Sophos, a global leader of innovative security solutions for defeating cyberattacks, today announced new findings from the Sophos State…Sophos, a global leader of innovative security solutions for defeating cyberattacks, today announced new findings from the Sophos State…

Manufacturing industry shows stronger early detection of ransomware, blocks more attempts- Sophos report

2025/12/06 14:30

Sophos, a global leader of innovative security solutions for defeating cyberattacks, today announced new findings from the Sophos State of Ransomware in Manufacturing and Production 2025 report. 

The study reveals that manufacturers are stopping more ransomware attacks before data can be encrypted; however, adversaries are increasingly stealing data and using extortion-only tactics to maintain pressure. 

As a result, more than half of manufacturing organizations impacted by encryption paid the ransom despite progress in defensive measures. The report is based on an independent survey of 332 manufacturing organizations that were hit by ransomware in the last year. 

Sophos Report finds education sector strengthening against ransomware, but IT teams pay personal priceSophos logo

The Sophos State of Ransomware in Manufacturing and Production report found: 

●      Encryption rates are falling, but adversaries are shifting tactics: 40% of attacks on manufacturers resulted in data encryption, the lowest level in five years and down from 74% last year. However, extortion only attacks surged to 10% from just 3% in 2024 as attackers increase reliance on data theft for leverage.

●      Data theft remains a significant concern: 39% of manufacturers that experienced encryption also had data stolen, one of the highest rates across all surveyed sectors.

●      More organizations are stopping attacks before encryption: 50% of manufacturing organizations stopped the attack before data could be encrypted, more than double last year’s 24%.

●      Expertise shortfalls and inadequate protection fuel attacks: Lack of expertise was cited by 42.5% of organizations. Unknown security gaps were cited by 41.6%, and a lack of protection by 41%. Respondents identified an average of three internal factors that contributed to the attack.

●      More than half of manufacturers with encrypted data paid the ransom: 51% of affected organizations paid the ransom. The median ransom paid was $1 million dollars, compared to a median demand of $1.2 million dollars.

●      Recovery costs and timelines are improving: The average cost to recover from a ransomware attack, excluding ransom payment, declined by 24% to $1.3 million dollars. 58% of manufacturers fully recovered within one week, up from 44% last year.

●      Ransomware incidents affect IT and security teams: 47% of manufacturers reported increased team stress after experiencing data encryption. 44% said pressure from senior leaders increased, and 27% reported leadership change as a result of the attack.

“Manufacturing depends on interconnected systems where even brief downtime can stop production and ripple across supply chains,” said Alexandra Rose, Director of Threat Research, Sophos Counter Threat Unit. “Attackers exploit this pressure: despite encryption rates falling to 40%, the median ransom paid still reached $1 million. While half of manufacturers stopped attacks before encryption, recovery costs average $1.3 million and leadership stress remains high. Layered defenses, continuous visibility, and well-rehearsed response plans are essential to reduce both operational impact and financial risk.”

What Sophos is Seeing in Manufacturing

Over the past twelve months, Sophos X-Ops has observed ransomware activity across leak sites and found that 99 distinct threat groups targeted manufacturing organizations. 

The most prominent groups targeting manufacturing organizations based on leak site observations are GOLD SAHARA (Akira), GOLD FEATHER (Qilin) and GOLD ENCORE (PLAY).  Reflecting the trends revealed in the report, in over half of the ransomware incidents that 

Sophos Emergency Incident Response was brought in to remediate, attackers both stole and encrypted data, highlighting the use of double extortion tactics where data is held for ransom and threatened with release on a leak site. 

Strengthening Defences for the Long Term

Based on its experience protecting manufacturing organizations worldwide, Sophos recommends the following best practices to help businesses stay ahead of ransomware and other cyberthreats:

●      Eliminate Root Causes: Take proactive steps to address common technical and operational weaknesses—such as exploited vulnerabilities—that adversaries frequently target. Solutions like Sophos Managed Risk can help organizations assess their exposure and reduce risk across their environments.

