Why Manufacturing Companies Get Hit With Ransomware (and Which Gap Is Yours)

Last updated: 10/06/2026
Cybersecurity
Why Manufacturing Companies Get Hit With Ransomware (and Which Gap Is Yours)

Manufacturing companies get hit with ransomware because a stopped production line pressures them to pay fast, and because their networks are unusually easy to get into. Old plant equipment, shared office and plant networks, open vendor access, and thin security staff do the rest.

IBM's 2026 X-Force Threat Intelligence Index put manufacturing at the top of its target list for the fifth year in a row, at 27.7% of the incidents its responders worked. If you run a plant, that ranking isn't trivia. It describes who attackers are shopping for, and it's the assumption our manufacturing IT work starts from.

Industrial gears locked in place by a green padlock and chain, representing a production line stopped by ransomware

Attackers Aren't After Your Data. They're After Your Production Schedule.

When ransomware hits a law firm, the firm loses email and files for a while. When it hits a manufacturer, the manufacturer loses output. Orders slip. Trucks leave the dock half empty. A customer with a late-delivery penalty in the contract starts doing math, and so does your bank.

Comparitech studied 858 confirmed ransomware attacks on manufacturers between 2018 and October 2024 and put the average cost of the downtime at about $1.9M per day, with production down for 11.6 days on average. Those figures blend small job shops with global plants, so your daily number will be different. The direction won't be.

Attackers price that pressure in. In Sophos's State of Ransomware in Manufacturing and Production 2025, a survey of 332 manufacturers hit by ransomware, 51% paid. The average payment was $1.0M against average demands of $1.2M.

A ransom that looks outrageous on Monday can look cheap by Thursday if the line is still down. That's the bet the attacker is making.

And the pain travels. Black Kite's Manufacturing and Distribution Ransomware Report 2026 notes that when the systems that make or move goods stop, the effects don't stay inside the victim's network. Your customers feel it, which turns your outage into their problem and adds one more voice telling you to pay. The full cost picture, past the ransom itself, is in our breakdown of the real cost of a ransomware attack.

"We're Too Small to Be a Target" Is the Most Expensive Assumption on the Plant Floor

The big names make the news. They aren't the typical victim.

Black Kite tracked 4,780 manufacturing ransomware victims from January 2023 through July 2026. The median victim brings in $42.9M a year. Companies in the $10M to $100M revenue band made up 70.2% of victims with known revenue in 2026, up from 54.3% in 2023, while billion-dollar victims fell from 13.1% to 5.3% over the same stretch.

Picture a $40M plant with 2 people in IT. That's the typical victim, not a Fortune 500 brand.

The mid-market is where the math works for an attacker. A company that size has enough revenue to pay a seven-figure demand and, very often, not enough security staff to spot the attacker during the weeks they spend inside the network before anything gets encrypted. Large enterprises have security teams and budgets built for this. A $40M manufacturer is more likely to have spent the last few years adding machines, a second shift, and a cloud ERP.

The crews change constantly, too. Black Kite found that 49.7% of 2026 manufacturing incidents came from groups that didn't appear in its data in 2023 or 2024. Names like Qilin, Akira, and a newcomer calling itself The Gentlemen sit at the top of the 2026 list. You won't out-guess them. The gaps they walk through stay the same, and those you can close.

The Six Gaps Attackers Walk Through

Two data sets line up well here. Sophos asked victims what went wrong. Dragos, which handles incident response and security assessments inside industrial plants, published what its people actually found on site in its 2026 OT Cybersecurity Year in Review. Put them side by side and the same 6 gaps keep showing up.

1. Remote access nobody owns

The machine builder needs to get into the press controller. The ERP consultant needs remote desktop access to the server. Somebody set up a VPN account for a vendor back in 2019 so a technician could troubleshoot a machine over the holidays, and nobody has checked that account, its password, or whether that technician still works there since.

That's the door. CISA's advisory on Akira ransomware, updated in November 2025, lists critical manufacturing among the sectors Akira goes after and names a VPN without multifactor authentication (MFA, the app prompt or code on top of a password) as a primary way in. Akira had pulled in roughly $244M in ransom proceeds by late September 2025. In August 2026, CISA's Gunra advisory described affiliates breaking in through exposed credentials on internet-facing VPN gateways.

Can you name every outside company that has a standing connection into your network, right now, without looking it up? If not, that list is job one. Our post on vendor risk management for manufacturing supply chains covers how to build it.

