Skip to content
-
Promoting African Technology Globally. Subscribe Now!
Techknow Africa (Network) Techknow Africa (Network) Techknow Africa (Network)

Promoting African Tech globally

Techknow Africa (Network) Techknow Africa (Network) Techknow Africa (Network)

Promoting African Tech globally

  • Home
  • About Us
  • Contact
  • Shop
  • Support Us
  • Home
  • About Us
  • Contact
  • Shop
  • Support Us
Close

Search

  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Login
Techknow Africa (Network) Techknow Africa (Network) Techknow Africa (Network)

Promoting African Tech globally

Techknow Africa (Network) Techknow Africa (Network) Techknow Africa (Network)

Promoting African Tech globally

  • Home
  • About Us
  • Contact
  • Shop
  • Support Us
  • Home
  • About Us
  • Contact
  • Shop
  • Support Us
Close

Search

  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Login
Home/Business/Sophos: Manufacturing Blocks More Ransomware as Attackers Pivot to Data Theft
BusinessCyber SecurityInternational

Sophos: Manufacturing Blocks More Ransomware as Attackers Pivot to Data Theft

By Samzillah
January 29, 2026 3 Min Read
0

Sophos, a global leader of innovative security solutions for defeating cyberattacks, today announced new findings from the Sophos State of Ransomware in Manufacturing and Production 2025 report. The study reveals that manufacturers are stopping more ransomware attacks before data can be encrypted; however, adversaries are increasingly stealing data and using extortion-only tactics to maintain pressure. As a result, more than half of manufacturing organizations impacted by encryption paid the ransom despite progress in defensive measures. The report is based on an independent survey of 332 manufacturing organizations that were hit by ransomware in the last year.

The Sophos State of Ransomware in Manufacturing and Production report found:

Encryption rates are falling, but adversaries are shifting tactics: 40% of attacks on manufacturers resulted in data encryption, the lowest level in five years and down from 74% last year. However, extortion only attacks surged to 10% from just 3% in 2024 as attackers increase reliance on data theft for leverage.

 

  • Data theft remains a significant concern: 39% of manufacturers that experienced encryption also had data stolen, one of the highest rates across all surveyed sectors.
  • More organizations are stopping attacks before encryption: 50% of manufacturing organizations stopped the attack before data could be encrypted, more than double last year’s 24%.
  • Expertise shortfalls and inadequate protection fuel attacks: Lack of expertise was cited by 42.5% of organizations. Unknown security gaps were cited by 41.6%, and a lack of protection by 41%. Respondents identified an average of three internal factors that contributed to the attack.
  • More than half of manufacturers with encrypted data paid the ransom: 51% of affected organizations paid the ransom. The median ransom paid was $1 million dollars, compared to a median demand of $1.2 million dollars.
  • Recovery costs and timelines are improving: The average cost to recover from a ransomware attack, excluding ransom payment, declined by 24% to $1.3 million dollars. 58% of manufacturers fully recovered within one week, up from 44% last year.
  • Ransomware incidents affect IT and security teams: 47% of manufacturers reported increased team stress after experiencing data encryption. 44% said pressure from senior leaders increased, and 27% reported leadership change as a result of the attack.

 

“Manufacturing depends on interconnected systems where even brief downtime can stop production and ripple across supply chains,” said Alexandra Rose, Director of Threat Research, Sophos Counter Threat Unit. “Attackers exploit this pressure: despite encryption rates falling to 40%, the median ransom paid still reached $1 million. While half of manufacturers stopped attacks before encryption, recovery costs average $1.3 million and leadership stress remains high. Layered defenses, continuous visibility, and well-rehearsed response plans are essential to reduce both operational impact and financial risk.”

 

What Sophos is Seeing in Manufacturing

Over the past twelve months, Sophos X-Ops has observed ransomware activity across leak sites and found that 99 distinct threat groups targeted manufacturing organizations. The most prominent groups targeting manufacturing organizations based on leak site observations are GOLD SAHARA (Akira), GOLD FEATHER (Qilin) and GOLD ENCORE (PLAY).  Reflecting the trends revealed in the report, in over half of the ransomware incidents that Sophos Emergency Incident Response was brought in to remediate, attackers both stole and encrypted data, highlighting the use of double extortion tactics where data is held for ransom and threatened with release on a leak site.

