is a ransomware problem where the most important question may no longer be whether one company can withstand an attack, but how much of the surrounding supply chain depends on it.

Antoine is a visionary leader and founding partner of Unite.AI, driven by an unwavering passion for shaping and promoting the future of AI and robotics. A serial entrepreneur, he believes that AI will be as disruptive to society as electricity, and is often caught raving about the potential of disruptive technologies and AGI.

As a futurist, he is dedicated to exploring how these innovations will shape our world. In addition, he is the founder of Securities.io, a platform focused on investing in cutting-edge technologies that are redefining the future and reshaping entire sectors.