A recent study conducted by Black Kite has underscored the significant threat posed by ransomware attacks within the manufacturing sector. The findings revealed that manufacturing organizations comprised more than 22% of all ransomware victims from April 2025 to March 2026. This alarming statistic makes the manufacturing industry the most targeted by ransomware attacks for the fifth consecutive year, highlighting a worrisome trend in cybersecurity vulnerabilities.
Further analysis indicates a staggering increase in ransomware incidents within the manufacturing realm, rising approximately 40% year-over-year during the period from January 1 to July 29, 2026. The number of reported ransomware events surged from 847 to 1,183 incidents, a clear indication of an escalating threat landscape. This increase continues a trend identified by the researchers, who have observed a steady rise in disclosed ransomware incidents in the manufacturing sector since 2022.
The manufacturing industry is perceived as a high-value target for ransomware actors for several crucial reasons. Firstly, the operational downtime caused by a successful ransomware attack can be devastating for these organizations, leading to considerable financial losses. This financial strain often compels affected companies to consider paying the extortion demands in order to resume normal operations. A striking example of the economic repercussions of such attacks was the incident involving Jaguar Land Rover (JLR) in 2025, which is reported to have cost the UK economy a staggering £1.9 billion (approximately $2.5 billion).
A second contributing factor to the vulnerability of the manufacturing sector is the increasing convergence of Information Technology (IT) and Operational Technology (OT). This integration has made it easier for cybercriminals to compromise industrial systems, broadening the attack surface available to threat actors. Such vulnerabilities necessitate heightened cybersecurity measures and awareness within the industry.
The Black Kite report, published on September 17, further reveals seismic growth in ransomware victims originating from European manufacturing. The research indicates an impressive 85.4% increase in the number of European manufacturing companies victimized by ransomware in the first seven months of 2026, rising from 199 incidents in 2025 to 369 in the current year. In contrast, the number of victims in the United States remained relatively stable, declining slightly from 443 incidents to 412. Consequently, the share of US manufacturing victims dropped from 52.3% to 34.8%, signaling a shift in the ransomware threat landscape.
Germany emerged as the dominant country in Europe for ransomware victims in the manufacturing sector, witnessing a rise from 42 to 77 incidents year-over-year during the first half of 2026. Italy followed closely, reporting 57 incidents, while the UK and France reported 43 and 40 victims, respectively. This substantial increase in European victims can be partially attributed to the activities of the SafePay ransomware group, which has been particularly focused on German manufacturing targets, according to the researchers at Black Kite.
Moreover, the report highlighted the growing influence of the ransomware actor known as The Gentlemen, which has increasingly targeted manufacturing entities. Victims within this sector constituted 23% of The Gentlemen’s leak site listings. Although this group was only first identified in September 2025, it has rapidly gained notoriety, claiming 142 victims in the first seven months of 2026—second only to the group Qilin, which tallied 178 victims during the same period.
As the manufacturing sector continues to face increasing ransomware threats, the urgent need for robust cybersecurity measures becomes ever more pressing. Companies within this field should not only bolster their defenses but also cultivate a culture of security awareness to combat the rising tide of cybercrime effectively. The findings of the Black Kite study serve as a pertinent reminder of the ongoing challenges that the manufacturing industry must confront in order to safeguard its operations and economic stability against the persistent threat of ransomware.

