Smart technology increases cybersecurity risks for manufacturers
Key Highlights
- Ransomware attacks increasingly target manufacturers as connected smart factory technologies expand potential entry points across IT and operational technology networks.
- AI is helping ransomware groups accelerate phishing, reconnaissance and social engineering, while lowering barriers for less-skilled cybercriminals.
- Manufacturing cybersecurity requires controlled, monitored and continuously updated remote access, with rapid patching critical for defending against zero-day vulnerabilities.
- Network modernization and cybersecurity must support growing AI workloads as plastics processors connect more equipment, endpoints and data flows.
Cybersecurity and looking for a new job have some similarities.
Job applicants are using artificial intelligence (AI) to write resumes, which are sent to human resource departments using AI to screen and evaluate candidates.
Hackers are using AI to break into manufacturing systems, where security experts are increasingly using AI to try to keep them out.
We may be at the beginning of a cybersecurity AI race and you can bet that the hackers will likely stay a step ahead.
Manufacturers are adopting smart factory technology to make up for a shortage of skilled labor as well as to improve overall plant operations and quality. Smart technology requires external as well as internal connectivity, which means more potential entry points for hackers.
Most other industries deal with cloud-based generative AI, but manufacturers must grapple with physical AI — the integration of robots, autonomous systems and connected machinery.
Manufacturers are most attacked sector
The annual survey by cyber risk management firm Black Kite found that publicly known ransomware victims increased by 24.9 percent in the 12 months between April 2025 and March 2026. But even more startling — the increase accelerated to 60 percent during the second six months of the period.
Released in July, Black Kite’s “2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record” identified 7,551 ransomware victims. More than 49 percent of attacks targeted U.S. businesses.
Some 22 percent of the attacks were against manufacturing businesses, the most attacked sector for the fourth consecutive year, with a 58 percent year-over-year increase.
A ransomware attack occurs when malicious software is used to lock or encrypt a victim's files, systems or devices. The attacker then demands payment — usually in cryptocurrency — in exchange for the decryption key or release of the data.
Hackers have learned that stopping production is far more profitable than stealing email.
The Black Kite report did not attribute the increase in ransomware attacks specifically to artificial intelligence, but it sounded an alarm that some hackers are starting to use it.
“AI gives more actors access to work that once required time, language skill, technical discipline or a larger team,” the report said. “AI is a force multiplier for ransomware operators, not a substitute for them.”
Black Kite said ransomware groups are using AI to speed up reconnaissance, make phishing and vishing (voice phishing) more convincing, provide faster translations and craft better extortion messages. It said that “actors with limited skill can use AI to close some of the gap between ambition and execution.”
The report found a change in the target of ransomware attacks that can be attributed largely to AI: “Vishing, multilingual lures, voice cloning and deepfake audio all became easier to produce or scale. Help desk manipulation, employee impersonation and social engineering scripts became cheaper to prepare and easier to adapt in real time. This is especially important because some of the year's most disruptive intrusions were not defined by malware sophistication alone. They were defined by attackers understanding how people, vendors, support desks and identity workflows actually operate.”
The 2026 Black Kite report also identified 61 new ransomware hacker groups out of a total of 146 current, active groups.
Staying ahead of the hackers
Cisco Systems Inc., which describes itself as developing market-defining technologies driving the future of AI, in June published a white paper titled “Manufacturing in the age of AI: The network driving the factory floor and beyond,” that said 72 percent of manufacturers believe AI-related security threats are evolving faster than their organization’s ability to adopt security controls.
“The result is a major blind spot that can jeopardize security posture,” the report said. “As AI workloads expand the number of endpoints and data flows, security teams are struggling to maintain coherent, enforceable policies.”
Convergence of information technology (IT) and operational technology (OT) makes manufacturing networks uniquely complex. Cisco said this creates a sprawling attack surface to which AI is not just adding new traffic; it is fundamentally complicating the policies, monitoring and controls that security teams rely on.
How can a plastics processor protect the plant floor?
Recognize that industrial environments are not office environments, according to Spencer Cramer, CEO of ei3 Corp., a developer of IIoT solutions for manufacturers and machinery builders.
Remote access to industrial machines has created significant value for manufacturers and machine builders, Cramer said in a blog post.
“One of the most important steps manufacturers and machine builders can take is to standardize how machines connect,” Cramer said. “It is no longer enough to ask whether a technician can reach a machine remotely. The better question is whether the access can be controlled, limited, logged, updated and defended across the full life of the asset.”
Cramer said cybersecurity defense is not an install-and-forget-it proposition. An example is the zero-day attack — hackers find a software vulnerability and attack many companies before a patch can be implemented. The timeframe can be as little as a few hours, so patching vulnerabilities quickly is critical.
Black Kite agreed that paying attention to critical software patches and other items in the Known Exploited Vulnerabilities catalog, an authoritative list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) tracking software flaws actively targeted by attackers, is important.
Paying attention to vendors’ access, continued security training of company staff and preparing for AI-augmented threats were also recommendations from Black Hat.
Cisco recommends viewing network modernization as the critical backbone of all other AI investments. “Strategic modernization is essential to ensure the network scales with the pace of AI, drives performance that bests the competition, and upholds the heightened security demands of the AI era.”
About the Author
Ron Shinn
Editor
Editor Ron Shinn is a co-founder of Plastics Machinery & Manufacturing and has been covering the plastics industry for more than 35 years. He leads the editorial team, directs coverage and sets the editorial calendar. He also writes features, including the Talking Points column and On the Factory Floor, and covers recycling and sustainability for PMM and Plastics Recycling.
