Cybersecurity
Ransomware landscape, summer 2025: manufacturing in the crosshairs
In spring and summer 2025 ransomware mostly hit manufacturing. Data, active groups and what it means for industrial OT environments.
Sector telemetry collected between March and August 2025 tells the story of an intense season for ransomware operators. The figure that stands out is not the absolute number of attacks but their concentration: the manufacturing sector absorbed almost all of the detected alerts. For anyone running industrial plants and OT infrastructure, this is a signal that deserves operational attention, not just a statistic for a report.
The numbers of the season
The distribution of alerts by sector is stark:
| Sector | Share of alerts |
|---|---|
| Manufacturing | 83.82% |
| Transport | 13.87% |
| Consumer services | 1.16% |
Geographically, the United States remains the epicenter with 56.42% of incidents, followed by the United Kingdom (14.53%) and Japan (6.7%). The picture is clear: manufacturing is the priority target, and not by chance. Halting a production line generates immediate pressure and direct costs, a lever that ransom operators know well.
Who was active
Three families dominated the period, each with a different story:
- BlackSuit: a direct evolution of Royal and a descendant of the Conti galaxy, leader in alerts in May. Its combined operations exceeded 370 million dollars in ransoms, before a decline in August following a takedown operation by US authorities in July.
- Cl0p (TA505): specialized in exploiting zero-day vulnerabilities in file transfer solutions (MOVEit, GoAnywhere, Accellion). Still very much present two years after its first campaigns, confirming how persistent a working compromise chain can be.
- Black Basta: more than 500 organizations hit through mid-2024. Despite the internal leak of its operations in February 2025, modules already deployed continue to be detected.
On the front of emerging techniques, a prototype of AI-assisted ransomware (PromptLock) also appeared, still in an early stage but indicative of the direction the phenomenon could take.
Why OT is exposed differently
One detail of the detection deserves reflection: part of the alerts came from endpoint sensors installed on HMI machines, not only from network traffic monitoring. This is proof that the threat does not stop at corporate IT, but reaches the systems that directly govern the production process.
This is the substantial difference compared with a purely IT environment. In a plant you cannot simply isolate and reinstall: a poorly calibrated containment action can halt production just as much as the attack itself. For this reason, defense in the industrial domain requires an approach that holds security and operational continuity together.
The MON5 angle
Field experience confirms the priorities indicated by the research, but with a specific slant for the OT world:
- Visibility first. You cannot protect what you cannot see. Mapping plant assets completely, including HMIs and edge devices often off the IT radar, is the precondition for any defense strategy.
- Vulnerabilities in their real context. A CVE that is critical on paper may be irrelevant if the device is segmented and not exposed, or urgent if it governs a safety function. Correlating vulnerabilities with the plant context avoids wasting resources on the wrong priorities.
- Anomalies without stopping the line. Passive monitoring of traffic and behavior makes it possible to catch the early signals of a compromise, from lateral movement to communications with known indicators, without interrupting the production process.
The message of the 2025 season is simple to state and demanding to put into practice: manufacturing is today the hot front of ransomware, and defending OT environments cannot be a copy-paste of IT practices. It takes continuous visibility, contextualization of risk and the ability to react without shutting down the plant.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Cybersecurity
AI in offensive cybersecurity: from payloads to APT operations
Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

Cybersecurity
Anomaly detection in OT: building the baseline and managing false positives
OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.
Cybersecurity
Covert networks and hidden C2 channels in OT environments: how APTs operate
APT actors targeting industrial environments do not break in and act immediately: they settle quietly, build hidden command channels, and wait. How they work and how to detect them.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2