Report: Manufacturing Remains Most Targeted Industry for Cyberattacks

But they are coming for logistics, food and beverage and automotive.

Construction worker in safety gear analyzing data charts on computer monitor in industrial facility
iStock

San Jose, California -- Cybersecurity platform Zscaler today released new findings from its ThreatLabz 2026 Ransomware Report, which indicates that AI has driven an overall increase in ransomware attacks across all industries by more than 275% year over year. These attacks have cost companies an estimated $328 million in payments—the average ransom payment rose 5.3% to $431,995.

The amount of data stolen has been staggering, according to the research. Nearly 900 terabytes of data were ransomed; that's about 90 times the print collection at the Library of Congress.

Manufacturing Targeted Most by Ransomware Attacks

Manufacturing remains the most targeted industry, facing 1,025 ransomware attacks from April 2025 through March 2026. By comparison, the tech industry was a distant second, facing 605 attacks, followed by construction (568), healthcare (508), and legal (435). The food, beverage and tobacco industry faced 145 attacks, freight and logistics services were hit 132 times, and the automotive industry was targeted 131 times, according to data leak sites.

While it faced fewer attacks, the freight and logistics industry saw a significant uptick in attacks, increasing 725% year-over-year, the greatest percentage change of any other industry. Food, beverage and tobacco increased 179%, and automotive saw an 87% uptick. While manufacturing was targeted most often, the industry actually experienced a 4% decline in ransomware attacks year over year.

The U.S. continues to bear a disproportionate share of ransomware activity, with organizations accounting for 50.7% of attacks—more than 10x that of any other country. Canada (4.8%), Germany (4.3%) and the United Kingdom (4.1%) followed, after which each country fell below a 3% share.

Manufacturing Has the Most Victims By Far

The manufacturing industry accounted for 35.5% of all ransomware victims. The study said the high cost of operational disruption and downtime in manufacturing environments makes it a prime target, as production often depends on tightly timed processes and interconnected IT (information technology) and OT (operational technology) environments. IT manages data, software, computers and digital communication networks, while OT covers physical machinery, industrial equipment and real-time processes.

Even short disruptions can quickly become costly. For example, a recent Siemens study, “The True Cost of Downtime 2024,” found that an hour of stopped automotive production lines averages $2.3 million—about $38,333 per minute (or more than $600 every second).

More than 12 companies had more than one employee who fell victim to these attacks. Compromising multiple employees increases attackers’ chances of accessing an organization’s sensitive data and business-critical systems, because multiple identities can also give attackers alternate paths if one account is detected, disabled, or contained, helping them preserve access and keep pressure on the organization.

Advancements in AI have driven the rise in ransomware attacks, which now target nearly two-thirds of senior-level executives. These bad actors are increasingly using trusted workplace tools, like Microsoft Teams, to enable data theft. Manager-level titles and above accounted for 62% of victims, highlighting a focus on employees with privileged roles and business influence.

The study is designed to show how employees with privileged access to customer data and operational systems pose the highest risk, so security teams evaluate the systems, applications and resources employees can access or manage. Employee access should be limited to only the systems and data required for the role, according to Zscaler.

Ransomware’s Rapid Expansion

The ransomware landscape is expanding significantly. ThreatLabz, Zscaler's security research arm, identified 52 newly active groups in the last year. The report offers guidance on disrupting ransomware across the attack lifecycle. It also examines the current threat landscape in depth, including exfiltration trends, victim targeting, evolving attacker tradecraft and extortion economics. For example, ransomware operators are increasingly using a common initial-access playbook that combines spam bombing and vishing (voice phishing) with callers who impersonate IT staff to deploy malware tooling that establishes a foothold. In these attacks, the threat actor performs some basic information gathering to obtain a person’s name, email address and company-specific information (such as IT staff names).

"[Threat actors] are using GenAI to speed up operations and focusing on stealing more of an organization’s intellectual property, customer information, and other sensitive data to drive payment,” said Deepen Desai, executive vice president of cybersecurity at Zscaler. “Security teams need to stop these attacks early by reducing initial access opportunities, limiting lateral movement, and preventing data exfiltration."

Read the full report here: https://www.zscaler.com/campaign/threatlabz-ransomware-report.

Page 1 of 36
Next Page