45 Ivan Allen Jr Blvd NW
Atlanta, GA 30308
+1 (888) 808-7330
General: [email protected]
Sales: [email protected]
Support: [email protected]
Every year, a fresh crop of "most attacked industries" lists appears, and every year they disagree with each other. That is not because the underlying research is sloppy. It is because "most attacked" is four different questions wearing one coat: Which sector logs the most incidents? Which pays the most per breach? Which appears most often on ransomware leak sites? And which suffers the worst consequences when it goes down?
We built this ranking from four sources that measure different things — Verizon's 2026 Data Breach Investigations Report (31,000+ incidents and 22,000+ confirmed breaches across 145 countries, covering November 2024 through October 2025), IBM's 2026 X-Force Threat Intelligence Index, IBM's 2026 Cost of a Data Breach Report (published 29 July 2026), and quarterly ransomware victim tracking from GuidePoint's GRIT team and Comparitech. Where those sources disagree, we say so.
One editorial note before the list. Ransomware "victim counts" are drawn from criminal leak sites. They are attacker claims, not confirmed breaches, and groups routinely inflate, duplicate, and occasionally invent them. We use them because they are the best available proxy for targeting pressure, not because they are ground truth.
Manufacturing is the only sector that finishes first on nearly every measure. IBM X-Force put it at 27.7% of all incidents it responded to in 2025 — the fifth consecutive year in the top spot. Verizon logged 3,627 incidents and 2,713 confirmed breaches in NAICS 31–33, the largest confirmed-breach count of any vertical in the DBIR corpus. GRIT recorded 1,060 ransomware victims in manufacturing across 2025 (14% of all observed victims) and roughly 15% in Q2 2026.
The mechanics are unglamorous. Malware appeared in 75% of manufacturing breaches, with ransomware accounting for 61% of those. Vulnerability exploitation was the initial access vector in 38% of breaches — well above the cross-industry average of 31% — with phishing at 13% and credential abuse at 11%. Third parties were involved in 61% of breaches, the second-highest rate of any sector Verizon breaks out.
What makes manufacturing distinctive is not the intrusion; it is the leverage. The late-2025 ransomware attack on Asahi Group Holdings forced a shutdown of domestic production and suspended shipments. The ransom demand was the smallest line item in that incident.
Healthcare is not the most attacked sector. It is the most expensive one, and has been for thirteen consecutive years. IBM put the 2026 average healthcare breach at $6.64 million against a global average of $4.99 million, though notably that is down 10.5% from $7.42 million the prior year, the first meaningful decline in over a decade.
Verizon recorded 1,492 healthcare incidents and 1,438 confirmed breaches, an unusually high incident-to-breach conversion rate. Financial motive drove 99% of them. Two things separate healthcare from the rest of the list. First, internal actors accounted for 19% of breaches, and Miscellaneous Errors have appeared in healthcare's top three patterns in every DBIR since 2014 — misdelivery, lost devices, and internet-exposed data stores. Second, the pressure is migrating outward from providers. Comparitech counted 410 ransomware attacks on the healthcare sector in H1 2026 — roughly 2.3 per day — of which 247 hit direct care providers, and 163 hit the surrounding business layer. Attacks on providers rose about 3%; attacks on billing firms, manufacturers, and drug wholesalers rose nearly 35%, with medical retailers and wholesalers up 67%.
The Oracle E-Business Suite campaign attributed to Cl0p reached healthcare alongside everyone else, contributing to a third-party involvement figure of 32%.
Second-costliest sector in IBM's data at $6.29 million per breach, and the sector where third-party concentration risk is most visible.
Black Kite's 2026 financial services research found that among 140 tracked vendors serving financial institutions, confirmed breaches climbed from 6 to 39 in 12 months; among the top 20 most relied-upon vendors, from 1 to 7. Vendors carrying CVSS 9+ vulnerabilities grew 4.9x in a single year, from 15 to 73. The number of distinct ransomware groups targeting finance grew from 37 to 48, with Qilin alone claiming 59 finance-sector victims in 2025.
The Marquis Software incident is the reference case: a vendor compromise via a SonicWall vulnerability that reached 74 or more U.S. banks and credit unions, with regulatory filings in March 2026 putting exposure at between 672,000 and 1.35 million people. The institutions were not breached. Their supplier was.
The June 2026 NAIC intrusion is worth studying for a different reason. ShinyHunters claimed 3.1 terabytes across more than 105,000 files, affecting all 50 state insurance departments; NAIC's outside forensics concluded that the named regulatory filing systems were not accessed and that most of the exfiltrated material was already public. Both statements can be reported. Only one is verified.
