Manufacturing — Cyber Threat Activity
Manufacturing absorbs more ransomware than any other industrial sector, and our log reflects it: over 2,000 recorded incidents across 75 countries, more than 630 in the trailing 180 days. 102 groups have been attributed at least one claim, led by Akira (275), Qilin (273), Play (198), LockBit (107) and RansomHub (107). Dragos measured manufacturing at roughly two-thirds of all industrial ransomware incidents it tracked in early 2025, with construction, food and beverage, consumer goods and equipment the busiest subsectors and metals and chemicals far behind. The reason manufacturers are chosen is that they cannot wait. Encrypt the systems that schedule production and an assembly line stops earning within hours, which compresses the negotiation window in the attacker's favour. That pressure sits on top of flat networks, long-lived legacy controllers and IT-to-OT paths that were never designed to be adversarial. Attacks rarely need to touch control systems to halt production; disruption to enterprise IT cascades into the plant on its own. Manufacturing also carries a genuine espionage overlay that the extortion volume obscures. CrowdStrike has documented roughly ten adversary groups deliberately targeting the industry alongside the opportunists, mixing state-sponsored intellectual property theft with criminal extortion, and our own graph records 173 groups in total once profile-level research associations are included. Geography is broader here than in most sectors: the United States leads with 895 claims but Germany (145), Canada, the United Kingdom, Italy and India all carry meaningful volume, which is what a globally distributed supply chain looks like when it is attacked at the weakest link rather than the largest one.
- Recorded incidents: 2,623
- Incidents, trailing 180 days: 843
- Tracked threat actors: 181
- Malware families: 179
Recent incidents
- Kimberly-Clark 2026-09-13
- Shelco Filters 2026-09-12
- www.metalware.ca 2026-09-12
- Swadeshi Civil Infrastructure Private Limited (SCIPL) 2026-09-12
- 瑞祥机电 (Ruixiang Jidian) 2026-09-12
- Abourametals 2026-09-12
- Konica Minolta Bulgaria 2026-09-11
- Tuboaços da Amazônia Ltda. 2026-09-11
- HENRYPRATT.COM 2026-09-10
- HARLEY-DAVIDSON.COM 2026-09-10
- ArtiFlex Manufacturing LLC 2026-09-10
- jms building corporation 2026-09-10
- AK Stamping 2026-09-10
- Eagle Construction 2026-09-10
- Grunthal Welding & Supplies 2026-09-10
- Flexmaster 2026-09-09
- Melitron 2026-09-09
- Kyodo USA 2026-09-09
- Specchem LLC 2026-09-09
- Jet Specialty 2026-09-09
Threat actors targeting Manufacturing
- Qilin 379 incidents
- Akira 344 incidents
- Play Ransomware 214 incidents
- LockBit 129 incidents
- The Gentlemen 124 incidents
- RansomHub 115 incidents
- Cl0p 108 incidents
- INC Ransom 106 incidents
- DragonForce 106 incidents
- SafePay 88 incidents
- Lynx Ransomware 79 incidents
- Black Basta 45 incidents
- Hunters International 45 incidents
- 8Base 43 incidents
- Medusa Ransomware 38 incidents
- NightSpire 38 incidents
- Cactus 38 incidents
- Sarcoma 33 incidents
- Deadlock 22 incidents
- Fog Ransomware 22 incidents
- BlackSuit 21 incidents
- Rhysida 21 incidents
- RansomHouse 19 incidents
- KillSec 17 incidents
Where these victims are
- United States 1,074
- Germany 188
- Canada 124
- Italy 115
- United Kingdom 88
- India 79
- Japan 52
- Spain 49
- France 47
- Brazil 45
- Turkey 40
- Taiwan 36
Malware used against Manufacturing
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Akira Malware
- BlackCat Malware
- Cobalt Strike Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- QakBot Malware
Coverage. 95.3% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.