Security1 publisher3 min readPublished
Manufacturing ransomware victims rose 40% in seven months as European counts grew 85%
Black Kite's 2026 report locates the target set in the mid-market supplier layer that larger manufacturers buy from, and the Bank of England has already tied one carmaker's shutdown to a slowdown in UK growth figures.
The Watch · Security desk

What happened
- Black Kite counted 1,183 new ransomware incidents against manufacturers in the first seven months of 2026, a 40% increase on the same stretch of 2025.
- European manufacturing victims grew 85% year over year, while the US count came in almost identical to 2025.
- More than 5,000 other companies were affected by Jaguar Land Rover's UK plant shutdown, which stopped daily production of around 1,000 luxury vehicles.
- The UK's Cyber Monitoring Centre put the impact of that incident at GBP 1.9 billion and called it the most economically damaging cyberattack in UK history, ahead of 2017's WannaCry.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure By Black Kite's account the victims are concentrated in the mid-market, so a large manufacturer's exposure sits in the patch state and credential hygiene of firms it does not run and cannot instrument.
- cost The bill for a production stoppage keeps arriving after the incident is closed: Jaguar Land Rover says it will cut 4,000 jobs and blames the cyberattack.
- decision Anyone holding single-country supply in Germany now has a concrete number to weigh, 77 attacks in seven months against a sector worth a fifth of that economy.
- contradiction The report's own regional figures imply a rise nearer 45% than the headline 40%, so the growth claim is conservative and the reconciliation turns on how loosely two hedged phrases are read.
Black Kite's 40% figure and the Jaguar Land Rover shutdown do not measure the same thing. The comparison runs January to July 2026 against the same months of 2025 [1]. Jaguar Land Rover's UK plants were down through September 2025 [17], outside both windows [8]. The Bank of England suggested that shutdown contributed to a slowdown in national growth figures [19]. The report does not put a cost on the 1,183 incidents it counts [1].
What the count measures is the supplier layer. "The mid-sized manufacturers absorbing most of these attacks are the supplier layer from which larger enterprises assemble their products. When the mid-market is the primary target, a large manufacturer's vendor list is its attack surface," the report said [4]. Black Kite identified 5,237 disclosed victims across manufacturing and distribution between January 2023 and July 2026 [3].
The regional counts add up: 412 in the US, 369 in Europe and 402 in the rest of the world make 1,183 [11][12][13][1]. US volume was almost identical to last year's, so the fall in the US share from 52% to 35% comes from growth elsewhere [9][10][9]. Europe's 85% growth puts the prior-period European figure near 200, an increase of about 169 [9][2]. A near-doubling in the rest of the world adds roughly 197 more [13][3]. Those two increases alone imply a prior total near 817 and a rise closer to 45%, where the stated 40% implies 845 [4][7]. Looser readings of "almost identical" and "almost doubled" close most of that gap.
Half of the 2026 attacks came from groups that did not exist two years ago [5]. The Gentlemen, first seen by Black Kite in September 2025, had claimed 142 manufacturing victims by mid-2026 and accounted for 12% of the year's attacks [6][7]. Twelve per cent of 1,183 is 142 [5]. Qilin leads the current ranking, followed by The Gentlemen, Akira, DragonForce and INC Ransom [8].
Germany took 77 attacks, the highest count in Europe, in an economy where manufacturing was 20% of output in 2024 [14]. SafePay ran 22% of German attacks in 2025 and remains among the most active groups there [15]. Italy recorded 57, the UK 43 and France 40 [16].
"What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact," said Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. "One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker's negotiating position." Reconnaissance, he said, "relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses" [22][23].
Distribution runs at lower volume, with smaller victims [24]. The sector recorded 196 incidents in 2025 and 95 in the first half of 2026 [25]. Clop's January and February 2025 campaign alone took 52 of those victims, more than a quarter of the year's total [26]. Excluding it, comparable periods run from 75 in 2025 to 95 in 2026 [27], a 27% rise [6].
What to watch
- Whether The Gentlemen holds a double-digit share of manufacturing victims through the second half of 2026 or fragments.