BizInsider: Business | AI | Franchise | Strategy | OE | Lean

BizInsider: Business | AI | Franchise | Strategy | OE | Lean

Investment

Operational Excellence (OPEX) Insight – Tuesday - July 21, 2026: Hackers Found the Factory Floor: Manufacturing Is Now Ransomware's #1 Target.

Góc Nhìn Vận Hành Xuất Sắc – Thứ Ba, Ngày 21/07/2026: Tin Tặc Đã Tìm Đến Nhà Xưởng: Sản Xuất Thành Mục Tiêu Ransomware Số 1.

Jul 21, 2026
∙ Paid

Welcome To Operational Excellence (OPEX) Insight Article For The Paid Subscriber-Only Edition.

This is the bilingual post in English and Vietnamese. Vietnamese is below.

Đây là bài viết song ngữ Anh-Việt. Tiếng Việt ở bên dưới.

English

PART 1 – OFFICIAL INFORMATION

There is a truth few in manufacturing want to admit: the factory is now where hackers most love to aim. Cybersecurity reports in 2026 confirm that in the second quarter, manufacturing remained the industry most attacked by ransomware, and this is now the third consecutive year the sector has held that unwanted title. The numbers behind it are anything but gentle.

Start with the scale. Manufacturing alone accounts for about 26% of all ransomware incidents globally, meaning more than one in every four extortion-malware attacks lands on a factory. The trajectory is worrying too: ransomware incidents in the sector rose 61% in 2025, and counting industrial organizations specifically, the increase reached 87% in just two years. This is not a passing wave that then settles, but a trend thickening over time.

What makes the picture more serious is that the direction of attack has shifted toward the supply chain. Attacks targeting supply chains have risen roughly 431% since 2021, and in 2025 alone that figure doubled, averaging about 26 incidents a month. Attackers have grasped something very pragmatic: instead of drilling straight into a well-defended company, they slip in through a weaker third-party supplier, then spread into the whole network. Groups like Qilin repeatedly target industrial companies, while Cl0p is known for exploiting third-party software.

An example showing how heavy the consequences can be is the attack on Jaguar Land Rover in August 2025. Attackers exploited a vulnerability in a supplier’s software, deployed malware, and paralyzed manufacturing operations across three countries for five straight weeks. Five weeks for a carmaker is no minor inconvenience; it is a series of lines standing still, thousands of vehicles not rolling out, and a supply chain behind it dragged along. A hole in a link thought to be on the fringe was enough to stop an enormous machine.

In money terms, the damage is not abstract either. When you add up the costs of downtime, remediation, and reputational loss, each attack on the manufacturing sector causes average damage exceeding $4.2 million. And this figure is usually only the tip, because losses in customer trust or canceled contracts are hard to convert into currency.

Why has the factory become such easy prey? The answer lies in the very nature of operational technology. Most modern lines run on industrial control systems (ICS) and operational technology (OT) designed to run durably for decades, not to fend off hackers. They are old, hard to patch, loosely segmented, and very hard to monitor. When these aging OT systems are connected to modern IT networks to serve digitalization, each connection opens another door. Attackers understand that a factory cannot bear a production stoppage, so the pressure to pay ransom to restart the line is enormous, and that is precisely what they exploit.

What is notable from an operations lens is that the boundary between cybersecurity and operations has dissolved. A cyberattack now does not stop at data loss; it stops the physical line, turning a software incident into a production crisis. That means protecting the factory against ransomware is no longer the private affair of the IT department, but a core part of keeping the machine running. And to reason about it correctly, you need an operational model that examines exactly how layers of defense collapse.

Share

User's avatar

Continue reading this post for free, courtesy of BizInsider.

Or purchase a paid subscription.
© 2026 BizInsider · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture