Half Of This Year’s Manufacturing Ransomware Came From Groups That Did Not Exist Two Years Ago

Estimated reading time: 9 minutes

Jaguar Land Rover shut down its own global IT systems on 2 September 2025. Production stopped at three UK plants building roughly 1,000 vehicles a day, and stayed stopped for more than five weeks.

The UK’s Cyber Monitoring Centre rated it a Category 3 systemic event, put the financial impact at £1.9bn ($2.5bn), and counted more than 5,000 affected organizations. Most were small and medium-sized suppliers. The Bank of England’s November Monetary Policy Report named the attack as one of two reasons third-quarter GDP came in at 0.2% rather than the 0.3% it had forecast.

One company’s cyber incident moved a national economic indicator.

Black Kite’s 2026 Manufacturing and Distribution Ransomware Report, published 17 September, maps the pressure that produced it. The research covers 5,237 disclosed victims across manufacturing and distribution between January 2023 and July 2026.

Manufacturing Ransomware Set A Record Before August

The first seven months of 2026 produced 1,183 manufacturing victims. That is more than the whole of 2024.

Comparing the same January to July window each year strips out the partial-year problem. The count runs 319 in 2022, 505 in 2023, 593 in 2024, 847 in 2025, and 1,183 in 2026. Growth of 39.7% this year, on top of 42.8% the year before.

Manufacturing has ranked first for ransomware disclosures four years running, accounting for 22% of the 7,551 victims Black Kite tracked across all industries.

The US Share Collapsed Without The US Count Falling

The geography finding is the one most coverage will get backwards.

American manufacturers made up 52.3% of victims in the January to July window of 2025. This year they made up 34.8%.

The US count barely moved, from 443 to 412. European victims rose from 199 to 369, up 85.4%. The rest of the world rose from 205 to 402, up 96.1%.

American manufacturers are not safer. Everyone else is being hit more.

Germany leads Europe with 77 victims in seven months against 42 a year earlier, up 83.3%. Manufacturing generated 19.9% of German gross value added in 2024, against an EU average of 15.9%. SafePay, the group this publication covered in Black Kite’s European research in June for its concentration on German targets, accounted for 21.9% of German manufacturing victims in 2025.

Italy went from 37 to 57, the United Kingdom from 24 to 43, France from 14 to 40, Turkey from 7 to 32, Spain from 7 to 31, and Poland from 1 to 11.

Bar chart showing manufacturing ransomware victims rising from 319 in 2022 to 1,183 in 2026, same January to July period each year

The Median Victim Earns $42.9m

Ransomware’s primary manufacturing target is the mid-market, and the concentration has tightened sharply.

Victims in the $10m to $100m revenue band went from 54.3% of the revenue-known pool in 2023 to 70.2% in 2026, peaking at 73.9% in 2025. Victims under $10m also rose, from 14% to 17.3%. Both bands above $100m contracted.

See also  Integris Report Flags Fragile Trust As Banking Cybersecurity Fears Rise

The largest manufacturers have not been spared. Companies above $1bn appear every year, at 108 victims in 2023, 64 in 2024, 73 in 2025 and 45 so far in 2026. Their share fell from 13.1% to 5.3% because the base beneath them expanded, not because they stopped being hit.

Country variation is wide. The United Kingdom runs the highest mid-market concentration of any major country at 79.1%, well above the 66.3% global average. Canada follows at 76.8% and is climbing fastest, with mid-market victims rising from 11 in 2023 to 71 in 2025. Japan sits at the other extreme at 37%.

Black Kite’s reading of why is worth repeating. Companies in that band carry enough revenue to make extortion worthwhile, face contractual delivery obligations that increase downtime pressure, and share technology patterns that make them reachable in both targeted and campaign-driven attacks.

For anyone underwriting large manufacturers, that is a supply chain finding rather than a victim statistic. Mid-sized manufacturers are the supplier layer from which larger enterprises assemble their products.

The Threat Actor Ecosystem Rebuilt Itself

Across the full 2023 to 2026 period, four groups dominate: Qilin with 455 incidents, Akira with 385, LockBit 3.0 with 355, and Play with 335.

That hierarchy no longer exists.

The 2026 leaderboard reads Qilin at 178, The Gentlemen at 142, Akira at 96, DragonForce at 70, and INC Ransom at 65. The Gentlemen did not appear in the dataset before September 2025. DragonForce and INC Ransom entered with single-digit counts in 2023.

Nearly half of 2026 manufacturing incidents, 49.7%, came from groups absent in both 2023 and 2024. The Gentlemen alone account for 12% of the year’s incidents.

The decline side is just as sharp. Play, fourth across the full period, recorded 39 incidents in 2026. Medusa fell to four.

Why New Groups Arrive Already Competent

Black Kite counts the turnover. Matthew Butler, Director of Cyber Risk Services at Travelers, explained the mechanism on the Cyber Insurance News and Information Podcast this month.

Butler described The Gentlemen as the surprise of Travelers’ own Q2 data, where the group posted 248 victims across all sectors and sat second only to Qilin.

