I Need IT Support Now
Futuristic cityscape with glowing blue buildings, digital clouds streaming data lines, and power transmission towers.
Shane

Industrial Ransomware Attacks Surge in Q3 2025: Manufacturing Sector Bears the Brunt

Manufacturing Accounts For 72% Of Industrial Ransomware Targets This Quarter – Construction, Equipment, And Food Production Lead Targeted Manufacturing Subsectors

Threat Alert
Industrial Ransomware Just Hit 742 Attacks in One Quarter.

Dragos logged a sharp Q3 2025 jump, and manufacturing took 72% of it. For Houston-area makers, oil and gas, and logistics operators, the pressure to keep production running is exactly what attackers exploit.

TL;DR
Industrial cybersecurity firm Dragos recorded 742 ransomware incidents against industrial organizations in Q3 2025 (July-September), up about 13% from 657 in Q2. Manufacturing absorbed 72% of attacks (532 incidents), with construction the hardest-hit subsector. Qilin led all groups with 138 incidents; together with Akira, Play, and INC Ransom it accounted for nearly 40% of activity. The United States was the top target at 392 incidents. Attackers get in mainly through unpatched VPN and firewall appliances (SonicWall and Fortinet), stolen credentials, and social engineering - then delete backups and encrypt. Houston and Katy businesses with manufacturing, oil and gas, or logistics operations face elevated risk, and the defenses are known: patch remote access, enforce phishing-resistant MFA, isolate backups, and segment IT from OT.

Attackers know a manufacturing plant cannot afford downtime - so they target the IT systems that keep production running and squeeze on the pressure.

Dragos, a leading industrial cybersecurity firm, just published its Q3 2025 Industrial Ransomware Analysis, and the trend is sharply up. This is not only a big-factory problem: mid-market manufacturers, oil and gas operators, and logistics firms across the Houston area sit squarely in the target profile. Here is what the data shows, how these attacks actually start, and the defenses that stop them.

Why it matters here: Texas concentrates manufacturing, oil and gas, and logistics - exactly the sectors and systems this wave is hitting hardest.

The Q3 2025 Surge

A sharp quarter-over-quarter jump, concentrated in manufacturing.

Incidents rose about 13% in a single quarter, manufacturing took nearly three-quarters of them, and one group - Qilin - led the pack.

DRAGOS Q3 2025 INDUSTRIAL RANSOMWARE 742 Q3 incidents up ~13% 72% hit manufacturing 532 incidents 138 Qilin incidents top group 392 US incidents top country
Headline figures from the Dragos Q3 2025 Industrial Ransomware Analysis.

Construction was the hardest-hit manufacturing subsector (142 of the 532 manufacturing incidents). Beyond the top groups, the quarter saw a wave of new operations - Sinobi, Gentlemen, Beast, and nearly two dozen more - as leaked ransomware builders and affiliate programs keep dropping the barrier to entry. Even attacks that never touch industrial controls can halt production: Scattered Spider's intrusion at Jaguar Land Rover reportedly forced multi-week shutdowns just by disrupting ERP and logistics systems.

How These Attacks Get In

The playbook is predictable - which is exactly why it is defensible.

Most industrial ransomware starts at an exposed remote-access appliance or a stolen login, then moves to kill backups before encrypting.

  • Unpatched VPNs and firewalls. SonicWall SSL VPN (CVE-2024-40766) and Fortinet flaws (CVE-2024-55591, CVE-2024-21762) were actively exploited entry points.
  • Bought credentials. Initial Access Brokers sell working logins, so attackers skip the break-in entirely.
  • Social engineering. Help-desk impersonation and fake password-reset requests trick staff into handing over access.
  • Meeting-invite phishing. Lures disguised as Zoom and Microsoft Teams invitations deliver the first foothold.
  • Then the endgame. Escalate privileges, exfiltrate files, disable or delete backups, and encrypt - often targeting hypervisors for maximum impact.

Essential Defenses

The controls that break this chain are known and affordable.

You do not need OT-specific tooling to cut most of this risk - you need patched remote access, strong identity, protected backups, and segmentation.

  • Patch remote access now. Update SonicWall and Fortinet appliances with known vulnerabilities before attackers scan you.
  • Enforce phishing-resistant MFA. On every remote-access point, and add strict verification for help-desk password resets.
  • Protect your backups. Isolate backup infrastructure, keep offline copies attackers cannot reach, and test restores regularly.
  • Watch for RMM abuse. Inventory authorized remote-management tools and alert on any new or unauthorized installs.
  • Segment IT from OT. Put strong boundaries between business systems and production technology, and monitor traffic that crosses them.

Is Your Plant One Unpatched VPN Away From a Shutdown?

CinchOps hardens remote access, MFA, and backups - and segments IT from OT - so a single stolen login does not stop your production line.

Talk to CinchOps
100% Free

Free Cybersecurity Assessment

Would ransomware get into your operation through an exposed VPN? Get a FREE review of your remote access, MFA, and backups.

Get Your Free Assessment

You do not need someone to reach your machines to shut you down - taking out the ERP and logistics systems is enough. That is why industrial ransomware defense starts with your ordinary IT, not just the plant floor.
Shane Stevens, CEO, CinchOps - LinkedIn

Ransomware Defense for Industrial Operations

CinchOps gives Houston-area manufacturers, oil and gas, and logistics firms patch management, phishing-resistant MFA, protected backups, and IT/OT segmentation - through our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, defending the systems industrial ransomware targets.

  • 24/7 network monitoring. Detect suspicious activity before ransomware deploys.
  • Vulnerability and patch management. Find and fix critical weaknesses in VPNs, firewalls, and remote access.
  • Email security and awareness training. Block phishing and teach staff to spot social engineering.
  • Backup and disaster recovery. Protected, tested backups so you can recover without paying.
  • Incident response planning. A plan ready before the worst happens, plus network security assessments to find gaps first.

Do not wait for an attack to expose your gaps. Contact CinchOps to defend your operation from the ransomware surge.

Frequently Asked Questions

How many industrial ransomware attacks happened in Q3 2025?

Dragos recorded 742 ransomware incidents against industrial organizations in Q3 2025 (July-September), up about 13% from 657 in Q2. Manufacturing absorbed 72% of them.

Which ransomware groups were most active?

Qilin led with 138 incidents. Together with Akira (94), Play (64), and INC Ransom (51), the top four groups accounted for nearly 40% of all industrial ransomware activity in the quarter.

How do these attacks typically start?

Most begin with unpatched VPN and firewall appliances (SonicWall and Fortinet), stolen credentials bought from access brokers, or social engineering such as help-desk impersonation and fake meeting invites. Attackers then delete backups and encrypt.

Why is manufacturing hit so hard?

Because manufacturers cannot afford downtime, and a stopped line ripples through supply chains. Attackers use that pressure to push for fast ransom payments - and often only need to disrupt ordinary IT systems to halt production.

What should a Houston-area business do first?

Patch your VPN and firewall appliances, turn on phishing-resistant MFA for remote access, isolate and test your backups, and segment IT from OT networks. A managed IT provider can implement and monitor all of it.

Discover More

Sources

Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506