Site icon Soko Directory

Manufacturing Blocks More Ransomware As Attackers Pivot To Data Theft

Sophos

Sophos announced new findings from the Sophos State of Ransomware in Manufacturing and Production 2025 report.

The study reveals that manufacturers are stopping more ransomware attacks before data can be encrypted; however, adversaries are increasingly stealing data and using extortion-only tactics to maintain pressure. As a result, more than half of manufacturing organizations impacted by encryption paid the ransom despite progress in defensive measures. The report is based on an independent survey of 332 manufacturing organizations that were hit by ransomware in the last year.

The Sophos State of Ransomware in Manufacturing and Production report found:

Encryption rates are falling, but adversaries are shifting tactics: 40% of attacks on manufacturers resulted in data encryption, the lowest level in five years, and down from 74% last year. However, extortion attacks surged to 10% from just 3% in 2024 as attackers increased reliance on data theft for leverage.

“Manufacturing depends on interconnected systems where even brief downtime can stop production and ripple across supply chains,” said Alexandra Rose, Director of Threat Research, Sophos Counter Threat Unit. “Attackers exploit this pressure: despite encryption rates falling to 40%, the median ransom paid still reached $1 million. While half of manufacturers stopped attacks before encryption, recovery costs average $1.3 million and leadership stress remains high. Layered defenses, continuous visibility, and well-rehearsed response plans are essential to reduce both operational impact and financial risk.” 

What Sophos is Seeing in Manufacturing

Over the past twelve months, Sophos X-Ops has observed ransomware activity across leak sites and found that 99 distinct threat groups targeted manufacturing organizations. The most prominent groups targeting manufacturing organizations based on leak site observations are GOLD SAHARA (Akira), GOLD FEATHER (Qilin) and GOLD ENCORE (PLAY).  Reflecting the trends revealed in the report, in over half of the ransomware incidents that Sophos Emergency Incident Response was brought in to remediate, attackers both stole and encrypted data, highlighting the use of double extortion tactics where data is held for ransom and threatened with release on a leak site.

Based on its experience protecting manufacturing organizations worldwide, Sophos recommends the following best practices to help businesses stay ahead of ransomware and other cyberthreats:

Read Also: New Sophos–Microsoft Copilot Integration Democratizes Advanced Cyber Threat Intelligence for Organizations of All Sizes

Exit mobile version