Why are manufacturers still discovering ransomware attacks after attackers have already stolen their data?
By Heath Mullins, Chief Evangelist at ExtraHop
The manufacturing industry stands to be hit harder with ransomware than most other businesses. The threat of operational downtime and significant downstream costs has many manufacturing leaders investing more carefully in security and AI tools, but not all defense strategies are equal.
As a whole, the industry faces structural visibility gaps that make them more susceptible to ransomware attacks than ever, and they’re paying out ransoms that can be prevented with the right context.

ExtraHop’s 2026 Global Threat Landscape Report found that 19% of manufacturing organizations did not recognize they were under ransomware attack until their data was already being exfiltrated. Exfiltration is the end stage of a ransomware attack – and most of the damage takes place long before then.
The ransomware playbook of today demonstrates a much broader extortion model than the encryption of year’s past, where attackers are gaining access, moving through environments and stealing valuable data before demanding payment. In fact, attackers maintained access to internal systems for an average of 2.5 weeks before detection, in which time they’re able to steal data, build backdoors and generally establish control.
Why is this such an issue in manufacturing, specifically? They’re operating in increasingly connected environments – IT, OT, production networks, suppliers, cloud infrastructure and more. This sprawling surface makes it incredibly difficult to establish visibility and ultimately identify malicious activity hidden among legitimate operations.
“When you look at the big picture of modern cyber risk, the thread connecting every major challenge, from missed detections and prolonged dwell times to AI false positives, is a fundamental lack of situational awareness, or ground truth.” – Raja Mukerji, Co-Founder and Chief Scientist, ExtraHop
AI is increasingly part of this visibility issue. Manufacturers are embracing AI-driven operations, connected systems and automation, from predictive maintenance and robots to supply chain optimization and decision-making. These technologies create new dependencies across applications, APIs and third party systems that require additional security considerations.
The issue isn’t the adoption itself, but the rapid implementation cycle exposes a growing gap between how quickly organizations deploy AI capabilities and how quickly they can establish security controls and visibility. Research suggests that organizations are increasingly aware that their AI implementations are a new entry point for adversaries: 55% identified AI agents, agentic infrastructure, and GenAI applications as their biggest cybersecurity attack surface risk.
Even worse, 85% already reported security incidents, data exposure or near misses where AI was the root cause. This isn’t from the expanding attack surface alone. Attackers are also using AI to increase the speed and scale of their operations, with AI-enhanced external attacks as the leading response for top AI-related risks – and suggesting that defenders must improve their own security automation and context to meet machine speed threats.
Cyberattackers understand that operational disruption is a major concern for the manufacturing industry, and that’s what makes them such a good target. The downstream consequences of a cyberattack – as seen just this year with Stryker and West Pharmaceutical Services – can delay production and shipping and significantly threaten customer trust and revenue.
This pressure for uptime can influence the way organizations in the manufacturing industry respond during ransomware negotiations. When downtime per ransomware incident averages nearly 30 hours, many leaders may choose to pay the ransom, rather than deal with the operational impact.
This becomes easier when attackers are demanding lower payments, and new research reflects that: the average ransomware payments decreased from $3.6 million to $2.8 million, but 83% of victims are paying the ransom – an 18% increase from last year. With attackers prioritizing more frequent, lower-value ransom payments, manufacturers become ideal targets because they’re often incentivized to pay quickly.
Attackers are moving faster with AI, taking advantage of complex manufacturing operating environments, and security teams are facing down significant blind spots. In response, many defenders have turned to AI-powered security tools. But the reality is, these tools are only effective when they have access to accurate, real time information on what’s happening within their environments.
“As threat actors leverage AI to scale their operations, defenders are countering with automated operations that don’t have the context required to make definitive decisions. The network bridges this critical gap, revealing exactly how threats are moving and communicating so security teams have the full picture.”
—Raja Mukerji, Co-Founder and Chief Scientist, ExtraHop
Without the right context, these tools create a slog for security teams, where they must spend significant time investigating alerts, gathering data manually, and validating suspicious activity. Nearly 30% said AI-generated alerts created false positives that negatively impacted investigation timelines.
The network is the highest fidelity data source for threat detection and investigation. It can’t be compromised or disabled, and every user and device has to communicate over the network. Organizations must also map out the dependencies of their existing OT environments and combine that insight with a layer of real-time network context for full clarity into their attack surface. By arming AI-security tools with this layer, security teams are much better able to see all the traffic, parse out unusual behavior from legitimate activity and detect attacks as they unfold.
In short, network intelligence gives AI the context it needs to distinguish identify attacks before they escalate.
Manufacturing offers valuable intellectual property, complex operational environments, and high costs associated with downtime, making it an attractive target for attackers.
AI is expanding the number of systems organizations must secure while helping attackers increase the speed and scale of their operations.
Attackers are increasingly using techniques that blend into normal activity, including encrypted communications, valid credentials, and trusted workflows.
Organizations should focus on improving visibility and situational awareness across their environments to identify threats before data theft or operational disruption occurs.
Manufacturers are facing a new ransomware threat landscape where attackers are faster and stealthier than ever before. The challenge ahead is not in making an impenetrable operating environment, it’s catching attacks before they escalate by closing the visibility gaps attackers exploit.
AI plays a critical role in that defense strategy, but only if it’s rooted in complete, high-fidelity context. Organizations that invest in providing comprehensive network context to their AI tools will be best positioned to detect threats earlier, contain attacks faster, and ultimately minimize the operational disruption that today’s ransomware campaigns are designed to inflict.

About the Author:
Heath Mullins is Chief Evangelist at ExtraHop, where he leads thought leadership and advocacy around advanced cybersecurity solutions. Before joining ExtraHop, he served as a Senior Analyst at Forrester, advising Global 100 enterprises, U.S. federal agencies, the Department of Defense, and allied governments on cybersecurity strategy. A recognized voice in the industry, Heath is known for his expertise in Zero Trust, cyber resilience, and threat detection for highly regulated organizations.
As manufacturers offer more customization than ever before, managing product complexity has become a critical challenge. Tune in with Dan Joe Barry, Vice President of Product Marketing at Configit, who explores how companies are tackling the growing number of product configurations across engineering, sales, manufacturing, and service. He explains how Configuration Lifecycle Management (CLM) helps organizations maintain a single source of truth for configuration data. The result: fewer errors, faster quoting, and the ability to deliver customized products at scale.