As cybercriminals grow more sophisticated, manufacturers have become prime targets. Modern factories rely on interconnected production equipment, industrial control systems, and enterprise software to keep operations moving. When those systems are compromised, the effects can ripple across an entire organization.
The threat is especially severe for small and midsize manufacturers. While large companies may have the financial resources to withstand an extended shutdown, such a disruption could become an existential threat to smaller operations. A month without production can mean lost customers, broken supplier relationships, cashflow problems and even the end of the business.
Recent attacks illustrate just how disruptive ransomware and cyber-attacks have become.
Jaguar Land Rover: Five-week production shutdown
A cyberattack on Jaguar Land Rover’s information technology systems forced the company to halt production at its major U.K. manufacturing facilities for five weeks in 2025. The disruption affected approximately 5,000 suppliers, logistics providers and other businesses tied to the company’s operations.
Cost: An estimated$2.5 billion — one of the costliest cyber incidents ever to affect a manufacturer. After production resumed, the company worked for months to restore systems and stabilize its supply chain.
Clorox: Months-long manufacturing and distribution disruption
A ransomware attack on Clorox’s information technology systems in August 2023 forced the company to take parts of its network offline, disrupting manufacturing, order processing, and product distribution across North America.
The firm temporarily reverted to manual processes while rebuilding critical systems, resulting in widespread retail shortages of products such as bleach, disinfecting wipes and trash bags.
Cost: Approximately$356 million in reduced sales and $49 million in direct response and recovery costs. The company also incurred expenses during the months-long process of restoring automated systems and rebuilding inventories.
Dole Food: Halted production and shipments
A ransomware attack in February 2023 forced Dole Food Company to temporarily shut down production at several North American facilities and suspend food shipments while working to contain the incident. The attack caused temporary shortages of packaged salads and other produce at grocery stores.
Cost: Approximately$10.5 million in losses incurred during the quarter, including lost revenue, recovery expenses, and losses from operational disruptions.
How it happens
Cybercriminals increasingly spend time inside company networks before launching an attack.
They identify critical systems, steal sensitive information, and learn how an organization operates. Some threat actors even search for cyber insurance policies to understand coverage limits and tailor their ransom demands.
They may also threaten to publish stolen data if a ransom is not paid, creating additional legal, regulatory, and reputational risks.
Artificial intelligence is making matters worse. AI enables criminals to create highly convincing phishing e-mails, automate attacks and identify vulnerabilities much faster than in the past. Small and midsize manufacturers are often targeted because they may have fewer cyber security resources than larger organizations.
Steps manufacturers can take
While no organization can eliminate cyber risk entirely, manufacturers can significantly improve their resilience by taking practical steps:
- Require multifactor authentication for all critical systems.
- Regularly back up production and business data and test restoration procedures.
- Segment manufacturing systems from business networks to limit the spread of an attack.
- Train employees to recognize phishing attempts and other social engineering tactics.
- Promptly install security updates for all software and monitor networks for unusual activity.
- Develop and regularly test incident response and business continuity plans.
Finally, manufacturers should review their cyber insurance coverage. This may help cover losses and expenses related to forensic investigations, business interruption, system restoration, legal services, notifications, and other recovery costs.
