Manufacturing — Cyber Threat Activity
Manufacturing absorbs more ransomware than any other industrial sector, and our log reflects it: over 2,000 recorded incidents across 75 countries, more than 630 in the trailing 180 days. 102 groups have been attributed at least one claim, led by Akira (275), Qilin (273), Play (198), LockBit (107) and RansomHub (107). Dragos measured manufacturing at roughly two-thirds of all industrial ransomware incidents it tracked in early 2025, with construction, food and beverage, consumer goods and equipment the busiest subsectors and metals and chemicals far behind. The reason manufacturers are chosen is that they cannot wait. Encrypt the systems that schedule production and an assembly line stops earning within hours, which compresses the negotiation window in the attacker's favour. That pressure sits on top of flat networks, long-lived legacy controllers and IT-to-OT paths that were never designed to be adversarial. Attacks rarely need to touch control systems to halt production; disruption to enterprise IT cascades into the plant on its own. Manufacturing also carries a genuine espionage overlay that the extortion volume obscures. CrowdStrike has documented roughly ten adversary groups deliberately targeting the industry alongside the opportunists, mixing state-sponsored intellectual property theft with criminal extortion, and our own graph records 173 groups in total once profile-level research associations are included. Geography is broader here than in most sectors: the United States leads with 895 claims but Germany (145), Canada, the United Kingdom, Italy and India all carry meaningful volume, which is what a globally distributed supply chain looks like when it is attacked at the weakest link rather than the largest one.
- Recorded incidents: 2,656
- Incidents, trailing 180 days: 846
- Tracked threat actors: 182
- Malware families: 179
Recent incidents
- Electrolux 2026-09-19
- Giti Corp 2026-09-18
- American Casting Company 2026-09-18
- Anderson Industries 2026-09-18
- Premier Lighting & Controls 2026-09-18
- Vista Plastic Solutions 2026-09-18
- Appliance Factory & Mattress Kingdom 2026-09-17
- rottner-tresor.at 2026-09-17
- Aarsleff 2026-09-16
- Manders 2026-09-16
- Roshd Sanat 2026-09-16
- Thema Foundries 2026-09-16
- RDA MOTORS S.P.A. 2026-09-16
- Honda (Peru) 2026-09-15
- Balkan Polymers 2026-09-15
- Downrite Engineering 2026-09-15
- Neff Drexel 2026-09-15
- Dome Gold Mines 2026-09-15
- TMI Tecnicas Mecanicas Ilerdenses 2026-09-15
- SFA Engineering Corporation 2026-09-15
Threat actors targeting Manufacturing
- Qilin 385 incidents
- Akira 347 incidents
- Play Ransomware 215 incidents
- LockBit 129 incidents
- The Gentlemen 129 incidents
- RansomHub 115 incidents
- Cl0p 108 incidents
- INC Ransom 107 incidents
- DragonForce 106 incidents
- SafePay 90 incidents
- Lynx Ransomware 79 incidents
- Black Basta 45 incidents
- Hunters International 45 incidents
- 8Base 43 incidents
- Medusa Ransomware 38 incidents
- NightSpire 38 incidents
- Cactus 38 incidents
- Sarcoma 33 incidents
- Deadlock 22 incidents
- Fog Ransomware 22 incidents
- BlackSuit 21 incidents
- Rhysida 21 incidents
- RansomHouse 19 incidents
- KillSec 18 incidents
Where these victims are
- United States 1,084
- Germany 189
- Canada 124
- Italy 116
- United Kingdom 90
- India 79
- Japan 54
- Spain 51
- France 48
- Brazil 45
- Turkey 41
- Taiwan 36
Malware used against Manufacturing
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Akira Malware
- BlackCat Malware
- Cobalt Strike Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- QakBot Malware
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.