Black Kite’s Manufacturing & Distribution Ransomware Report 2026 Confirms Manufacturing Remains #1 Target | #ransomware | #cybercrime


New research finds ransomware attacks on manufacturers surged nearly 40% year over year in the first half of 2026

BOSTON, Sept. 17, 2026 /PRNewswire/ — Black Kite, the leader in third-party cyber risk management, today released its 2026 Manufacturing & Distribution Ransomware Report: Still the #1 Target, but the Victim Profile Moved Downmarket and Overseas. Examining the pressure across the full supply chain – from manufacturers to the companies that move their products – the report provides a blueprint for ranking suppliers by observable ransomware susceptibility, rather than by revenue, tier, or the date of their last questionnaire.

“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” said Ferhat Dikbiyik, Chief Research & Intelligence Officer (CRIO), Black Kite. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses. Black Kite analyzes that same external attack surface, giving organizations a view of what adversaries can already see and where they may be most vulnerable.”

Ransomware Attacks Continue to Accelerate

Manufacturing’s position at the top is consistent across Black Kite’s broader ransomware research. Black Kite’s 2026 Ransomware Report identified 7,551 publicly disclosed ransomware victims across all industries, with manufacturing ranking first for the fourth consecutive year,  accounting for 22% of all disclosures.

While ransomware activity is rising across industries, manufacturing stands apart for the consistency and pace of that growth. Ransomware attacks on manufacturers have more than doubled since 2023, and in the first half of 2026 alone, attacks increased nearly 40% year over year.

Manufacturing Ransomware is Going Global

The geographic footprint of manufacturing ransomware is expanding, driven by a sharp rise in European victims. Victim counts across Europe increased 85.4%, while the U.S. share of global manufacturing ransomware victims fell from 52.3% to 34.8%.

Germany saw particularly significant growth. Manufacturing accounts for nearly 20% of the country’s economy, and ransomware victims in the sector increased by more than 83% in the first seven months of 2026 compared with the same period in 2025.

One group contributing to that pressure is SafePay. Black Kite’s European ransomware research previously identified the group’s concentration on German targets. SafePay accounted for 21.9% of German manufacturing ransomware victims in 2025 and remains among the country’s most active ransomware groups in 2026.

The Victim Profile: Mid-Market Bears the Brunt

Ransomware’s primary target is the mid-market, not the enterprise as widely assumed. The median ransomware victim generates $42.9 million in annual revenue, and from 2023 through the first half of 2026, 73% of ransomware attacks in North America and Europe hit mid-market companies.

For manufacturing, that concentration carries broader implications. Mid-sized manufacturers often sit within the supplier networks of larger enterprises, meaning attacks on the mid-market can create risk well beyond the initial victim. When suppliers are the primary target, a manufacturer’s vendor ecosystem becomes part of its attack surface.

Threat Actor Spotlight: The Gentlemen

The threat actor ecosystem has been rebuilt, with the hierarchy of players being replaced by Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom. Among the new arrivals, The Gentlemen stands out for how quickly it found its footing in manufacturing.

First appearing in Black Kite’s dataset in September 2025, The Gentlemen had claimed 142 manufacturing victims by mid-2026. Manufacturing now accounts for 23.1% of the group’s activity, one of the highest concentrations among major ransomware groups.

Key findings from the report:

  • 1,183 Manufacturing Victims in Seven Months, and the Climb Hasn’t Paused: The first seven months of 2026 produced more manufacturing victims than all of 2024, and same-period volume is up 39.7% year over year.
  • 49.7% of 2026 Incidents Came From Groups Absent Two Years Ago: The attacker ecosystem rebuilt itself in two years. Nearly half of 2026 manufacturing incidents came from groups absent in 2023 and 2024, and a single new entrant, The Gentlemen, accounts for 12% of the year’s incidents on its own.
  • 70.2% of Manufacturing Victims Sit in the $10M to $100M Revenue Band: The mid-market carries the volume. The median victim generates $42.9 million in revenue, while the largest manufacturers continue to be hit every year.
  • 85.4% Growth in European Victims Cut the U.S. Share to 34.8%: The U.S. victim count barely moved (443 to 412), so the drop in the U.S. share from 52.3% to 34.8% came entirely from growth elsewhere, led by Germany, where manufacturing carries 19.9% of the economy

The report measured every exposure from the outside, using the same vantage point available to an attacker. The findings show that many victims displayed measurable signs of ransomware susceptibility at the time of disclosure. Nearly three-quarters (74.4%) had an RSI above 0.4, placing them in the critical range, while more than one-third (35.1%) had an RSI of 0.6 or higher. The average victim scored 0.552.

For manufacturers and distributors, resilience depends on continuously measuring these external signals across their own organization and third-party ecosystems, and acting on them before a breach occurs.

To read the report, visit https://blackkite.com/reports/2026-manufacturing-distribution.

Methodology
The report integrates several streams of intelligence curated by the Black Kite Research Group™ between January 1, 2023 and July 29, 2026. The ransomware data covers confirmed, publicly disclosed ransomware and data extortion incidents, retained once an incident was ready for publication, with attribution to a named threat group recorded where it could be established. Population exposure data was derived from Black Kite’s telemetry, assessed from the outside using non-intrusive, attacker’s-perspective methods that require no questionnaires and no vendor cooperation, current as of August 2026.

About Black Kite
Black Kite is an AI-native third-party cyber risk management platform built for the connected world. By distilling billions of external risk signals from millions of monitored organizations, Black Kite delivers the trusted intelligence that powers a connected defense network, enabling organizations to identify risk earlier, act faster, and move from isolated defense to collective resilience. With Black Kite, organizations benefit from greater control, earlier warning, and the confidence to work safely with third parties at scale. Black Kite has received numerous industry awards and recognition from customers. Learn more at www.blackkite.com, or on the Black Kite blog.

Media Contact:
Michelle Kearney
Hi-Touch PR
443-857-9468
[email protected]

SOURCE Black Kite



Click Here For The Original Source.

——————————————————–

..........

.

.