Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Ransomware attacks targeting manufacturers and distributors are surging, with a 40% increase in incidents year-over-year and a significant rise in European targets. The Black Kite report highlights the long-term economic impact of these attacks, exemplified by the Jaguar Land Rover incident, which disrupted production for 5,000 other organizations and led to 4,000 job cuts. The increasing interconnectivity of global economies is expanding the attack surface, and lawmakers are exploring measures like the UK’s Cyber Security and Resilience Bill to mitigate supply chain vulnerabilities. The trend indicates a continued escalation in ransomware activity and a growing threat to critical industries.
Ransomware attacks on manufacturers and distributors are rapidly increasing, with a notable shift in geographic targeting. According to Black Kite’s 2026 Manufacturing & Distribution Ransomware Report, the number of incidents rose by 40% compared to the same period in 2025, marking a significant escalation in the threat landscape. Europe is now a primary target, experiencing an 85% growth in attacks compared to the US, where the percentage remained relatively stable. The UK’s Cyber Monitoring Centre estimated a £1.9 billion financial impact from the Jaguar Land Rover attack, describing it as the most economically damaging cyberattack in UK history, surpassing the 2017 WannaCry outbreak.
This surge is driven by the interconnected nature of global supply chains. Manufacturers, particularly mid-sized ones, are often vulnerable as they rely on a larger supplier base. The report emphasizes that a large manufacturer’s vendor list represents a significant attack surface, making them attractive targets for ransomware operators. The attack against Jaguar Land Rover, for example, impacted over 5,000 other organizations, and the company subsequently announced plans to cut 4,000 jobs due to the disruption.
Several new ransomware groups, including The Gentlemen and INC Ransom, are emerging, alongside established actors like Qilin, Akira, and DragonForce. The Gentlemen, first identified by Black Kite in September 2025, was responsible for 142 manufacturing victims by mid-2026. The distribution sector, focusing on trucking, freight, and warehousing, presents a distinct attack surface, with attacks peaking in 2025 following a Clop campaign targeting Cleo.
Lawmakers are attempting to address these supply chain vulnerabilities through legislation, such as the UK’s Cyber Security and Resilience Bill, which aims to protect critical infrastructure by allowing ministers to block downstream supply from high-risk providers. The report highlights that supply chain victims are often innocent, lacking the ability to patch vulnerabilities that lead to their victimization. Despite these efforts, the underlying trend indicates a continued escalation in ransomware activity and a growing threat to critical industries, fueled by increasing interconnectivity and a proliferation of ransomware actors.