31193775299?profile=RESIZE_400xThe manufacturing sector recorded an overall risk rating of 6.7 out of 10, classified as elevated, according to the latest Cyfirma Industry Report for Q2 2026.  The findings are based on 90 days of telemetry across five threat categories and reveal sustained pressure from ransomware and advanced persistent threat activity.  Ransomware affected 279 victims across 49 countries during the period.  This figure represented 12.48% of all ransomware victims globally, marking the most concentrated exposure of any single industry.  Food and beverage production along with machinery and heavy equipment emerged as the most targeted sub-sectors.[1]

Victim numbers rose steadily from September 2025, reaching a peak of 115 in March 2026 before settling into the low-to-mid 90s.  This pattern indicates a new elevated baseline rather than a return to previous levels.  Sixty-two per cent of active ransomware gangs recorded victims in the sector.  The Akira group directed more than a quarter of its global activity, specifically at manufacturing organizations.

Twenty advanced persistent threat campaigns impacted manufacturing organizations across 31 countries.  The broadest grouping of China-linked actors observed in any sector operated during this period.  Operating systems faced targeting at a notably higher rate, reflecting greater exposure to operational technology and host-level systems in industrial environments.

Reported incidents included the FortiBleed campaign, which harvested 110 million credentials from more than 430,000 FortiGate firewalls.  These devices are commonly deployed at IT and OT segmentation boundaries in manufacturing settings.  The sector recorded 171 CVE mentions, placing it sixth overall for vulnerability disclosures.  Remote code execution vulnerabilities more than quadrupled during the period and remained elevated through to the end.  Other categories such as injection attacks and denial of service also showed mid-period spikes before partial declines.

The manufacturing threat landscape is expected to remain elevated over the next 90 days.  Ransomware activity is projected to stay at the new higher baseline of between 270 and 300 victims.  Sustained APT volume, continued dominance by China-linked actors and growing exposure of control systems point to ongoing challenges.

Organizations are advised to strengthen defenses around operational technology environments and maintain vigilance against both ransomware and state-linked intrusion attempts.

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://www.cybersecurityintelligence.com/blog/manufacturing-sector-faces-elevated-ransomware-and-apt-risks-9522.html

 

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!