2. Office and plant on the same network

OT, or operational technology, is the equipment that runs production. Controllers, the touchscreens operators use to run a line (HMIs), and the Windows PCs that sit next to the machines. In a well-built plant, OT lives on its own network with a firewall between it and the office.

An industrial robotic arm wired directly to an office laptop, representing office and plant systems sharing one network

In a lot of plants, it doesn't. Dragos found shared IT and OT domains, meaning the office and the plant trust the same logins and network, in nearly half of its manufacturing assessments. That was the highest rate of any sector and more than 3 times the rate in oil and gas or electric utilities, according to its manufacturing analysis.

Ransomware crews don't need to understand a PLC (programmable logic controller, the small industrial computer that runs a machine). They need a phished office password and a path to the Windows boxes on the floor. A shared network hands them that path. If you're not sure how many barriers sit between an accounting laptop and the HMI on line 1, assume none, then go check. The fix is laid out in OT vs. IT security in manufacturing.

3. Equipment that can't be patched

Plants run machines for 20 years, and the PC that drives each one often runs whatever Windows version shipped with it, on the understanding that the machine builder will void support the day you update it.

Sometimes there's no update to install anyway. Dragos reports that 26% of the industrial control system advisories it reviewed in 2025 came with no patch or mitigation from the vendor. You can't patch your way out of that. You fence it off, so the old box can only talk to the things it has to talk to.

4. Known holes on the internet-facing edge

The plant floor gets the attention. The attacker often comes in through the front office firewall.

Exploited vulnerabilities were the top root cause of ransomware attacks on manufacturers in the Sophos survey, at 32%, ahead of malicious email at 23%. IBM saw the same trend across industries, with a 44% jump in attacks that started by exploiting public-facing applications, and vulnerability exploitation behind 40% of all the incidents it worked in 2025. These are holes in firewalls, VPN appliances, file-transfer servers, and remote access portals, usually with a fix already published. Ask your team 3 questions this week.

  • When was the firewall's firmware last updated?
  • Is any device facing the internet listed in CISA's Known Exploited Vulnerabilities catalog, the federal list of flaws attackers are actively using?
  • Who's responsible for patching those devices within days, not at the next quarterly maintenance window?

5. Nobody watching the network

Ransomware doesn't go off the moment an attacker gets in. They look around first. They find the backups, map the file shares, figure out which servers run scheduling and shipping, steal whatever looks valuable enough to threaten you with later, and then wait for a holiday weekend when fewer people are watching.

A magnifying glass over a web of connected network nodes beside a green shield, representing round-the-clock network monitoring

Dragos puts the average dwell time, the stretch between break-in and discovery, at 42 days for ransomware in OT environments. Plants with full visibility into their OT networks detected and contained those incidents in an average of 5 days. And 30% of Dragos incident response cases in 2025 started without any alert at all. Someone simply noticed that something seemed wrong.

Six weeks is a long time to have a stranger in the building. Who gets the alert at 2 a.m. on a Saturday, and can they act on it? If the honest answer is "it goes to an inbox," that's the gap. Round-the-clock monitoring is the core of managed cybersecurity services for exactly this reason.

6. Not enough security expertise in-house

Victims named lack of expertise as the biggest organizational factor in their attacks, at 42.5% in the Sophos survey. Unknown security gaps came in right behind at 41.6%. Those two are really the same problem described twice. You can't close a gap nobody on staff knows to look for.

This isn't a knock on the IT manager. One person covering the ERP, the phones, the label printers, 140 users, and security on top of everything else isn't someone failing at the job but a staffing decision made years ago, and attackers know how that decision usually plays out. Dragos also found that 24% of manufacturing sites have no OT incident response plan at all, the highest of any sector it measured.

Manufacturing ransomware self-check: six gaps, the question to ask your team this week, and the red-flag answer for each

Why Backups Alone Don't Settle It Anymore

For years the standard answer to ransomware was simple. Keep good backups, restore, and refuse to pay.

A green shield with a padlock in front of database stacks and a separate offline drive, representing protected, offline backups

That still matters. In the Sophos survey, 58% of manufacturers restored encrypted data from backups. But the attackers adjusted. IBM found data theft was the most common impact in manufacturing incidents in 2025. Sophos saw extortion-only attacks, where nothing is encrypted and the threat is purely to leak what was stolen, rise from 3% of manufacturing cases to 10% in a year.