Verizon logged 3,634 incidents and 2,410 confirmed breaches in NAICS 92, with incident volume nearly matching that of manufacturing. Vulnerability exploitation drove 40% of initial access, well above baseline, and accounted for 82% of hacking-related government breaches.
Government is the only sector on this list where espionage is a first-order motive rather than a rounding error: 33% of breaches carried an espionage motive, and state-affiliated actors appeared in 35%. Verizon cites the Silk Typhoon breach of the U.S. Department of the Treasury, which was achieved by exploiting a vulnerability in a third-party's cloud-based support software.
It is also the sector with the worst self-inflicted numbers. Internal actors were involved in 44% of breaches. Misdelivery accounted for 88% of all public-sector errors, and 91% of those errors were attributed to plain carelessness rather than to poor process or tooling.
Caveat, per Verizon's own methodology note: the public administration dataset draws on fewer contributors than private-sector verticals, and government entities operate under stricter mandatory reporting. The error and misuse figures are likely inflated relative to sectors that report fewer errors and misuses.
Technology ranks second in GRIT's annual ransomware tracking at 9% of observed victims, and IBM puts the average breach cost for technology at $5.50 million. But the sector's real significance is structural: it is the multiplier.
Verizon's headline third-party finding — breaches involving a third party rose 60% year over year to 48% of all breaches — is a statement about this sector's blast radius. IBM found that large-scale supply chain disruptions and third-party compromises have nearly quadrupled since 2020.
ReliaQuest's analysis of more than 600 Scattered Spider-linked domains found 81% impersonated technology vendors, and that roughly 70% of the group's targets sat in technology, finance, and retail. The group's shift toward MSPs and IT contractors is a deliberate one-to-many play: one help desk compromise, many downstream client environments.
The remediation data is the uncomfortable part. Of third-party organizations with missing or improperly secured MFA on cloud accounts, only 23% fully remediated. For weak passwords and permission misconfigurations, the time to resolve just half of all findings approached eight months.
Verizon recorded 997 retail incidents and 806 confirmed breaches. Two figures stand out: vulnerability exploitation drove 42% of initial access — the highest rate of any sector in this list — and third parties were involved in 68% of breaches, the highest third-party figure Verizon reports anywhere. External actors accounted for 99%.
Retail is also where identity-layer social engineering has been most visibly industrialized. Unit 42 and RH-ISAC tracked a cluster designated CL-CRI-1116 targeting retail and hospitality since February 2026, combining vishing calls impersonating IT help desk staff with credential-harvesting phishing pages, living-off-the-land techniques, and residential proxies to defeat IP reputation filtering. The 2025 UK retail wave — Marks & Spencer, Co-op, Harrods — followed the same playbook: a phone call to a help desk, not an exploit.
Verizon's phishing simulation data explains why this works. Median successful click rates on mobile-centric channels such as voice and SMS are 40% higher than for email.
The fastest-growing target set on this list. GRIT recorded legal-sector ransomware victims more than doubling, from 196 in 2024 to 455 in 2025 — a 132% year-over-year increase, compared with an overall sector growth rate of 58%.
Law firms, title companies, and compliance consultancies hold M&A plans, litigation strategy, IP filings, privileged communications, and financial disclosures — material with extortion value that does not require encryption to monetize. Activity attributed to UNC3753 reflects exactly that shift: data theft and extortion over ransomware deployment. Google Threat Intelligence Group documented a campaign running through early 2026 against legal, financial, and professional services organizations that opens with a benign invoice-themed email.
Professional services firms tend to be small relative to the value of what they hold, which is a poor combination.
Verizon logged 1,302 incidents and 1,252 confirmed breaches in NAICS 61 — again, an unusually high conversion rate. System Intrusion accounted for 52% of education breaches, roughly three times as much as any other pattern. Vulnerability exploitation drove 34% of initial access, phishing 22%. Ransomware appeared in 65% of malware-related breaches, and web applications were the malware vector in 71% of cases.
The sector-level trend is genuinely split, and most coverage misses it. Comparitech recorded 104 ransomware attacks targeting education in H1 2026, down 13% overall — but K-12 fell by 26% while higher education rose by more than 8%. The Gentlemen drove much of that increase, with education attacks up 275% half-over-half and 80% of its education claims against colleges and universities. Median ransom demands in the sector rose 53% to $420,620, with a $1.9 million demand following the Mount Royal University attack.
Third parties were involved in 40% of education breaches. The Oracle E-Business Suite zero-day campaign compromised more than 100 organizations, with a heavy concentration in this sector.
Verizon's utilities data covers 638 incidents and 597 confirmed breaches, with System Intrusion, Basic Web Application Attacks, and Social Engineering accounting for 94% of them. IBM found financial services and energy absorbed the heaviest concentration of AI-driven attacks in its 2026 dataset.
