
Black Kite, the leader in third-party cyber risk management, today announced the release of Manufacturing & Distribution Ransomware Report 2026, Still the #1 Target, but the Victim Profile Moved Downmarket and Overseas (https://blackkite.com/reports/2026-manufacturing-distribution). The report examines ransomware pressure throughout the supply chain, covering both manufacturers and the organizations responsible for moving their products. It offers a framework for prioritizing suppliers according to observable ransomware susceptibility rather than revenue, supply-chain tier, or the timing of their most recent security questionnaire.
“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” said Ferhat Dikbiyik, Chief Research & Intelligence Officer (CRIO), Black Kite. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses. Black Kite analyzes that same external attack surface, giving organizations a view of what adversaries can already see and where they may be most vulnerable.”
Ransomware Attacks Continue to Accelerate
Manufacturing has maintained its position as the leading ransomware target in Black Kite’s broader research. The company’s 2026 Ransomware Report recorded 7,551 publicly disclosed ransomware victims across industries, with manufacturing ranking first for the fourth consecutive year and representing 22% of all disclosures.
Although ransomware activity continues to increase across multiple sectors, manufacturing has experienced particularly sustained growth. Attacks against manufacturers have more than doubled since 2023, while the first seven months of 2026 saw ransomware activity increase by nearly 40% compared with the same period in 2025.
Manufacturing Ransomware is Going Global
The geographic distribution of manufacturing ransomware is shifting, largely as a result of substantial growth in European victims. Manufacturing ransomware victims across Europe increased 85.4%, while the U.S. portion of global manufacturing ransomware victims declined from 52.3% to 34.8%.
Germany experienced especially notable growth. Manufacturing represents nearly 20% of the country’s economy, and ransomware victims within the sector rose by more than 83% during the first seven months of 2026 compared with the corresponding period in 2025.
SafePay is among the threat groups contributing to this activity. Black Kite’s European ransomware research previously documented the group’s focus on German organizations. SafePay was responsible for 21.9% of German manufacturing ransomware victims in 2025 and continues to rank among the country’s most active ransomware groups in 2026.
The Victim Profile: Mid-Market Bears the Brunt
The mid-market remains the primary target for ransomware rather than large enterprises, contrary to a common assumption. The median ransomware victim generates $42.9 million in annual revenue. Between 2023 and the first half of 2026, mid-market organizations accounted for 73% of ransomware attacks across North America and Europe.
This concentration has significant implications for manufacturing. Mid-sized manufacturers frequently operate as suppliers within larger enterprise ecosystems, meaning a ransomware incident affecting one of these organizations can introduce risk throughout the wider supply chain. When suppliers become targets, their interconnected vendor environments also become part of the broader attack surface.
Threat Actor Spotlight: The Gentlemen
The ransomware threat actor landscape has undergone significant changes, with Qilin, The Gentleman, Akira, DragonForce, and INC Ransom replacing the previous hierarchy of prominent groups. Among these newer actors, The Gentlemen has established a notable presence in manufacturing in a relatively short period.
The Gentlemen first appeared in Black Kite’s dataset in September 2025 and had claimed 142 manufacturing victims by the middle of 2026. Manufacturing now represents 23.1% of the group’s overall activity, placing it among the ransomware groups with the highest concentration of manufacturing victims.
Key findings from the report:
• 1,183 Manufacturing Victims in Seven Months, and the Climb Hasn’t Paused: Manufacturing recorded 1,183 victims during the first seven months of 2026, exceeding the total number recorded throughout 2024. Volume for the comparable period also increased 39.7% year over year.
• 49.7% of 2026 Incidents Came From Groups Absent Two Years Ago: The ransomware ecosystem has changed substantially over the past two years. Nearly half of manufacturing incidents recorded in 2026 involved groups that were absent in 2023 and 2024, while the new entrant The Gentlemen alone accounted for 12% of incidents during the year.
• 70.2% of Manufacturing Victims Sit in the $10M to $100M Revenue Band: Mid-market organizations account for the largest share of manufacturing ransomware victims. The median victim generates $42.9 million in annual revenue, although large manufacturers continue to experience ransomware attacks each year.
• 85.4% Growth in European Victims Cut the U.S. Share to 34.8%: The number of U.S. manufacturing victims changed only slightly, from 443 to 412. As a result, the decline in the U.S. share from 52.3% to 34.8% was driven by growth in other regions, particularly Germany, where manufacturing carries 19.9% of the economy.
The report assessed external exposure using the same perspective available to an attacker. Its findings indicate that a substantial proportion of ransomware victims exhibited measurable indicators of susceptibility when their incidents were disclosed. Nearly three-quarters (74.4%) recorded an RSI above 0.4, placing them within the critical range, while more than one-third (35.1%) recorded an RSI of 0.6 or higher. The average victim had an RSI score of 0.552.
For manufacturers and distributors, improving resilience requires continuous measurement of these external signals across both internal environments and third-party ecosystems, followed by remediation before an attacker can exploit the identified exposure.
To read the report, visit https://blackkite.com/reports/2026-manufacturing-distribution.
Methodology
The report combines multiple intelligence sources curated by the Black Kite Research Group™ from January 1, 2023 through July 29, 2026. Its ransomware dataset includes confirmed, publicly disclosed ransomware and data extortion incidents that were retained once they were ready for publication. Named threat-group attribution was included when it could be established. Population exposure data was generated from Black Kite telemetry and evaluated externally through non-intrusive, attacker-perspective techniques that require neither questionnaires nor vendor cooperation. The exposure data was current as of August 2026.
About Black Kite
Black Kite is an AI-native third-party cyber risk management platform built for the connected world. By distilling billions of external risk signals from millions of monitored organizations, Black Kite delivers the trusted intelligence that powers a connected defense network, enabling organizations to identify risk earlier, act faster, and move from isolated defense to collective resilience. With Black Kite, organizations benefit from greater control, earlier warning, and the confidence to work safely with third parties at scale. Black Kite has received numerous industry awards and recognition from customers. Learn more at www.blackkite.com, or on the Black Kite blog.
Media Contact:
Michelle Kearney
Hi-Touch PR
443-857-9468
kearney@hi-touchpr.com
Join our LinkedIn group Information Security Community!










