Ransomware groups go for the money. This may suggest cybercriminals are primarily interested in valuable data or documents companies would be desperate to recover. But that’s not always the case.
Manufacturing is a significant target of cyberattacks. Experts say this is because malicious actors recognize that breaching a manufacturer’s defenses and disrupting operations can lead to costly production delays and supply chain disruptions.
Those painful delays can create enough pressure to coerce a victimized company into paying a ransom — a new and diabolical approach to criminality.
“Ransomware groups have moved away from random, wide-net approaches,” said Michael Tanji, director of cybersecurity for MxD, the National Center for Cybersecurity in Manufacturing as designated by the U.S. Department of Defense. “Many are now focused on finding targets that cannot afford to slow, much less stop, production. It gives attackers leverage.”
This helps explain why manufacturing is a primary target worldwide. Manufacturing accounted for 27.7% of cybersecurity incidents last year, more than any other industry, according to IBM’s 2026 X-Force Threat Intelligence Index.