Cybersecurity

Mid-Market Manufacturers Are Ransomware's Main Target: What Black Kite's 2026 Report Means for Shop Floors

Black Kite's Sept. 17, 2026 Manufacturing & Distribution report: 1,183 manufacturing victims in seven months (+39.7% YoY), mid-market $10M–$100M carries 70.2% of victims (median $42.9M). Practical continuity for industrial SMBs and exhibit/fab shops—MFA, IT/OT segment, vendor VPN, immutable CAD/ERP backups, external attack-surface hygiene.

Manufacturing is still ransomware’s favorite industry—and the victim profile keeps sliding toward the shops that keep supply chains moving. On Sept. 17, 2026, Black Kite released its Manufacturing & Distribution Ransomware Report 2026, with coverage from PR Newswire and SecurityWeek. The headline numbers are blunt: 1,183 manufacturing victims in the first seven months of 2026—up 39.7% year over year, and more than all of 2024 in seven months alone.

Manufacturing ranked #1 for the fourth consecutive year, accounting for 22% of 7,551 publicly disclosed ransomware victims in Black Kite’s broader 2026 research. Attacks on manufacturers have more than doubled since 2023, with roughly a 40% YoY increase in H1 2026. For mid-market industrial SMBs—and for exhibit and experiential fabrication shops that run CAD, ERP, shop-floor systems, and show-install logistics—the report is a continuity briefing, not abstract enterprise risk.

Mid-market is the main target

Black Kite’s data pushes back on the idea that only Fortune-scale plants get hit. 70.2% of manufacturing victims sat in the $10M–$100M revenue band; the median victim generated $42.9M in annual revenue. From 2023 through H1 2026, 73% of ransomware attacks in North America and Europe hit mid-market companies. Those firms often sit inside larger OEM and brand supplier networks—so one shop’s downtime becomes a customer’s missed ship date.

Geography is shifting too. European manufacturing victims rose 85.4%, while the U.S. share of global manufacturing ransomware victims fell from 52.3% to 34.8%. The U.S. count barely moved (about 412 victims)—the share drop came from growth elsewhere, not a sudden U.S. lull. Shops in Georgia, Tennessee, and Alabama still operate in a high-volume region; the global pie simply got wider.

New groups, same shop-floor pressure

Nearly half—about 49.7%—of 2026 manufacturing incidents came from groups that were absent two years earlier. The Gentlemen, first appearing in Black Kite’s dataset in September 2025, had claimed 142 manufacturing victims by mid-2026—roughly 12% of the year’s manufacturing incidents and 23.1% of that group’s own activity. Names change; the operational bait does not.

Ferhat Dikbiyik, Black Kite’s Chief Research & Intelligence Officer, put the attraction plainly: one successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. Reconnaissance, he notes, leans on externally visible signals—unpatched systems, exploitable services, leaked credentials, and misconfigured defenses—the same vantage point shops can measure before a breach.

What this means for fabrication and industrial SMBs

Exhibit houses, experiential fabrication shops, metals fabricators, and other mid-market manufacturers share the same crown jewels: CAD and design IP, ERP and job scheduling, HR/payroll, and the office/shop network that ties them together. Flat IT/OT layouts, shared vendor VPNs, and same-domain-only backups turn phishing into a show-week outage. Cleaning the external attack surface customers (and adversaries) can already see is table stakes before the next RFQ.

Clear takeaway

Black Kite’s 2026 manufacturing report shows ransomware volume surging into mid-market shops—treat CAD, ERP, shop-floor, and vendor remote access as crown jewels: MFA everywhere, segment office from production, immutable backups with tested restores, and continuous external attack-surface hygiene so a supplier-network headline does not become your install-week crisis.

Actions to take this week

  1. Require MFA on email, VPN, ERP, CAD servers, and any shared “shop” accounts—password-only remote access remains the cheapest path onto a fabrication network.
  2. Segment office IT from shop-floor / OT where practical so a compromised workstation does not equal a full production stop.
  3. Tighten vendor VPN hygiene: unique accounts, MFA, time-bounded access, and a revoke path when install crews or contractors roll off.
  4. Keep immutable backups of CAD libraries, ERP/job data, and HR/payroll—and run a restore test before the next show or peak ship week.
  5. Reduce externally visible attack surface (exposed RDP, forgotten admin portals, stale credentials) and answer customer diligence with evidence—not hope.

Brotherly Technology helps manufacturers, exhibit and experiential fabrication shops, and industrial SMBs across Rome, Northwest Georgia, and metro Atlanta turn sector ransomware research into a short continuity review. Black Kite’s Sept. 17, 2026 report is a timely reminder that mid-market shop floors—not only enterprise plants—are where volume lives.

Sources:

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation