← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Ransomware Attacks on Manufacturers Increase 40% in 2026, Disrupting Supply Chains

🔄 Updated 6d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Ransomware attacks on manufacturers increased 40% in early 2026.
  • Jaguar Land Rover shutdown in 2025 caused £1.9 billion economic damage.
  • Mid-sized manufacturers are primary targets due to supply chain impact.
  • Half of 2026 attacks were by new ransomware groups.

Rising Ransomware Incidents in Manufacturing

Ransomware attacks on the manufacturing sector have seen a significant increase, with incidents in the first seven months of 2026 rising by 40% compared to the same period in 2025. This trend highlights the ongoing vulnerability of manufacturers to cyber threats, as detailed in the Black Kite 2026 Manufacturing & Distribution Ransomware Report. The report identified 5,237 disclosed ransomware victims across manufacturing and distribution between January 2023 and July 2026.

Economic Impact and Supply Chain Disruption

The severe consequences of these attacks are a primary reason for manufacturing remaining a target. A notable example is the September 2025 incident where Jaguar Land Rover's UK plants were shut down, halting production of approximately 1,000 vehicles daily. This attack affected over 5,000 other companies and was cited as a factor in a slowdown of national growth figures by the Bank of England. The UK’s Cyber Monitoring Centre estimated the financial impact at £1.9 billion, making it the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak. Jaguar Land Rover subsequently announced 4,000 job cuts, attributing them to the cyberattack.

Mid-Sized Manufacturers as Key Targets

Mid-sized manufacturers, which often serve as suppliers to larger enterprises, are absorbing most of these attacks. The report emphasizes that a large manufacturer's vendor list effectively becomes its attack surface when the mid-market is targeted. Ferhat Dikbiyik, chief research and intelligence officer at Black Kite, noted that the immediate operational impact, such as stopping production lines and disrupting delivery commitments, makes manufacturing and distribution attractive to ransomware operators. Attackers leverage externally visible signals like unpatched systems, exploitable services, and leaked credentials for reconnaissance.

Emergence of New Ransomware Groups

The landscape of ransomware groups is also evolving rapidly. Half of the attacks recorded in the first seven months of 2026 were carried out by groups that did not exist two years prior. A single new group, "The Gentlemen," was responsible for 12% of this year's attacks, claiming 142 manufacturing victims by mid-2026 after being first noticed in September 2025.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Ransomware incidents targeting manufacturing companies rose by 40% in the first seven months of 2026 compared to the previous year, according to the Black Kite 2026 Manufacturing & Distribution Ransomware Report. This surge is attributed to the significant operational impact and supply chain disruption these attacks cause, making manufacturers, particularly mid-sized suppliers, attractive targets for ransomware groups.