Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Black Kite reports manufacturing ransomware incidents up 40% in 2026, with new gang The Gentlemen responsible for 12% of attacks.
Black Kite's 2026 Manufacturing & Distribution Ransomware Report counted 1,183 disclosed incidents in the first seven months of 2026, a 40% year-over-year increase, led by Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom. The Gentlemen, first observed in September 2025, claimed 142 manufacturing victims and was behind 12% of this year's attacks. European targeting grew 85%, with Germany (77), Italy (57), UK (43), and France (40) as top victims. The report cites the Jaguar Land Rover attack, estimated by the UK Cyber Monitoring Centre at £1.9 billion in impact with 4,000 announced job cuts, as the most economically damaging cyberattack in UK history.
- 1,183 manufacturing/distribution ransomware incidents in first seven months of 2026, up 40% year-over-year
- Half of attacks came from groups that did not exist two years ago
- European attacks grew 85% while US share fell from 52% to 35%
- Jaguar Land Rover attack disrupted ~1,000 vehicles daily and affected 5,000+ companies
- UK Cyber Security and Resilience Bill aims to curb downstream supply chain risk
Full article915 words · extracted from securityweek.com · click to collapse
Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year.
Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack.
The UK’s Cyber Monitoring Centre estimated a £1.9 billion financial impact and described the incident as the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak. It is a vivid example of the potential consequence of ransomware incidents within the manufacturing sector.
The Black Kite 2026 Manufacturing & Distribution Ransomware Report believes this long tail of severe consequence is a primary reason for manufacturing continuing to be a primary ransomware target.
Manufacturing
“The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products. When the mid-market is the primary target, a large manufacturer’s vendor list is its attack surface,” says the report. From January 2023 to July 2026, the firm identified 5,237 disclosed ransomware victims across the two associated groups.
“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” adds Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses.”
Advertisement. Scroll to continue reading.
The first seven months of 2026 recorded 1,183 new incidents – a 40% increase over the same period in 2025. The number of ransomware groups is also climbing: half of these attacks were performed by groups that didn’t exist two years ago. A single new group (The Gentlemen) was responsible for 12% of this year’s attacks.
The Gentlemen was first noticed by Black Kite in September 2025 and had claimed 142 manufacturing victims by mid-2026. The current hierarchy of ransomware actors is Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom.
Europe is increasingly targeted. While the number of US attacks this year was almost identical to that of 2025; there was an 85% growth in European targets. As a result, the volume of attacks in the US dropped from the previous 52% to a current 35%. Despite the shift in percentages, the US remains the most targeted region with 412 attacks. Europe totaled 369 attacks, and attacks against the rest of the world almost doubled to 402.
The surge in European attacks focused on Germany (77 attacks), where manufacturing in 2024 accounted for 20% of the national economy. The SafePay group accounted for 22% of 2025 attacks and remains among the country’s most active groups in 2026. Other primary European ransomware victim nations include Italy (57), UK (43) and France (40).
Distribution
The distribution sector is distinct from the manufacturing sector. “Trucking companies, freight arrangers, and warehouse operators form their own industry with their own attack surface, and they occupy a distinct position in the supply chain. They are the layer where many companies’ goods concentrate in one place, which is precisely what makes the sector consequential beyond its size.”
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
The attacks against distribution are lower in volume while the victims are smaller in size than in the manufacturing sector. The volume peaked in 2025 following a Clop campaign in January and February of that year, accounting for 52 victims and more than 25% of the year’s total. This distorts the underlying growth in attacks: 95 in the first half of 2026 against 196 for 2025. But without the Clop campaign, the underlying growth pattern continues, from 75 to 95 incidents during the same period in 2025 and 2026.
The attraction of these two sectors is that they both provide supply chain potential to the attackers, thus magnifying the impact and potential negotiating power. Downstream, the Jaguar Land Rover incident affected 5,000 other organizations. Upstream, the Clop attack against Cleo ultimately produced nearly 400 disclosed victims. But supply chain victims are innocent – they do not own and cannot patch the vulnerabilities that lead to their victimization. Lawmakers are recognizing this and attempting to break the chain.
The UK’s Cyber Security and Resilience Bill (CSRB) provides an example. It seeks to protect the critical infrastructure from supply chain effects by allowing ministers to block downstream supply from providers it considers high risk. This forces the supply chain to improve its security or lose its customer.
The underlying problem remains and is forcefully illustrated by Black Kite’s report: ransomware attacks are consistently increasing in volume, and the number of attackers continues to grow. At the same time, the evermore complex interconnectivity of expanding economies grows the attack surface and increases the risk. If Black Kite’s figures are correct, there is little indication that anything will change in the foreseeable future.

Related: Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping
Related: Masimo Manufacturing Facilities Hit by Cyberattack
Related: Cyberattack Disrupts Microchip Technology Manufacturing Facilities
Related: Simpson Manufacturing Takes Systems Offline Following Cyberattack
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/