Ransomware groups go for the money. This may suggest cybercriminals are primarily interested in valuable data or documents companies would be desperate to recover. But that’s not always the case.
Manufacturing is a significant target of cyberattacks. Experts say this is because malicious actors recognize that breaching a manufacturer’s defenses and disrupting operations can lead to costly production delays and supply chain disruptions.
Those painful delays can create enough pressure to coerce a victimized company into paying a ransom — a new and diabolical approach to criminality.
“Ransomware groups have moved away from random, wide-net approaches,” said Michael Tanji, director of cybersecurity for MxD, the National Center for Cybersecurity in Manufacturing as designated by the U.S. Department of Defense. “Many are now focused on finding targets that cannot afford to slow, much less stop, production. It gives attackers leverage.”
This helps explain why manufacturing is a primary target worldwide. Manufacturing accounted for 27.7% of cybersecurity incidents last year, more than any other industry, according to IBM’s 2026 X-Force Threat Intelligence Index.
Ransomware groups see two avenues to disruption. They may worm their way directly into a manufacturer’s operational technology. Or they may find another entry point, compelling a company to shut down production as a defense against the intrusion.
Either way, the cybercriminals can wreak havoc with production lines.
In this Q&A, Tanji describes the shifting ransomware landscape and offers advice for keeping manufacturing operations safe.
Describe the current ransomware landscape.
Michael Tanji: The threat has changed from blocking emails to stopping factory floors. Criminals have learned that a law firm can survive a few days without email, but an automotive plant loses thousands of dollars per minute when the line stops.
This is a carefully designed business model. The attackers use operational technology downtime as their main lever. This is where it gets weird because the hackers often understand the financial pressure points of your specific supply chain better than your own insurance company does.
How do cybercriminals launch these attacks?
M.T.: Criminals are using automated scanning tools to find unpatched remote access portals. Old virtual private networks or exposed firewalls are favorite targets.
Once inside, they use real administrative tools already built into operating systems or applications to blend in.
A major recent change in tactics involves data theft without any file encryption. Groups like ShinyHunters often skip locking files entirely. They just steal engineering designs, client lists, and formulas, then threaten to post them online if a victim does not pay.
If a factory refuses to pay the initial demand, attackers will threaten to email the company’s customers directly. They may also launch distributed denial-of-service attacks to knock the company’s public website offline during negotiations.
These multi-layered pressure tactics are meant to break the resolve of executives watching millions of dollars vaporize each day.
It sounds like attackers are becoming more sophisticated. True?
M.T.: Attackers are not just clicking “encrypt all.” They are studying the software used to plan production schedules and mix raw materials.
For example, groups may look for specific systems running manufacturing execution systems (MES) or supervisory control software. By targeting the precise server that tells the machines what to make next, they cause mass confusion. Employees cannot tell which batch of product is safe to run or where the inventory is supposed to go.
Identify some specific vulnerabilities manufacturers must understand.
M.T.: Here are some of the challenges:
Recovery time: Restoring specialized industrial databases requires manual calibration and testing for each machine.
OT environment rebuilds: You cannot simply spin up a virtual machine copy of an assembly line. Physical hardware must be wiped and reconnected to physical sensors.
Data corruption: Attackers are deliberately altering recipes, heating calibrations, or scheduling parameters, which means you cannot trust the integrity of your formulas even after you get the systems back.
Legacy systems: Many plants run critical equipment on old Windows or other operating systems that cannot support modern endpoint security tools.
Supply chain dependencies: If a small vendor providing specific heat-treatment services gets hit, an entire assembly line stops because of a lack of alternative suppliers.
What steps should companies take to defend themselves?
M.T.: Consider separating your corporate network from your factory floor network, or if you’ve integrated the two, having the capability in place to do so once you detect something going wrong.
Create strict choke points between the office internet and the assembly line machinery, so an infected email that lands in accounting cannot reach a robotic arm.
Any company failing to enforce multi-factor authentication (MFA) on every single system that can handle it is flirting with negligence. MFA is table stakes at this point. You must allocate the time to run tabletop exercises so people know what they’re supposed to do when things go sideways. The more dust that collects on your recovery plans, the less likely you are to recover quickly and cost-effectively.