Cyber-criminals are ramping up their attacks on the manufacturing sector, exploiting outdated operational technology (OT) systems and interconnected supply chains with devastating effects.
A new analysis of the cyber threat landscape in the manufacturing industry by IDS-INDATA reveals a staggering 50% increase in supply hain attacks, making them the fastest-growing cyber threat to the industry.
The analysis also highlights alarming rises in ransomware (23.5%), malware (11.1%) and social engineering (8.6%) attacks, underscoring the vulnerabilities in ageing OT-IT networks.
As manufacturers increasingly rely on OT systems integrated with IT networks, unmanaged or legacy systems serve as weak links, creating entry points fro sophisticated, AI-driven cyber-attacks. Hackers are exploiting these gaps in security with alarming speed, leveraging AI to automate and adapt their tactics.
This surge in AI-enhanced malware, deepfake social engineering, and ransomware underscores the urgency of modernising these vulnerable systems.
Supply Chain Attacks
The significant increase in attacks of this type highlights the trend of targeting third-party vendors and suppliers to infiltrate manufacturing systems. In 2023, these threats affected 20% of manufacturing businesses, rising to 30% this year.
The interconnected nature of supply chains creates cascading vulnerabilities, making manufacturers susceptible to devastating disruptions. AI-driven tools are now enabling cyber-criminals to automate the identification of weak points, accelerating the scale of these attacks.
Ransomware
Ransomware attacks, which saw a 23.5% year-on-year increase, are becoming more sophisticated. Cyber-criminals are utilising AI to create malware that can adapt in real time to avoid detection.
According to the analysis by IDS-INDATA, ransomware threats impacted 34% of businesses in 2023, which rose to 42% this year.
Older OT systems, often running on outdated software, are prime targets for these attacks. As a result, manufacturers face increased downtime, financial losses, and the risk of permanent damage to critical infrastructure.
Malware
AI-powered malware is more sophisticated than ever, as proven by its impact on half of manufacturing businesses this year. These attacks can learn from network environments and adapt to exploit vulnerabilities within OT-IT networks, stealing sensitive data, disrupting productivity, and compromising system integrity.
Recommended reading
- Manufacturing Slows GenAI Adoption Due to Accuracy Concerns
- 95% of UK Businesses Hit by Supply Chain Cyber-breaches
- 97% of UK FTSE 100 Exposed to Supply Chain Breaches in Last Year
Social Engineering
Social engineering tactics, including phishing and impersonation, affected over a third of businesses in 2024 (38%). Due to AI-driven deepfakes and automated scams, these tactics have become increasingly influential.
Cyber-criminals can create highly personalised attacks that exploit human error, one of the weakest links in manufacturing cybersecurity. This highlights the importance of ongoing training and awareness for manufacturers.
Spear Phishing
AI has enhances spear-phishing campaigns, enabling cyber-criminals to customise emails from individuals using personal information obtained from public sources.
The 4.8% increase in targeted phishing incidents highlights the ongoing prevalence of these campaigns against the manufacturing sector. Spear phishing remains the primary threat affecting 88% of businesses.
This trend likely stems from manufacturers reliance on email communication for operational logistics and coordination.
“The findings show an opportunity for manufacturers,” said Ryan Cooke, chief information security officer at IDS-INDATA. “Older systems that run on outdated software are increasingly vulnerable to attacks, whilst the lack of proper network segmentation dramatically increases the impact of malware and lateral movement.
“Addressing these risks can help the industry overcome today’s sophisticated, AI-enhanced cyber threats, which is especially critical given the interconnected nature of supply chains.
“We advocate for regular system checks to stay ahead of evolving threats,” Cooke continued. “IDS-INDATA’s testing and risk management services are designed to assess vulnerabilities in OT-IT networks and fortify defences against the growing tide of cyber threats, from ransomware to AI-powered malware.”
Building Resilience
Manufacturers must also focus on resilience planning to ensure long-term cybersecurity IDS-INDATA excels at developing short-term and long-term strategies, which include secure configurates, timely patching, and adherence to best practices in cybersecurity.
These strategies ensure that manufacturers are prepared to recover from current threats and ready for future challenges.
“Effective resilience planning is essential in today’s cybersecurity landscape,” says Cooke. “By ensuring that OT-IT systems are securely designed, regularly patched, and aligned with best practices, manufacturers can create a strong defence against even the most sophisticated threats.”





