Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Ransomware in Europe 2026: manufacturing hit hardest

Black Kite reports disclosed ransomware in Europe rose 55% in 2026, with manufacturing the top target. What it means for companies across the EU.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
2 July 2026
READING TIME
9 min read
TOPIC
Threats and Incidents
Ransomware in Europe 2026: manufacturing hit hardest

Ransomware in Europe is not slowing down in 2026 — quite the opposite, it’s accelerating. According to a Black Kite report on the European threat landscape, the number of publicly disclosed ransomware attacks rose by about 55% year-on-year in the first four months of 2026. The most frequently attacked sector is manufacturing, and a significant share of incidents is driven by breaches via suppliers. For companies across the EU — with economies heavily rooted in manufacturing and subcontracting — this isn’t foreign trivia but a description of their own risk landscape.

What the data says

A few takeaways from the reported trends of the first half of 2026 (figures per Black Kite; interpretation ours):

  • A ~55% rise in disclosed ransomware attacks in Europe in the first four months of 2026 versus the same period a year earlier.
  • Manufacturing is target no. 1 — industry accounted for the largest share of disclosed attacks (close to 28%). Behind it: professional services, healthcare, retail and transport.
  • Geographic concentration — the most cases were recorded in Germany, followed by the UK, France, Italy and Spain; together these countries accounted for the majority of incidents.
  • Suppliers as the weak link — a growing share of breaches begin not at the victim but at their supplier or in third-party software.

Two honest caveats are needed. First, these are disclosed attacks — the real number is higher, because some victims pay or stay silent. Second, not every country sits in the top tier of the ranking, but the whole region shares a risk profile: lots of manufacturing, dense supply chains and rising regulatory pressure.

Why manufacturing gets hit most

Manufacturing is a prize for ransomware operators for several reasons. Downtime is immediately expensive — a halted line means real losses per hour, so the pressure to pay is enormous. These environments blend old OT systems (controllers, machines) with the IT network, and such systems can’t be patched like a laptop. Add an extensive supply chain: access to one subcontractor can be the doorway to a larger partner.

That’s important context wherever manufacturing and subcontracting for larger corporations are a pillar of the economy. An attack on a supplier in one country can halt a factory in another — and vice versa. The risk is shared, and assessing it is exactly third-party risk management.

NIS2: regulatory pressure is part of the picture

The rise in attacks comes alongside tighter requirements. The NIS2 directive covers a far broader set of entities than earlier rules — including many manufacturers and suppliers who never thought of themselves as “critical infrastructure.” NIS2 mandates, among other things, risk management, supply-chain security controls and fast incident reporting. Treat it as paperwork and you miss the point: it’s a list of the minimum you need anyway to survive the trends above. We laid it out in our piece on NIS2 obligations.

What to do about it — concrete steps

The trend is worrying, but ransomware defence is well understood. Priorities:

Ransomware-resistant backups. The 3-2-1 rule, with an offline or immutable copy and regular restore testing. A backup you’ve never restored is an assumption, not a safeguard.

MFA and patching on anything internet-facing. Most attacks come in through remote access: VPN, RDP, panels. Phishing-resistant MFA and short patch windows for edge services close the most common doors. It’s part of a standing vulnerability-management process.

IT/OT segmentation. Separate the production network from the office one, so an email infection doesn’t halt the line. For systems that can’t be patched, isolation is the basic control.

A response plan and supplier fallback. Have a ready scenario for “it blew up here” and “it blew up at a supplier.” Knowing whom to notify and how to restore a critical process determines the length of downtime. We laid out the fundamentals in the guide on how to actually defend against ransomware.

Frequently asked questions (FAQ)

Our country isn’t in the top tier — can we relax? No. The ranking counts disclosed attacks, and the whole region shares a risk profile: lots of manufacturing and subcontracting, dense supply chains and proximity to the most-hit countries. Being “outside the top tier” is not the same as being out of range.

We’re a small plant — does this affect us? Yes, doubly. Smaller suppliers are targeted precisely as a route to a larger partner, and they have fewer resources to defend. The good news: the basics (backups, MFA, patching, segmentation) are within any company’s reach.

What does NIS2 give us, since it’s just more obligations? NIS2 is, in practice, a list of the minimum you need anyway against rising attacks: risk management, supply-chain security and incident reporting. Instead of treating it as paperwork, use it as a ready-made structure for your security programme.

Where do we start on a limited budget? With the best effort-to-cost items: tested offline backups, MFA on remote access, and fast patching of internet-facing services. Get in touch and we’ll help set priorities for your reality.

Summary

A roughly 55% rise in ransomware attacks in Europe, with manufacturing in first place, is a signal that companies — especially in manufacturing and subcontracting — shouldn’t ignore. The threat increasingly arrives via suppliers, and NIS2 raises the bar of requirements. Defence is no secret: tested backups, MFA, fast edge patching, IT/OT segmentation and a real response plan. If you want to see how your organisation stacks up against these trends — let’s start with a resilience assessment.


Sources and further reading: Help Net Security — Black Kite report, ENISA Threat Landscape, ENISA.

SHARE / COPY