Ransomware: Why Manufacturing Became Hackers’ Top Target
If the question is “which industry do criminals attack most?”, intuition says banking — after all, that is where the money is. Reality, however, has been different for years: manufacturing leads the incident rankings, pressured above all by ransomware. The reason is cold and rational: a stopped production line costs so much per hour that the victim tends to pay fast.
That is why, in this article, we explain why manufacturing became the preferred target for data hijacking, how this crime works today and what an industrial operation must do to avoid funding the next attack. We speak from the experience of protecting production environments and the SAP systems that support them.
Why manufacturing became target number one
Three factors combine. First, criticality: manufacturing sits at the base of supply chains — when it stops, customers, carriers and retail stop with it. That pressure plays in the extortionist’s favor.
Second, uneven maturity. The financial sector invested heavily in security and reaped the results; part of the crime migrated to less prepared sectors. Third, IT/OT convergence: sensors, controllers and shop-floor systems were connected to the corporate network and the cloud, often running old software that cannot be updated without halting production. Every new connection is one more door.
How ransomware works today
The model has professionalized. In ransomware as a service (RaaS), one group develops the malware and affiliates carry out the intrusion, splitting the ransom. Groups vanish and reappear under new names, but the code and the people remain.
Moreover, double extortion has become the rule: before encrypting, the criminal copies the data and threatens to publish it. In other words, restoring the backup fixes the downtime but not the leak — which, with LGPD (the Brazilian data-protection law) under full enforcement, still triggers mandatory notification and the risk of sanctions. In some cases there is a third layer: direct pressure on the victim’s customers and partners.

The perimeter is gone — identity took over
Hybrid work has become normal in manufacturing too: engineering accesses the SCADA system from home, the integrator connects remotely, maintenance uses tablets on the shop floor. As a result, the traditional perimeter has lost practical meaning. Whoever controls access controls the risk.
In practice, that means conditional access, segmentation between the corporate and industrial networks, and visibility over devices and sessions. Furthermore, vendors and integrators must be in scope — a large share of industrial incidents comes in through the supply chain, not through the front door.
Recommendations against ransomware in manufacturing
- A rehearsed response plan — immediate containment; communication with authorities, the regulator, customers and suppliers. Simulate the scenario before it happens.
- Immutable, isolated and tested backups — a backup that has never been restored is not yet a backup. Include shop-floor systems in the scope.
- IT/OT segmentation — ransomware that comes in through email must not have a free path to the line controller.
- Phishing-resistant MFA — FIDO2 keys or passkeys on all remote access, with frequent revocation of old sessions.
- Behavior-based detection — machine learning models spot deviations in accounts, devices and traffic before encryption begins.
- Prepared people — phishing today arrives with flawless writing and already uses cloned voice and video in approval scams. Train for the current threat, not the one from five years ago.
In short, manufacturing will stay in the crosshairs as long as production downtime means fast payment. The financial sector has already shown the way: consistently high security standards change the criminal’s math — and they go looking for another victim. Our cybersecurity practice builds exactly that barrier, with special attention to the technology for manufacturing environments where IT and OT meet.