●      Defend Every Endpoint: Ensure all endpoints, including servers, are protected with dedicated anti-ransomware defenses to prevent attacks from gaining a foothold.

●      Plan and Prepare: Establish and routinely test a comprehensive incident response plan. Maintain reliable backups and practice data restoration regularly to minimize downtime in the event of an attack.

●      Monitor Around the Clock: Continuous visibility is essential. Organizations without in-house resources can strengthen their resilience by partnering with a trusted Managed Detection and Response (MDR) provider for 24/7 threat monitoring and expert response.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors

Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors

The post Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors appeared on BitcoinEthereumNews.com. The Pi Network team has announced the implementation of upgrades to simplify verification and increase the pace of its Mainnet migration. This comes before the token unlock happening this December. Pi Network Integrates AI Tools to Boost KYC Process In a recent blog post, the Pi team said it has improved its KYC process with the same AI technology as Fast Track KYC. This will cut the number of applications waiting for human review by 50%. As a result, more Pioneers will be able to reach Mainnet eligibility sooner. Fast Track KYC was first introduced in September to help new and non-users set up a Mainnet wallet. This was in an effort to reduce the long wait times caused by the previous rule. The old rule required completing 30 mining sessions before qualifying for verification. Fast Track cannot enable migration on its own. However, it is now fully part of the Standard KYC process which allows access to Mainnet. This comes at a time when the network is set for another unlock in December. About 190 million tokens will unlock worth approximately $43 million at current estimates.  These updates will help more Pioneers finish their migration faster especially when there are fewer validators available. This integration allows Pi’s validation resources to serve as a platform utility. In the future, applications that need identity verification or human-verified participation can use this system. Team Releases Validator Rewards Update The Pi Network team provided an update about validator rewards. They expect to distribute the first rewards by the end of Q1 2026. This delay happened because they needed to analyze a large amount of data collected since 2021. Currently, 17.5 million users have completed the KYC process, and 15.7 million users have moved to the Mainnet. However, there are around 3 million users…
Share
BitcoinEthereumNews2025/12/06 16:08
Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential

Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential

The post Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential appeared on BitcoinEthereumNews.com. Solana ($SOL) is approaching a critical support level at $124, where buyers must defend to prevent further declines amid cautious market conditions. A successful hold could initiate recovery toward $138 or higher, while failure might lead to deeper corrections. Solana’s price risks dropping to $124 if current support zones weaken under selling pressure. Reclaiming key resistance around $138 may drive $SOL toward $172–$180 targets. Recent data shows liquidity resets often precede multi-week uptrends, with historical patterns suggesting potential recovery by early 2026. Solana ($SOL) support at $124 tested amid market caution: Will buyers defend or trigger deeper drops? Explore analysis, liquidity signals, and recovery paths for informed trading decisions. What Is the Current Support Level for Solana ($SOL)? Solana ($SOL) is currently testing a vital support level at $124, following a decline from the $144–$146 resistance zone. Analysts from TradingView indicate that after failing to maintain momentum above $138, the token dipped toward $131 and mid-range support near $134. This positioning underscores the importance of buyer intervention to stabilize the price and prevent further erosion. Solana ($SOL) is in a crucial stage right now, with possible price drops toward important support zones. Recent price activity signals increased downside risks, analysts caution. TradingView contributor Ali notes that Solana may find quick support at $124 after falling from the $144–$146 resistance range. The token eventually tested $131 after failing to hold over $138 and plummeting toward mid-range support near $134. Source: Ali Market indicators reveal downward momentum, with potential short-term volatility around $130–$132 before possibly easing to $126–$127. Should this threshold break, $SOL could slide to the firmer support at $124–$125, according to observations from established charting platforms. Overall sentiment remains guarded, as highlighted by experts monitoring on-chain data. Ali warns that without robust buying interest, additional selling could intensify. TradingView analyst…
Share
BitcoinEthereumNews2025/12/06 16:33