Manufacturing accounted for 22% of publicly disclosed ransomware victims from April 2025 through March 2026, retaining its position as the most-targeted sector for a fifth consecutive year. Recorded incidents rose about 40% year over year to 1,183 in the first seven months of 2026, with European victims increasing 85.4% and Germany facing particular pressure. Attackers target manufacturers because production stoppages, delayed deliveries, and supply-chain disruption increase leverage in extortion negotiations; the Jaguar Land Rover incident and Clop’s exploitation of Cleo illustrate the potentially broad downstream impact.
New and established ransomware-as-a-service operations are driving the increase. Qilin claimed the most victims during the reporting period, while SafePay focused heavily on German manufacturers and The Gentlemen expanded rapidly; in Japan, The Gentlemen led observed activity with 14 of 90 ransomware incidents from January through July, where manufacturing was also the most affected sector and 78% of victims were small and medium-sized organizations. Talos identified The Gentlemen infrastructure consistent with reconnaissance, Active Directory compromise, credential theft, lateral movement, backup theft, and exfiltration to Wasabi cloud storage, while Qilin-linked endpoint-wiping and Veeam-backup destruction scripts showed signs of likely LLM-assisted development.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Black Kite published a report finding that manufacturing accounted for 22% of disclosed ransomware victims from April 2025 through March 2026 and remained the most targeted sector for a fifth consecutive year. It recorded 1,183 manufacturing incidents from January 1 to July 29, 2026, about 40% more than the equivalent 2025 period, with European victims rising 85.4%.
The Gentlemen's leak-site listings exceeded 100 organizations for the first time in June 2026, reaching 108 listings; its listings had numbered 48 in January.
Cisco Talos recorded 90 ransomware incidents affecting Japanese organizations from January through July 2026, up from 86 in the corresponding 2025 period. Manufacturing represented 34% of victims, and The Gentlemen was the most frequently observed group with 14 incidents.
Black Kite first observed The Gentlemen in September 2025. The group later became a significant contributor to ransomware activity targeting manufacturers.
Jaguar Land Rover shut down its UK plants throughout September 2025 following a cyberattack, halting production of roughly 1,000 luxury vehicles per day and disrupting more than 5,000 other companies in its supply chain.
The Gentlemen began operating as a ransomware-as-a-service group around July 2025, using double extortion against victims.
A Clop campaign targeting Cleo in January and February 2025 produced 52 disclosed distribution-sector victims and ultimately resulted in nearly 400 publicly disclosed victims.
Talos identified infrastructure associated with The Gentlemen containing reconnaissance, exploitation, Active Directory compromise, credential theft, backup theft, and Wasabi cloud exfiltration tooling; Russian-language artifacts suggested possible Russian-speaking operator involvement. Talos also found Qilin-associated wiping, backup-destruction, and ransomware-deployment Python scripts with characteristics suggesting likely LLM-assisted generation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcesecurityweek.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.