 

Strengthening Defenses for the Long Term

 

Based on its experience protecting manufacturing organizations worldwide, Sophos recommends the following best practices to help businesses stay ahead of ransomware and other cyberthreats:

 

  • Eliminate Root Causes: Take proactive steps to address common technical and operational weaknesses—such as exploited vulnerabilities—that adversaries frequently target. Solutions like Sophos Managed Risk can help organizations assess their exposure and reduce risk across their environments.
  • Defend Every Endpoint: Ensure all endpoints, including servers, are protected with dedicated anti-ransomware defenses to prevent attacks from gaining a foothold.
  • Plan and Prepare: Establish and routinely test a comprehensive incident response plan. Maintain reliable backups and practice data restoration regularly to minimize downtime in the event of an attack.
  • Monitor Around the Clock: Continuous visibility is essential. Organizations without in-house resources can strengthen their resilience by partnering with a trusted Managed Detection and Response (MDR) provider for 24/7 threat monitoring and expert response.

 

Download the Sophos State of Ransomware in Manufacturing and Production 2025 report to learn more. 

Thanks 

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
Author

Samzillah

An experienced software developer and Pentester .

Follow Me
Other Articles
Previous

Zoho Expands Young Creators Program Across East Africa, Empowering Students with Future-Ready Digital Skills

How to Optimize Images for Your Website
Next

How to Optimize Images for Your Website

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Business
  • Cyber Security
  • Featured
  • International
  • Startups
  • Trending
Hey, I’m Samuel Musila. I build Websites, Mobile Apps, Management Systems and also Graphic Design
  • X
  • Instagram
  • Facebook
  • YouTube
  • WhatsApp
Work Experience

Zillah Technologies LTD

Chief Technology Officer (CTO)

2021-To Date

Intermedia Networks LTD

Software Developer

2016-2021

The Ultimate Leader Schools

ICT Officer

2023- To Date

Available for Hire
Get In Touch

Recent Posts

  • How to Optimize Images for Your Website
    How to Optimize Images for Your Website
    by Andrew Walyaula
    January 29, 2026
  • Safaricom named Kenya’s No. 1 Employer and a Top Employer in Kenya and Africa for 2026
    by Samzillah
    January 27, 2026
  • Safaricom has appointed Sylvia Anampiu as director of fixed business as Kenya’s biggest telco moves closer to rolling out pay-as-you-go fibre broadband for Kenyan homes and offices.
    by Samzillah
    January 27, 2026
  • A Proof that google Voice assistant spies on users as it is taken to court
    by Samzillah
    January 27, 2026

 TechKnow Africa (Network) is an Organization that focuses on Tech by Africa, For Africa.

Our goal is to show the Tech World that AFRICA can and will come to the forefront of the Modern Age.

  • Facebook
  • X
  • Instagram
  • LinkedIn

Latest Posts

  • Zoho Expands Young Creators Program Across East Africa, Empowering Students with Future-Ready Digital Skills
    Zoho, a global technology company, has expanded its Young Creators… Read more: Zoho Expands Young Creators Program Across East Africa, Empowering Students with Future-Ready Digital Skills
  • Spiro Lands Historic $100M Funding, Setting a New Benchmark for Africa’s E-Mobility
    Africa’s electric mobility story has often been one of promise… Read more: Spiro Lands Historic $100M Funding, Setting a New Benchmark for Africa’s E-Mobility
  • Sophos: Manufacturing Blocks More Ransomware as Attackers Pivot to Data Theft
    Sophos, a global leader of innovative security solutions for defeating cyberattacks,… Read more: Sophos: Manufacturing Blocks More Ransomware as Attackers Pivot to Data Theft

Pages

  • Home
  • About Us
  • Contact
  • Shop
  • Cart
  • Checkout
  • My account
  • Donation Confirmation
  • Donation Failed
  • Donor Dashboard
  • Support Us

Contact

Phone

+(254) 740 386 944

+254 753 788691

Email

info@techknow.africa

editor@techknow.africa

Location

Machakos Town - Kenya

Copyright 2026 — Techknow Africa (Network). All rights reserved.