Ransomware continues to pose a significant threat to the manufacturing and logistics industries, with attackers increasingly targeting these sectors due to their critical role in global supply chains. According to Black Kite's 2025 Manufacturing Research Report, manufacturing has been the top target for ransomware groups for four consecutive years, accounting for 22% of all reported attacks between April 2024 and March 2025. This equates to 1,314 attacks out of a total of 6,046, highlighting the persistent focus of cybercriminals on this sector. The report notes that while newer ransomware groups may favor smaller companies, large manufacturing enterprises remain highly attractive targets due to the potential for widespread operational disruption. Attackers are not acting indiscriminately; they deliberately target manufacturing because any interruption can have cascading effects throughout the supply chain. The evolution of ransomware tactics is also notable, with some groups shifting from traditional encryption-based extortion to pure data theft and extortion, and others leveraging artificial intelligence to enhance their attacks. The Dragos Industrial Ransomware Analysis for Q2 2025 corroborates these findings, emphasizing that manufacturing remains the most impacted sector. Companies are responding by strengthening their cybersecurity postures, particularly through improved patch management protocols and increased awareness of the threat landscape. The logistics sector has also been severely affected, as illustrated by the ransomware attack on Kantsu, a midsize Japanese logistics company. On September 12, 2024, Kantsu's internal network and all systems were locked by ransomware, halting shipping operations and cutting off communications both internally and externally. The attack rendered all company data unavailable, impacting over 500 partner companies and threatening the very survival of the business. Kantsu's experience underscores the importance of business resilience and the need for robust incident response plans. The company, which had invested in cloud-based warehouse management systems to streamline operations, found itself grappling with the operational and reputational fallout of the attack. The incident highlights the broader trend of ransomware groups targeting organizations whose operational continuity is vital to the functioning of other businesses. Both manufacturing and logistics companies are increasingly aware that their critical position in supply chains makes them prime targets for cybercriminals. As a result, there is a growing emphasis on proactive defense measures, including timely software updates, employee training, and the adoption of advanced security technologies. The ongoing battle between ransomware actors and these industries is driving innovation in both attack techniques and defensive strategies. The stakes are high, as successful attacks can disrupt not only individual companies but also the broader economy. The need for cross-sector collaboration and information sharing has never been greater, as organizations seek to stay ahead of evolving threats. Ultimately, the fight against ransomware in manufacturing and logistics is an escalating battle, with both sides adapting rapidly to new challenges and opportunities.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Reporting described ransomware as an intensifying threat to factory-floor and industrial environments, reflecting a broader escalation in attacks against manufacturing and OT operations. The coverage frames this as an ongoing trend rather than a single newly disclosed breach.
A ransomware attack hit Japanese logistics company Kantsu, creating a business resiliency crisis and forcing the company to respond to operational disruption. The incident is described retrospectively in reporting on the company's response measures.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.