The IT-side numbers understate the sector. Dragos now tracks 26 OT threat groups globally, 11 of them active in 2025, and named three new ones in its 2026 report — including SYLVANITE, an initial access broker observed exploiting Ivanti vulnerabilities at U.S. electric and water utilities and handing footholds to VOLTZITE. KAMACITE spent 2025 systematically mapping control loops across U.S. infrastructure. ELECTRUM targeted distributed energy systems in Poland with deliberate attempts to affect operational assets. Dragos's research into battery energy storage systems found authentication bypass and command injection flaws across over 100 internet-exposed devices, including roughly 1MW of grid inverters.
The single most actionable statistic in the sector: organizations with comprehensive OT visibility detected and contained OT ransomware incidents in an average of 5 days, compared with an industry-wide average of 42 days.
The newest entry, and the one where cyber intrusion most directly funds physical crime.
In April 2026, the FBI's IC3 issued a public service announcement on cyber-enabled strategic cargo theft. Since at least 2024, threat actors have compromised brokers and carriers via spoofed email, fake URLs, and hijacked carrier accounts, then used that access to post fraudulent listings on load boards — sometimes tens of thousands of fake loads — to divert real freight. Proofpoint documented coordinated remote-access campaigns targeting trucking and logistics firms, designed to steal cargo and redirect payments. North American cargo theft losses reached $6.6 billion in 2025.
Logistics is also the sector where "was data exfiltrated?" is the wrong first question. Missed delivery windows, port congestion, customs delays, and cascading partner effects are the loss event.
Just outside the top ten: construction. GRIT ranked it fourth by ransomware victim volume in Q1 2026, with 131 victims — up 12% quarter-over-quarter and 44% year-over-year — against a broader quarterly decline. Blueprints, subcontractor bids, and change orders carry independent extortion value, and halted work triggers contract penalties. If the trajectory holds, it will be inside the top ten next year.
Read the ten sections above, and the sector labels start to look like packaging. Underneath them sit four mechanics who barely vary across industries.
Vulnerability exploitation has overtaken credentials. For the first time in nineteen editions of the DBIR, exploitation of vulnerabilities is the leading initial access vector, at 31% of breaches, down from 38% in the previous edition. Credential abuse is down to 13%. IBM observed a 44% increase in attacks beginning with the exploitation of public-facing applications, largely driven by missing authentication controls. The defensive picture went backward: only 26% of CISA KEV-cataloged critical vulnerabilities were fully remediated in 2025, down from 38%, and the median time to full resolution rose from 32 to 43 days, while the median organization had 50% more critical vulnerabilities to patch.
Your third parties are your attack surface. Third-party involvement reached 48% of all breaches, up 60% year over year. That figure ranges from 68% in retail to 32% in healthcare, but it is not small in any sector.
Ransomware has stopped being about encryption. It appears in 48% of breaches, up from 44%. But 69% of victims did not pay; median payments fell to $139,875; and GRIT tracked a record 91 active groups across 108 countries in Q2 2026, with the top five accounting for over 40% of attacks. The economics have shifted toward data theft and extortion, which means backups alone no longer constitute a recovery plan.
The human element is holding at 62%, and it has moved to the phone. Pretexting has become a more common precursor to ransomware and extortion, and mobile-centric social engineering outperforms email-based social engineering by 40% in simulations.
Specifically on AI, the data does not support the marketing. Verizon found that the median threat actor used AI assistance across about 15 documented techniques. Most AI-assisted tooling replicated well-established attack functions, with a median of 55 existing malware examples doing the same job, and fewer than 2.5% of observations involved genuinely uncommon techniques. GRIT reached the same conclusion from a different angle: threat actors are using LLMs to analyze exfiltrated data and personalize ransom negotiations, not to invent new attack classes. IBM's cost data does show AI-driven attacks up 56% year over year and adding roughly $1 million to average breach cost — but also that 92% of organizations suffering an AI-related breach lacked proper AI access controls. That is a governance failure, not a novel threat.
Why Organizations Choose Zaxtron
Organizations face increasingly sophisticated ransomware campaigns that exploit unpatched systems, stolen credentials, exposed remote access, and third-party weaknesses. To stay protected, they need actionable intelligence, not just alerts, to identify and reduce cyber risks before disruption occurs. Zaxtron provides Cybersecurity Risk Management, AI Risk Management, and Cyber Threat Intelligence services that deliver continuous visibility and risk-based insights. By combining attack surface intelligence, vulnerability data, threat and breach intelligence, and third-party risk analysis, Zaxtron offers a complete view of cyber exposure. This helps security leaders respond to threats, improve vendor security, and make informed decisions. Contact Zaxtron to strengthen cyber resilience today.
Cookie preferences