Decoding the world of cybersecurity

· ·

European manufacturing ransomware victims rise sharply

Black Kite recorded an 85.4% increase in European manufacturing ransomware victims, while Germany’s count rose by more than 83% during the first seven months of 2026.

European manufacturing ransomware victims rise sharply
Summary
  • Black Kite counted 1,183 manufacturing victims globally during the first seven months of 2026, up 39.7% year on year.
  • Its dataset shows European manufacturing victims rising 85.4%, with Germany increasing by more than 83%.
  • The figures describe publicly observed ransomware and extortion incidents rather than the complete underlying incidence of attacks.

European manufacturers are representing a growing share of publicly observed ransomware victims, according to new research that records an 85.4% year-on-year rise across Europe and an increase of more than 83% in Germany during the first seven months of 2026.

Black Kite counted 1,183 manufacturing victims globally over the seven-month period, up 39.7% from the equivalent period a year earlier and already above the company’s full-year 2024 total.

The figures come from Black Kite’s 2026 Manufacturing & Distribution Ransomware Report and should be read as a vendor intelligence dataset rather than an official census of ransomware incidents. The company tracks confirmed and publicly disclosed ransomware and data-extortion events alongside externally observable cyber-risk data.

Within that dataset, the geographic distribution shifted markedly. Black Kite said the US share of global manufacturing ransomware victims fell from 52.3% to 34.8%, largely because victim counts rose elsewhere rather than because US activity collapsed. European victims increased 85.4%.

Germany stands out. Black Kite recorded an increase of more than 83% in German manufacturing victims during the first seven months of 2026 compared with the same period in 2025. Manufacturing accounts for a substantial part of German economic output, making disruption in the sector relevant beyond individual victim companies.

The research also points to concentration among mid-sized businesses. Organisations with annual revenue between $10 million and $100 million represented 70.2% of the manufacturing victims in Black Kite’s dataset, while the median victim generated $42.9 million in revenue.

That distribution matters because manufacturing resilience is often evaluated around large strategic groups while operational dependencies can sit with substantially smaller suppliers. A component manufacturer, logistics provider, specialist engineering company, or regional distributor can interrupt production even when its own turnover is modest relative to the customer depending on it.

The report also describes rapid churn among ransomware operators. Black Kite said 49.7% of manufacturing incidents recorded in 2026 involved groups absent from its dataset in 2023 and 2024. That weakens the value of supplier assessments focused heavily on named groups or a fixed picture of attacker behaviour.

The latest numbers extend a trend Cyber Insider has already tracked in industrial ransomware activity across multiple regions, but the manufacturing-specific dataset sharpens the European exposure. The increase is not simply a result of more US incidents being reported under a global label; Black Kite records substantial growth inside Europe itself.

Manufacturing also presents leverage for extortion because downtime can immediately affect production commitments, inventory, customers, and downstream businesses. The cost of an attack can therefore spread through commercial relationships before the victim has determined whether encrypted systems or stolen information can be restored.

Ransomware leak-site and intelligence datasets remain imperfect measures. Not every attack is disclosed, criminal claims can be false or duplicated, and changes in monitoring coverage affect trend lines. Black Kite says its analysis uses confirmed, publicly disclosed ransomware and data-extortion incidents, which improves consistency but cannot describe the full number of attacks occurring privately.

Even with those limits, the European growth is substantial enough to alter the geographic picture within the company’s dataset. Manufacturing ransomware is no longer represented predominantly as a US-heavy phenomenon, while Germany’s increase places one of Europe’s most industrialised economies directly inside the shift.

×