✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Manufacturing sector.
Explore Other Sectors
Manufacturing Threat Reports
Oracle EBS Exploited in Clop Ransomware Extortion Campaign (2025)
In September 2025, Oracle confirmed that customers running E-Business Suite (EBS) were targeted by extortion emails attributed to the Clop ransomware gang, following exploitation of security vulnerabilities addressed in the July 2025 Critical Patch Update. Multiple executives at affected companies received emails demanding ransom, with Clop claiming to have exfiltrated confidential data from unpatched Oracle EBS instances. While Oracle has not formally verified the data theft, the vulnerabilities—three of which were remotely exploitable without authentication—enabled attackers to potentially access sensitive business documents and threaten public disclosure if ransoms were not paid. This incident highlights a continued and escalating trend of ransomware groups leveraging zero-day and freshly patched vulnerabilities to target critical enterprise software. Organizations dependent on ERP and business process applications are increasingly at risk, underscoring the urgent need for rapid patching and advanced network-layer security controls.
6 months ago
Kill Chain
Asahi Ransomware Disruption: Lessons from a 2024 Supply Chain Attack
In June 2024, Asahi Group Holdings, a leading Japanese beverage manufacturer, experienced a disruptive ransomware attack that targeted its IT infrastructure. The incident led to shutdowns across several of its breweries and bottling plants, impacting production and distribution operations in Japan and parts of Europe. Initial investigations revealed that attackers penetrated corporate systems and deployed ransomware, encrypting critical files and demanding payment for restoration. While Asahi swiftly shut down affected systems to contain the threat, the disruption highlighted business continuity vulnerabilities and the risks inherent in operational technology integration. This attack underscores a rising trend in ransomware targeting critical supply chain sectors, particularly food and beverage manufacturing. As threat actors refine their methods and exploit operational downtime pressure, organizations across sectors face increasing urgency to harden east-west traffic security and implement zero trust segmentation to minimize lateral movement risks.
6 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach: 2024 Supply Chain Disruption Case Study
In early 2024, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that exposed the company’s vulnerability to advanced persistent threats. Attackers, suspected to be Medusa ransomware operators, leveraged residual access from a prior breach to re-enter JLR’s systems, eventually encrypting sensitive data and disrupting operations across its supply chain. The breach forced significant production slowdowns, delayed supplier payments, and prompted the company to enact emergency IT protocols and notify regulatory authorities. This incident highlights the growing threat of repeat ransomware campaigns targeting global manufacturers and their digital supply chains. It underscores the critical need for continuous detection, east-west network visibility, and rigorous post-breach remediation in defending against evolving ransomware tactics.
6 months ago
Kill Chain
Clop Ransomware Claims Oracle E-Business Suite Data Breach in 2025 Extortion Wave
In late September 2025, a widespread extortion campaign was detected targeting companies using Oracle E-Business Suite, with the Clop ransomware group (also tracked as FIN11) claiming to have exfiltrated sensitive data. Attackers used hundreds of compromised email accounts to send extortion messages to executives, demanding payment to prevent data leaks on Clop's darknet site. While links to previous Clop activity were identified through reused email accounts and familiar tactics, as of early October, no definitive evidence of a successful Oracle E-Business Suite breach has been confirmed by investigators (Mandiant, Google Cloud, and GTIG). As a result, organizations remain on alert as the situation develops, and incident response efforts continue. This attack underscores a continuing trend of cyber extortion groups leveraging data theft and email-based threats rather than traditional encryption. The campaign's timing and targeting highlight rapidly evolving attacker sophistication and the ongoing vulnerability of enterprise applications, emphasizing the importance of robust lateral movement controls and proactive monitoring in the face of persistent ransomware and extortion campaigns.
6 months ago
Kill Chain
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.
6 months ago
Kill Chain
Jaguar Land Rover’s 2025 Ransomware Crisis: Lessons on Supply Chain and Zero Trust Resilience
In September 2025, Jaguar Land Rover (JLR) was forced to halt production across multiple plants after suffering a catastrophic ransomware attack. The incident resulted in severe IT system disruption, suspended manufacturing operations, and subsequent data theft. A cybercrime group calling itself 'Scattered Lapsus$ Hunters' – reportedly linked to Scattered Spider and ShinyHunters – claimed responsibility, providing evidence of internal SAP system access. The attack’s impact exposed JLR’s business continuity vulnerabilities, prompted supply chain paralysis, and led the UK government to back a significant £1.5 billion loan guarantee to stabilize operations and prevent wider economic fallout. The breach highlights how ransomware actors are increasingly targeting critical manufacturing and supply chains for greater leverage. With mounting regulatory pressure and evolving attack tactics, strengthening enterprise resilience, zero trust architectures, and segmentation is more urgent than ever.
6 months ago
Kill Chain
Stellantis 2024 Salesforce Supplier Breach: Lessons on Third-Party SaaS Risk
In June 2024, automaker Stellantis confirmed that a cybersecurity incident impacted some of its North American customers after attackers compromised a third-party service provider’s platform integrated with their Salesforce infrastructure. The breach exposed sensitive customer data, though financial and highly confidential information reportedly remained secure. The attackers exploited weaknesses in the external vendor’s environment to gain unauthorized access, demonstrating the risks inherent in today's interconnected supply chains. Stellantis responded by notifying affected customers, engaging security experts, and working closely with the vendor to contain and investigate the incident. This breach highlights the ongoing surge of supply chain and third-party risks as enterprises rely on hosted platforms like Salesforce for mission-critical operations. The event underscores the increasing sophistication of attackers targeting SaaS ecosystems and underscores the need for robust supplier security controls and monitoring.
6 months ago
Kill Chain
Critical SAP S/4HANA Code Injection Vulnerability Exploited in 2025
In August 2025, a critical code injection vulnerability (CVE-2025-42957) in SAP S/4HANA was exploited in the wild, enabling attackers with even low-privileged user access to inject ABAP code and achieve full compromise of both the SAP environment and the underlying host OS. Publicly disclosed and patched by SAP in its August security updates, the flaw affects both private cloud and on-premise deployments. The exploit requires only a basic user account and a remote function call, after which attackers can manipulate or delete SAP data, create persistent admin backdoors, exfiltrate sensitive data, and control the OS. Exploitation attempts surged following patch publication, with confirmed abuse reported by specialist vendors. This incident highlights the increasing risk of low-complexity, high-impact ERP vulnerabilities, especially as attackers rapidly weaponize disclosed flaws. It underscores the continued targeting of critical business platforms by threat actors leveraging phishing and privileged escalation, emphasizing the urgent need for swift patching and stronger access controls.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports