Dive Brief:
- Companies in the manufacturing sector are leaving themselves wide open to hackers by failing to fix basic and persistent cybersecurity failures, the security firm Black Kite said in a report published on Thursday.
- Manufacturing topped the list of sectors in Black Kite’s latest annual ransomware report, and Thursday’s report zooms in on the sector to explain why.
- Black Kite analyzed both the makeup of the victimized manufacturing firms and the overall security posture of the sector, finding that businesses were making progress in one area while overlooking another key source of breaches.
Dive Insight:
Black Kite paints a grim picture of cybersecurity at the 1,000 largest manufacturers. Roughly three-quarters of “Top 1,000” firms that the company publicly scanned were using software with at least one critical vulnerability, and 54% had at least one vulnerability that the Cybersecurity and Infrastructure Security Agency (CISA) has said hackers are already exploiting.
Manufacturers’ identity and access management practices are equally insufficient. Black Kite discovered “employee or system credentials” for roughly 70% of the manufacturers it analyzed on the dark web, the result of information-stealer malware quietly siphoning off those credentials for sale in the criminal underground.
Meanwhile, more than one-third of the Top 1,000 manufacturers showed indications that some of their computers were infected with botnet malware, and roughly three in 10 had already experienced a data breach.
Companies’ external communications are also insecure. Malicious actors have impersonated almost half of them in phishing campaigns, Black Kite found, and more than one-third of them haven’t properly configured a key email anti-spoofing tool, known as Message Authentication, Reporting and Conformance (DMARC). “A manufacturer’s open email authentication becomes its suppliers’ and customers’ phishing problem,” researchers wrote.
Black Kite’s historical data suggests that manufacturers are getting better at some aspects of cybersecurity. The share of analyzed Top 1,000 firms with critical vulnerabilities dropped from 80% in 2024 to 75% in 2026, while exposure to exploited vulnerabilities fell from 67% to 54%. Researchers called those data points “evidence that prioritizing known-exploited flaws works when the sector’s largest companies commit to it.”
But companies’ access-management failures remain as persistent as ever. The share of firms with exposed credentials was the same in 2024 as it was in the latest report.
While manufacturers, like other critical infrastructure operators, worry about sophisticated AI-fueled cyberattacks, basic mistakes are still their biggest weakness. In every year of Black Kite’s reporting, the company has found that misconfigured technology was the most common problem. In 2023, 84% of manufacturing-sector ransomware victims had failed to configure some key piece of technology correctly; in 2026, that figure improved only marginally, to 71%.
The share of victims with internet-exposed remote-access ports has barely budged in three years, according to Black Kite — 51.9% in 2026 versus 51.3% in 2023.
Meanwhile, far more manufacturers have been leaking credentials and other data. In 2023, only one-quarter of breached firms showed up in stealer logs; by 2026, that number was 42%.
Manufacturers aren’t moving quickly enough to fix the problems that will create tomorrow’s cyberattacks, Black Kite said.
Top 1,000 manufacturers’ improvements in patching are important, researchers wrote, but they only address “the doors attackers have always used.” Meanwhile, those firms’ credential exposure “feeds the market attackers are moving toward.”
Black Kite said it had identified more than 1,180 ransomware victims in the manufacturing sector since the beginning of 2026 — more than the annual totals for both 2023 and 2024. Victim disclosures in the first seven months of the year are up 40% over the 2025 figure.
Interestingly, roughly half of the incidents were the work of cybercrime gangs that were not active in 2023 and 2024. One of those groups, The Gentlemen, conducted roughly 12% of all the attacks that Black Kite has logged so far in 2026.
Another interesting finding: Seven in 10 victims are mid-market firms, those with annual revenue between $10 million and $100 million. Black Kite warned in August that the midmarket was a disproportionate ransomware target because of its unique challenges.
“The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products,” researchers wrote in the new report. “When the mid-market is the primary target, a large manufacturer’s vendor list is its attack surface.”
Black Kite collected its data between Jan. 1, 2023, and July 29, 2026, through a combination of public infrastructure scanning and analysis of disclosed ransomware incidents.
