惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Microsoft Security Blog
Microsoft Security Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
爱范儿
爱范儿
T
Tailwind CSS Blog
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
WordPress大学
WordPress大学
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
腾讯CDC
V
V2EX
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
B
Blog
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
Why Manufacturing Cyber Security is Becoming More Complex...
lizwu@checkpoint.com · 2026-04-13 · via Check Point Blog

The global manufacturing sector entered 2025 facing one of the most aggressive cyber threat environments in its history. Digital transformation, smart factories, and interconnected supply chains have expanded operational efficiency to places 50 years ago we wouldn’t have thought possible. But, this comes with unprecedented cyber risk. According to the Manufacturing Threat Landscape 2025 report, cyber incidents targeting manufacturing increased sharply year over year, placing the industry at the center of global ransomware activity.

Manufacturing Becomes the Primary Ransomware Target

In 2025, global ransomware incidents reached 7,419 documented cases, representing a 32 percent increase year over year. Manufacturing was the most targeted industry sector. Attacks against manufacturers rose 56 percent, increasing from 937 incidents in 2024 to 1,466 in 2025.

The financial reasoning of attacking manufacturers is the fact that downtime can cost millions per day, disrupt safety of critical operations, and cascade across global supply chains. Threat actors increasingly view production disruption as leverage rather than collateral damage.

The United States led globally with 713 manufacturing ransomware incidents, followed by India (201), Germany (79), the United Kingdom (65), and Canada (62). These figures show that both mature and emerging industrial economies face similar exposure levels.

Manufacturing Top 5 Targeted Countries 2025

Why Manufacturers Are So Vulnerable

Three structural weaknesses continue to drive manufacturing cyber risk.

  1. First, legacy operational technology systems remain deeply embedded in industrial environments. Many programmable logic controllers, SCADA systems, and industrial IoT devices were never designed with modern security controls. In Europe, 80 percent of manufacturers still operate critical OT systems with known vulnerabilities, making exploitation both feasible and repeatable.
  2. Second, supply chain complexity has expanded the attack surface. In 2025, supply chain attacks nearly doubled, rising from 154 incidents in 2024 to 297 in 2025. Threat actors increasingly compromise smaller vendors, managed service providers, or SaaS platforms to gain indirect access to large industrial targets.
  3. Third, ransomware-as-a-service operations have matured. Affiliate-based models allow threat groups to scale attacks rapidly, reuse proven tooling, and localize campaigns by geography and industry.

Read the manufacturing threat landscape now.

The Threat Actors Driving Industrial Attacks

Several ransomware groups dominated manufacturing attacks in 2025.

Manufacturing Top 10 Threat Actors

Akira, active since 2023, emerged as one of the most financially successful groups, generating an estimated $244 million in proceeds by late 2025. Akira commonly gains access through VPNs without multifactor authentication, exploited vulnerabilities, and spear phishing. A notable 2025 incident involved a German cable manufacturer, where 27 GB of sensitive data was exfiltrated before encryption.

Qilin, a Russiabased ransomware-as-a-service operation, focused heavily on manufacturing and logistics. In one 2025 attack, Qilin stole 29,843 internal files from a manufacturing and logistics firm, creating downstream supply chain risk beyond the initial victim.

Play ransomware continued to impact U.S. manufacturers, with the FBI reporting approximately 900 affected entities by mid2025. Play is known for abusing valid credentials and disabling security controls prior to encryption, increasing operational impact.

Alongside ransomware groups, hacktivist and geopolitical actors such as NoName057(16) and Chinese – aligned defacement groups targeted industrial entities with denial-of-service attacks, OT reconnaissance, and public website defacement, particularly during periods of geopolitical tension.

The Most Common Attack Paths Into Manufacturing Networks

Manufacturing Attack Vectors

Ransomware remained the dominant threat vector, responsible for 890 manufacturing incidents in 2025. However, attackers used multiple entry points to gain access.

  • Exploited vulnerabilities accounted for 32 percent of attacks, frequently targeting legacy OT systems and public facing applications
  • Phishing and malicious email campaigns represented 23 percent of incidents, increasingly enhanced with AI-generated lures
  • Compromised credentials became more valuable, with industrial access credentials selling for $4,000 to $70,000 on dark web marketplaces
  • Supply chain compromise and remote access abuse enabled attackers to move laterally between IT and OT environments with limited detection

Beyond encryption, attackers also deployed data theft, extortion-only tactics, and information system disruption, reflecting a broader shift away from single vector attacks.

Regional Impact Highlights

In Europe, manufacturing represented 72 percent of industrial ransomware attacks in Q3 2025. Average ransom demands reached $1.16 million, more than double the previous year. High profile incidents disrupted automotive, aerospace, and transportation supply chains across multiple countries.

In the United States, manufacturing was the most attacked sector for the fourth consecutive year, with ransomware comprising nearly half of all industrial breaches. Median attack costs reached $500,000, excluding long-term operational losses.

India emerged as the APAC ransomware epicenter, with 65 percent of affected companies paying ransoms and average payments reaching $1.35 million, particularly within manufacturing and critical IT services.

A Manufacturing Cyber Security Reprioritization is Needed

A manufacturing cyber security shift is needed to reprioritize the following things:

  1. Manufacturers must implement Zero Trust architectures across both IT and OT environments, enforcing strict identity validation, least privilege access, and network segmentation.
  2. Vulnerability management and patching remain critical, particularly for VPNs, internet facing applications, and OT gateways. Patching and compensating controls, must be implemented in hours and not days/weeks, per the CTEM framework.
  3. Credential management must be significantly improved, from detecting leaked credentials, to implementing SSO/MFA.
  4. Immutable, offline backups are essential, as attackers increasingly target backup infrastructure.
  5. Employee training also requires renewed focus, as AI-assisted phishing continues to evolve.
  6. Finally, third-party risk management has become a core security function. Vendor access, SaaS integrations, and managed services now represent primary attack vectors rather than secondary concerns.
2026 Manufacturing Security Forecast

Cyber threats targeting manufacturers are expected to intensify further in 2026. AI-enabled ransomware, faster attack execution, reduced dwell time, and a continued shift toward data extortion are projected to define the next phase of industrial cyber risk.

Read the manufacturing threat landscape  to see what else shaped 2025 and what needs to be shifter in 2026.