Why This Matters to Distributors:Ransomware attacks are increasingly hitting midsized manufacturers and other companies embedded in distribution supply chains, creating potential disruptions to product availability, fulfillment, and customer deliveries.
Ransomware attacks against manufacturers increased 40% year over year in the first half of 2026, adding to cybersecurity risks across the supply chains that distributors rely on, according to new research from Black Kite.
Black Kite identified 1,183 manufacturing ransomware victims during the first seven months of 2026, up 39.7% from the same period a year earlier. The seven-month total also exceeded the number of manufacturing victims recorded during all of 2024.
The findings are part of Black Kite’s 2026 Manufacturing & Distribution Ransomware Report, released Sept. 17. The cybersecurity firm examined ransomware activity across manufacturing and distribution supply chains and analyzed characteristics of companies targeted in attacks.
Manufacturing accounted for 22% of the 7,551 publicly disclosed ransomware victims across all industries identified in Black Kite’s broader 2026 ransomware research. Manufacturing ranked first among industries for the fourth consecutive year, according to the firm.
The concentration of attacks among midsized companies could be particularly significant for distributors because those businesses frequently operate as manufacturers, suppliers, and service providers within larger supply chains.
About 70.2% of manufacturing victims identified in 2026 had annual revenue between $10 million and $100 million, while the median victim generated $42.9 million in annual revenue. Across North America and Europe, 73% of ransomware attacks from 2023 through the first half of 2026 involved midmarket companies.
“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” Ferhat Dikbiyik, Black Kite’s chief research and intelligence officer, said. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position.”
For distributors, an attack does not necessarily have to penetrate their own systems to affect operations. Ransomware that shuts down a manufacturer or other supplier can interrupt the flow of products through the supply chain and delay customer orders.
Black Kite’s research also points to a geographic shift in ransomware activity. The firm reported an 85.4% increase in European manufacturing victims, while the U.S. share of global manufacturing ransomware victims fell to 34.8% from 52.3%.
The number of U.S. victims declined to 412 from 443 indicating that the decrease in the U.S. share reflected faster growth in attacks elsewhere rather than a sharp decline in U.S. incidents
Germany recorded one of the larger increases. Manufacturing ransomware victims there rose more than 83% during the first seven months of 2026 compared with the same period in 2025, according to the report.
The ransomware groups responsible for attacks are also changing. Black Kite said 49.7% of manufacturing incidents identified in 2026 involved groups that were not present in its dataset in 2023 or 2024. One group, known as The Gentlemen, accounted for 12% of manufacturing incidents during 2026.
Black Kite based its report on intelligence collected from Jan. 1, 2023, through July 29, 2026. Its ransomware data includes confirmed, publicly disclosed ransomware and data-extortion incidents. The company also analyzed organizations’ externally observable cybersecurity exposures using nonintrusive methods intended to make approximate information available to potential attackers.
Do not miss any content from Distribution Strategy Group. Join our list.