His explanation for how a group arrives at that scale from nothing is that it usually does not. “Starting from nothing is few and far between right now,” he said. Groups are disbanded or have infrastructure seized, and the operators reappear under a new brand carrying everything they learned.

Take The Cyber Insurance News Survey

Respondents get the results first.

Cyber insurance survey graphic from Cyber Insurance News asking what the market actually sees and whether loss data is good enough, with an eight minute completion time

“Like any professional team, professional company, they know what to do,” Butler said. “They have defined tactics, patterns. They know how to run the business in their space.”

See also  Nearly Nine Out of Ten Utility Companies Hacked in the Last Three Years

That is why attribution works through behavior rather than identity. Individual operators disappear. Tactics, techniques and procedures travel with them.

Black Kite’s manufacturing figures put a number on Butler’s point. Manufacturing accounts for 23.1% of The Gentlemen’s total activity, one of the highest concentrations among major groups, and they reached 142 manufacturing victims within ten months of first appearing.

Downtime Is The Leverage, And Bots Now Apply It Faster

Ferhat Dikbiyik, Black Kite’s Chief Research and Intelligence Officer, frames the sector’s appeal in operational terms. One successful attack can stop production lines and disrupt delivery commitments, he said, and every hour of downtime strengthens the attacker’s negotiating position.

Butler’s reporting from the claims side shows how that pressure is now being compressed. Travelers has confirmed threat actors using AI chatbots during ransom negotiations, providing availability across every time zone to speed up early exchanges.

“It’s the automation of urgency and not pricing,” Butler said. “That pricing decision is still very human.”

Put the two together, and the manufacturing case becomes clear. The production line supplies the leverage. The bot removes the hours a victim would otherwise use to check backups and understand the incident.

The Peter Green Chilled case in the report shows what that looks like at $79.5m in revenue. The UK chilled logistics firm serves Tesco, Sainsbury’s, Aldi, M&S, Waitrose, Asda, Co-op and Morrisons. Attackers encrypted its data in May 2025. Transport continued, but new orders went unprocessed. One customer, The Black Farmer, put its own potential loss at up to £100,000 with product stuck in a warehouse it could not retrieve and a shipment stranded at port.

Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!

What The Attackers Could See First

The report’s underwriting argument rests on its Ransomware Susceptibility Index, which scores externally visible posture from zero to one.

Scanned at the point of disclosure, 74.4% of manufacturing victims carried an RSI above 0.4, the critical range. Thirty-five percent stood at 0.6 or higher. The average victim scored 0.552.

Black Kite reports that companies scoring above 0.8 are 291 times more likely to be attacked than those below 0.2, with 41% of the top band experiencing an attack against 0.14% of the bottom.

Two worked examples carry it. Fairlife, the Coca-Cola dairy unit, scanned at 0.58 before disclosure. Asahi, whose attackers reached the network through equipment at a group site and exploited a weak password, scanned at 0.778. Thirty Asahi factories went offline, six breweries closed for a week, and direct losses passed $31m before legal and response costs.

All of it was collected externally, with no questionnaires and no vendor cooperation.

See also  Marsh McLennan and Zurich Call for Public-Private Collaboration to Tackle Cybersecurity Gaps

That proposition should sound familiar. It is the sixth time this year a security firm has proposed observable external signals as an underwriting input, following Sophos and Spektrum, Marsh and Resilience, and Silent Push, among others.

The gap is the same one every time. A correlation between score and attack likelihood is not the same as a demonstrated reduction in claims frequency or severity. Black Kite publishes the first. Nobody has yet published the second.

What the report does establish is harder to argue with. Three-quarters of the manufacturers who got hit were already visibly susceptible before anyone knew they had been attacked.

FAQ – Manufacturing Ransomware

How many manufacturers were hit by ransomware in 2026?

Black Kite counted 1,183 disclosed manufacturing victims in the first seven months of 2026, more than the whole of 2024. Same-period volume rose 39.7 percent year over year, following 42.8 percent growth the year before.

Which companies are most at risk from manufacturing ransomware?

The mid-market. Companies in the 10 million to 100 million dollar revenue band accounted for 70.2 percent of victims, up from 54.3 percent in 2023. The median victim generates 42.9 million dollars in annual revenue.

Is manufacturing ransomware still mainly a US problem?

No. The US share fell from 52.3 percent to 34.8 percent, but the US count barely moved, from 443 to 412. European victims rose 85.4 percent and the rest of the world 96.1 percent. Germany led Europe with 77 victims.

Which ransomware groups target manufacturing?

Qilin leads 2026 with 178 manufacturing victims, followed by The Gentlemen at 142, Akira at 96, DragonForce at 70 and INC Ransom at 65. Nearly half of this year’s incidents came from groups absent in 2023 and 2024.

What is the Ransomware Susceptibility Index?

A Black Kite score from zero to one measuring externally visible posture, including exposed remote access, exploitable vulnerabilities and leaked credentials. At disclosure, 74.4 percent of manufacturing victims scored above 0.4, the critical range.

Leave a Comment

×