Part of that is good news. Defenses got better at stopping encryption, and only 40% of attacks on manufacturers ended with data encrypted, the lowest rate in 5 years of the survey, with half of the companies stopping the attack before anything got locked. So the crews steal first. A restore puts the line back up. It doesn't pull your CAD drawings, customer pricing, or supplier contracts back off a leak site.

Backups still have to be offline or immutable (they can't be changed or deleted, even by an admin account), and the restore has to be tested on the systems that run production, like the ERP and the MES (the manufacturing execution system that tracks work orders on the floor). Our ransomware recovery playbook walks through the response step by step, and manufacturing disaster recovery and business continuity covers how to plan restore order around the line. If you want to see how the aftermath plays out on a real production floor, read what happens when ransomware hits an electronics manufacturer.

What to Fix First

The order below follows how an attack actually unfolds. Getting in, moving around, staying hidden, then cashing out. Close the early steps and the later ones get much harder for the attacker.

  1. Lock down remote access. MFA on every VPN and remote tool, no exceptions for vendors. Kill accounts nobody uses, and move vendor access to approved, time-limited sessions instead of always-on tunnels. It's usually the cheapest fix on this list, and CISA's Akira and Gunra advisories both name it as a way in.
  2. Patch the edge. Firewalls, VPN appliances, and anything else facing the internet, checked against the CISA catalog and patched within days.
  3. Separate the office from the plant. At minimum, a firewall between them that allows only the traffic production needs, and separate logins for OT. Fence off the machines you can't patch.
  4. Put eyes on the network around the clock. Monitoring that covers both office and plant, with someone who can isolate a machine at 2 a.m.
  5. Plan for theft, not just encryption. Offline backups, a tested restore of ERP and MES, and an incident plan that includes the plant floor and who decides whether to shut a line down.

Already running a 24/7 security operations center with OT coverage and segmented plant networks? Then you've likely handled 1 through 4. Spend your time on the restore test instead. It's the step that gets skipped when production is busy, which is always.

Find Out Which Gap Is Yours

Consilien works with manufacturers across the country on these six gaps, from vendor remote access and network separation to 24/7 monitoring and recovery planning. You can see how that looks on a plant floor on our manufacturing cybersecurity page.

If you went through the self-check above and hit "let me find out" more than once, that's worth a conversation. Speak to a Cybersecurity Expert and we'll walk through your remote access, network layout, and recovery plan with you.

Not Sure Which Gap Is Yours?

If the self-check left you saying "let me find out" more than once, start there.

We'll walk through your vendor remote access, how your office and plant networks connect, who's watching after hours, and how fast you could restore the systems that run production.

Manufacturing Ransomware Questions Plant Leaders Ask

Is manufacturing really the most targeted industry for ransomware?
Yes. IBM ranked manufacturing the most attacked industry for the fifth straight year in its 2026 X-Force index, at 27.7% of incidents. Black Kite counted 1,660 manufacturing ransomware victims between April 2025 and March 2026, 22.0% of all disclosed victims, more than any other sector.
Why do manufacturers pay ransoms so often?
51% of manufacturers hit by ransomware paid in the Sophos 2025 survey, because every day of downtime can cost more than the average demand. When production stops, shipments, contracts, and customer relationships start slipping within hours.

Paying doesn't guarantee much, though. The data has usually been stolen already, and a decryption key still leaves you with days of restore work.
How do attackers usually get into a manufacturing network?
Through the front door, mostly. Exploited vulnerabilities in firewalls, VPNs, and other internet-facing systems were the leading cause in the Sophos survey at 32%, followed by malicious email at 23%. Stolen or weak credentials on VPNs without MFA are the other big one, and CISA's advisories on groups like Akira name them directly.
Can ransomware reach the plant floor from an office email?
It can if the office and plant share a network or login system, and Dragos found that setup in nearly half of manufacturing assessments. A phished password in accounting can then reach the Windows PCs and HMIs that run production. A firewall between the two networks, with separate OT logins, breaks that path.
Should a manufacturer pay the ransom?
The U.S. government strongly discourages it, and the Treasury Department's OFAC ransomware advisory warns that paying a sanctioned group can create legal trouble of its own. In practice, the call gets made with legal counsel and your cyber insurer, and it's a much easier call when you have clean, tested backups.

Either way, report the attack to the FBI through IC3 quickly. OFAC treats a prompt report to law enforcement as a significant mitigating factor if a payment question ever comes up.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.