Manufacturing is still ransomware’s favorite industry—and the victim profile keeps sliding toward the shops that keep supply chains moving. On Sept. 17, 2026, Black Kite released its Manufacturing & Distribution Ransomware Report 2026, with coverage from PR Newswire and SecurityWeek. The headline numbers are blunt: 1,183 manufacturing victims in the first seven months of 2026—up 39.7% year over year, and more than all of 2024 in seven months alone.
Manufacturing ranked #1 for the fourth consecutive year, accounting for 22% of 7,551 publicly disclosed ransomware victims in Black Kite’s broader 2026 research. Attacks on manufacturers have more than doubled since 2023, with roughly a 40% YoY increase in H1 2026. For mid-market industrial SMBs—and for exhibit and experiential fabrication shops that run CAD, ERP, shop-floor systems, and show-install logistics—the report is a continuity briefing, not abstract enterprise risk.
Mid-market is the main target
Black Kite’s data pushes back on the idea that only Fortune-scale plants get hit. 70.2% of manufacturing victims sat in the $10M–$100M revenue band; the median victim generated $42.9M in annual revenue. From 2023 through H1 2026, 73% of ransomware attacks in North America and Europe hit mid-market companies. Those firms often sit inside larger OEM and brand supplier networks—so one shop’s downtime becomes a customer’s missed ship date.
Geography is shifting too. European manufacturing victims rose 85.4%, while the U.S. share of global manufacturing ransomware victims fell from 52.3% to 34.8%. The U.S. count barely moved (about 412 victims)—the share drop came from growth elsewhere, not a sudden U.S. lull. Shops in Georgia, Tennessee, and Alabama still operate in a high-volume region; the global pie simply got wider.
New groups, same shop-floor pressure
Nearly half—about 49.7%—of 2026 manufacturing incidents came from groups that were absent two years earlier. The Gentlemen, first appearing in Black Kite’s dataset in September 2025, had claimed 142 manufacturing victims by mid-2026—roughly 12% of the year’s manufacturing incidents and 23.1% of that group’s own activity. Names change; the operational bait does not.
Ferhat Dikbiyik, Black Kite’s Chief Research & Intelligence Officer, put the attraction plainly: one successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. Reconnaissance, he notes, leans on externally visible signals—unpatched systems, exploitable services, leaked credentials, and misconfigured defenses—the same vantage point shops can measure before a breach.
What this means for fabrication and industrial SMBs
Exhibit houses, experiential fabrication shops, metals fabricators, and other mid-market manufacturers share the same crown jewels: CAD and design IP, ERP and job scheduling, HR/payroll, and the office/shop network that ties them together. Flat IT/OT layouts, shared vendor VPNs, and same-domain-only backups turn phishing into a show-week outage. Cleaning the external attack surface customers (and adversaries) can already see is table stakes before the next RFQ.
Clear takeaway
Black Kite’s 2026 manufacturing report shows ransomware volume surging into mid-market shops—treat CAD, ERP, shop-floor, and vendor remote access as crown jewels: MFA everywhere, segment office from production, immutable backups with tested restores, and continuous external attack-surface hygiene so a supplier-network headline does not become your install-week crisis.
Actions to take this week
- Require MFA on email, VPN, ERP, CAD servers, and any shared “shop” accounts—password-only remote access remains the cheapest path onto a fabrication network.
- Segment office IT from shop-floor / OT where practical so a compromised workstation does not equal a full production stop.
- Tighten vendor VPN hygiene: unique accounts, MFA, time-bounded access, and a revoke path when install crews or contractors roll off.
- Keep immutable backups of CAD libraries, ERP/job data, and HR/payroll—and run a restore test before the next show or peak ship week.
- Reduce externally visible attack surface (exposed RDP, forgotten admin portals, stale credentials) and answer customer diligence with evidence—not hope.
Brotherly Technology helps manufacturers, exhibit and experiential fabrication shops, and industrial SMBs across Rome, Northwest Georgia, and metro Atlanta turn sector ransomware research into a short continuity review. Black Kite’s Sept. 17, 2026 report is a timely reminder that mid-market shop floors—not only enterprise plants—are where volume lives.
Sources:
- PR Newswire — Black Kite Manufacturing & Distribution Ransomware Report 2026 (Sept. 17, 2026) — 1,183 mfg victims in seven months (+39.7% YoY); #1 sector fourth year / 22% of 7,551; mid-market 70.2% in $10M–$100M, median $42.9M; 73% NA/Europe mid-market 2023–H1 2026; ~49.7% from newer groups; The Gentlemen 142 / ~12% / 23.1%; Europe +85.4%, US share 52.3%→34.8% (~412); RSI stats; Ferhat Dikbiyik quote.
- SecurityWeek — Kevin Townsend, Sept. 17, 2026 — Corroborates ~40% surge, mid-market framing, The Gentlemen 142/~12%, Europe +85%, US ~412, Dikbiyik quote.
- Black Kite — 2026 Manufacturing & Distribution report — Primary report landing page.