According to distributionstrategy.com, ransomware attacks against midsized manufacturers surged 40% year over year in the first half of 2026, escalating supply chain risks for distributors reliant on those firms.
Escalating Victim Count and Industry Dominance
Black Kite identified 1,183 manufacturing ransomware victims during the first seven months of 2026, a 39.7% increase from the same period in 2025. That seven-month total exceeded the number of manufacturing victims recorded across all of 2024. Manufacturing accounted for 22% of the 7,551 publicly disclosed ransomware victims across all industries in Black Kite’s broader 2026 ransomware research — ranking first among industries for the fourth consecutive year.
Midsized Firms as Primary Targets
The concentration of attacks among midsized companies poses acute risk for distributors, as these firms often serve as manufacturers, suppliers, and service providers within integrated supply chains. Approximately 70.2% of manufacturing victims in 2026 reported annual revenue between $10 million and $100 million, with a median annual revenue of $42.9 million. Across North America and Europe, 73% of ransomware attacks from 2023 through the first half of 2026 involved midmarket companies.
Geographic Shift and Evolving Threat Actors
Black Kite reported an 85.4% increase in European manufacturing ransomware victims, while the U.S. share of global manufacturing victims fell to 34.8% from 52.3%. The number of U.S. victims declined slightly to 412 from 443. In Germany, manufacturing ransomware victims rose more than 83% during the first seven months of 2026 versus the same period in 2025. Meanwhile, 49.7% of manufacturing incidents in 2026 involved ransomware groups absent from Black Kite’s dataset in 2023 or 2024; one group, The Gentlemen, accounted for 12% of manufacturing incidents that year.
Operational Impact Drives Attacker Strategy
Ferhat Dikbiyik, Black Kite’s chief research and intelligence officer, emphasized the operational leverage attackers exploit:
“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact. One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position.” — Ferhat Dikbiyik, chief research and intelligence officer, Black Kite
The report draws on intelligence collected from Jan. 1, 2023, through July 29, 2026, covering confirmed, publicly disclosed ransomware and data-extortion incidents.
Source: distributionstrategy.com
Compiled from international media by the SCI.AI editorial team.