, ,

Ransomware Attacks on Distributors Rise as Midmarket Companies Bear the Brunt

Why This Matters to Distributors: Ransomware attacks against transportation, freight and warehousing companies continue to increase after adjusting for an unusually large 2025 attack campaign. Black Kite also found that 42% of the 2,289 distribution companies it monitors are above its critical threshold for ransomware susceptibility.

Ransomware attacks against companies that move and store goods are continuing to rise, with midsized transportation, freight and warehousing companies accounting for much of the risk, according to new research from cybersecurity risk intelligence company Black Kite.

Black Kite identified 457 publicly disclosed ransomware victims across trucking, freight arrangement, and warehousing from January 2023 through July 2026. The total included 63 incidents in 2023, 103 in 2024, 196 in 2025 and 95 during the first seven months of 2026.

The lower 2026 total does not mean attacks are declining.

A single campaign by the Clop ransomware group generated 52 distribution victims during an eight-week period in January and February 2025, accounting for 26.5% of the year’s total. Excluding that campaign, Black Kite found that incidents increased 26.7% from the comparable 2025 period, rising from 75 to 95.

“Distribution risk did not recede after 2025,” Black Kite said in the report. “The campaign wave receded, and the underlying growth continued underneath it.”

The findings are part of Black Kite’s 2026 Manufacturing & Distribution Ransomware Report, released Sept. 17. Black Kite said its research covers confirmed, publicly disclosed ransomware and data-extortion incidents from Jan. 1, 2023, through July 29, 2026. The broader study identified 5,237 victims across manufacturing and distribution. Black Kite’s release confirms the report’s scope and methodology.

J. Michael Skiba, a fraud specialist known professionally as “Dr. Fraud,” said the structure of distribution and the supply chain can create opportunities for criminals.

“The criminals are moving from the known areas where there are strong countermeasures, such as straight retail, finance  and moving towards vulnerable systems and channels, exactly like distribution,” Skiba said in comments provided to Distribution Strategy Group.

“They understand that anything related to supply chain has a lot of moving parts, which leads to gaps that they can manipulate,” he said.

Freight trucking accounts for 46% of victims

General freight trucking accounted for the largest share of distribution ransomware victims in Black Kite’s study.

The company identified 210 general freight trucking victims from January 2023 through July 2026, representing 46% of the 457 distribution incidents.

Freight transportation arrangement accounted for 127 victims, or 27.8%; warehousing and storage accounted for 80, or 17.5%; and specialized freight trucking accounted for 40, or 8.8%.

Black Kite said the position those companies occupy in the supply chain can amplify the effect of an attack. Warehouses, freight companies, and trucking operations often manage goods belonging to multiple companies, meaning a disruption can spread beyond the organization whose systems were initially compromised.

Black Kite chief research and intelligence officer Ferhat Dikbiyik made a similar point in announcing the report.

“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” Dikbiyik said.

Midmarket companies account for most victims

Black Kite’s data shows that ransomware attacks in distribution are concentrated among companies well below the industry’s largest enterprises.

The median distribution victim for which revenue data was available generated $28.7 million annually. Black Kite found that 68.6% of those victims had annual revenue between $10 million and $100 million.

That makes cybersecurity preparation particularly important for midsized distributors, according to Tim Bertschmann, founder and president of technology consultancy Bertschmann Group. His role and experience advising organizations on information technology infrastructure, telecommunications and cybersecurity are independently documented.

“A reminder to all companies out there: Education, education, education,” Bertschmann said in comments provided to DSG. “Your employees are human beings and this can and does happen. Regular, consistent, thoughtful educational programs for your employees is crucial.”

Bertschmann said companies also need to prepare for the possibility that their preventive measures will fail.

“You do the best you can; you make your firm ‘defensible’ at the least, and make sure your insurance is best in class,” he said.

Black Kite finds 42% above critical risk threshold

Black Kite also examined the current external cybersecurity posture of 2,289 trucking, freight arrangement and warehousing companies using scan data current as of August.

The average Ransomware Susceptibility Index, or RSI, among those companies was 0.388, slightly below Black Kite’s 0.4 threshold for critical ransomware susceptibility. The company found that 55.2% had an A-range cyber rating.

The average Data Breach Index was 0.088, compared with 0.178 among the large manufacturers Black Kite examined separately.

The averages, however, obscure a sizable group with significantly greater exposure.

Black Kite found that 42% of the distribution companies it examined (962 of the 2,289 businesses)  had an RSI of at least 0.4, placing them in its critical range. Black Kite also said publicly this week that 42% of its monitored distribution companies are above that threshold.

Another 372 companies, or 16.3%, had at least one vulnerability listed in the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, according to the report.

Black Kite also identified 270 companies, or 11.8%, with at least one active campaign FocusTag, its designation for exposure associated with an active vulnerability or attack campaign.

Among those 270 companies, 82.2% were above Black Kite’s critical RSI threshold. Their average RSI was 0.512, compared with 0.372 for the remainder of the distribution companies studied.

Criminals also target business processes

Skiba said distributors should look beyond traditional attacks on information technology systems because criminals increasingly target employees and business processes.

“Criminals are targeting the processes, not the IT department,” he said.

Skiba said accounts payable and other employees should independently verify requests to change banking information or make urgent payments using a known telephone number rather than contact information included in the request.

He also recommends requiring two-person authorization for automated clearing house transfers and payment changes above predetermined limits and training employees to identify spoofed display names and fabricated email threads.

Skiba said generative artificial intelligence is making some fraud attempts more convincing by allowing criminals to quickly customize invoices, vendor information and communications using publicly available information.

Those observations are Skiba’s assessment, rather than findings from the Black Kite report. His background as a fraud specialist and “Dr. Fraud” is independently documented.

One attack can spread across the supply chain

Black Kite’s findings also illustrate why cyber risk for distributors extends beyond their own networks.

An attack against a manufacturer, logistics provider, warehouse operator, or other supply chain partner can interrupt the movement of goods even when a distributor’s own systems have not been compromised.

Black Kite cited the May 2025 ransomware attack against Peter Green Chilled, a U.K. temperature-controlled warehousing and transportation company.

Attackers encrypted the company’s data and locked it out of its systems May 14, 2025. Transportation activities for orders already in the system continued, but new orders could not be processed, according to the report.

Peter Green Chilled served eight supermarket chains. One customer reported that thousands of packages of meat products were stranded in the company’s warehouse, while another shipment was unable to enter its distribution system.

The case illustrates the operational consequences for distributors: A cyberattack can become an inventory, transportation, and customer-service problem across multiple companies before the original victim restores its systems.

Black Kite’s distribution findings point to two related risks. The underlying number of ransomware incidents increased 26.7% in the first seven months of 2026 after adjusting for the Clop campaign, while 42% of the 2,289 distribution companies Black Kite currently monitors are above its critical ransomware susceptibility threshold.

For distributors, the exposure is not limited to their own systems. The interconnected nature of transportation, warehousing, suppliers, and customers means a successful attack anywhere along the chain can disrupt the movement of goods across multiple businesses.

Do not miss any content from Distribution Strategy Group. Join our list.


Share this article: