India OT and IoT Threats: Manufacturing Under Pressure

India OT and IoT Threats: Manufacturing Under Pressure

India’s manufacturing sector faced up to 2,786 cyberattacks per week over a recent six month period, according to Check Point’s Manufacturing Threat Landscape 2025 report, reported in April 2026. The report found that 65 percent of Indian companies hit by ransomware paid the demand, with an average payment of 1.35 million US dollars, positioning India as what Check Point’s India managing director described as the Asia Pacific region’s ransomware epicentre for manufacturing. Legacy operational technology, including programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, and internet connected devices, was identified as a key source of exposure, since these systems were not designed with modern cybersecurity controls in mind.

Check Point’s report found that ransomware groups including Akira, Qilin and Play have actively targeted manufacturing networks, with Qilin identified as the group leading assaults on Indian organisations. Globally, ransomware attacks on manufacturing rose 56 percent in 2025, from 937 incidents in 2024 to 1,466 incidents. Within that global picture, the United States recorded the highest national total at 713 incidents, while India recorded 201, placing it among the higher volume targets despite its smaller share of global manufacturing output compared with the United States.

MetricFigure
Weekly cyberattacks on Indian manufacturing organisations (recent six month period)Up to 2,786
Reported manufacturing ransomware incidents, India, 2025201
Reported manufacturing ransomware incidents, United States, 2025713
Share of affected Indian companies that paid the ransom65%
Average ransom payment reported$1.35 million
Leading ransomware group targeting Indian manufacturingQilin
Exploited vulnerabilities as a share of manufacturing attack paths (global)32%
Phishing as a share of manufacturing attack paths (global)23%

Table 1. India’s manufacturing sector cyber exposure, 2025 to 2026. Source: Check Point, Manufacturing Threat Landscape 2025 report, reported April 2026.

A separate report, Seqrite’s India Cyber Threat Report 2026, published in May 2026, found that Trojan and infector malware accounted for nearly 70 percent of all attacks tracked across Indian organisations, with USB and shortcut based exploits surging again specifically in manufacturing environments. Seqrite’s analysis is based on telemetry from more than 8 million endpoints and over 265 million detections processed by its threat research labs.

What the source data shows

The chart below compares India’s reported manufacturing ransomware incident count against the United States, the country with the highest total in the Check Point dataset.

Figure 1. India’s reported manufacturing ransomware incident count of 201 in 2025 was well below the United States total of 713, but Check Point’s report still places India among the higher volume targets in the Asia Pacific region given its weekly attack frequency. Source: Check Point, Manufacturing Threat Landscape 2025 report, reported April 2026.

India recorded 201 manufacturing ransomware incidents in 2025, compared with 713 in the United States, yet Check Point describes India as the Asia Pacific region’s ransomware epicentre for manufacturing based on attack frequency and the high rate of ransom payment. The two findings are not contradictory. The incident count reflects confirmed ransomware cases, while the weekly attack figure of up to 2,786 reflects a broader measure of attempted intrusions and probing activity against Indian manufacturing networks, which Check Point’s report treats as a separate metric from confirmed ransomware incidents.

Check Point’s report also broke down how attackers most commonly reached manufacturing networks globally. Exploited vulnerabilities, particularly in legacy systems and internet facing applications, accounted for 32 percent of attacks, while phishing campaigns made up 23 percent, with increasing use of AI to craft personalised messages.

Why it matters

Legacy operational technology infrastructure, including PLCs, SCADA systems and IoT devices, was specifically named by Check Point as a factor making Indian manufacturing networks exploitable, because these systems were not designed with modern cybersecurity frameworks in mind. This matters because OT systems in manufacturing plants are often long lived, difficult to patch without halting production, and increasingly connected to IT networks and the internet as part of digitisation efforts, expanding the attack surface described in the report.

The 65 percent ransom payment rate among affected Indian companies, at an average of 1.35 million US dollars, also has a self reinforcing effect. A high ransom payment rate signals to ransomware groups that Indian manufacturing targets are likely to pay, which Check Point’s analysis links to India’s continued position as a high frequency target. Combined with Seqrite’s finding that USB based exploits are surging again in manufacturing specifically, the picture is one where both network level and physical access vectors remain active threats to Indian OT environments.

Risks, limitations and caveats

The source material presents two different measures, weekly attack attempts and confirmed ransomware incidents, without providing a direct conversion between them, so readers should not assume that 2,786 weekly attacks translate proportionally into the 201 confirmed incidents reported for the year. The country level comparison between India and the United States also reflects total reported incidents rather than a rate adjusted for the size of each country’s manufacturing sector, so the raw incident counts alone do not establish which country faces proportionally greater risk.

The Seqrite figure that Trojan and infector malware made up nearly 70 percent of attacks is drawn from Seqrite’s own telemetry across more than 8 million endpoints, and the source material does not specify what proportion of that telemetry comes specifically from manufacturing or OT environments as opposed to general IT systems.

Recommended actions

For security teams in Indian manufacturing organisations, the attack vector breakdown points toward two immediate priorities: patching internet facing systems and legacy OT components where exploited vulnerabilities are a factor, and strengthening phishing defences given that nearly a quarter of attacks reach networks this way. Given the resurgence of USB based exploits identified by Seqrite, reviewing and restricting removable media policies on shop floor systems is also a practical near term step, particularly for unmanaged endpoints on the plant floor.

Mapping these priorities to established guidance such as NIST SP 800-82, which addresses security for industrial control systems, or IEC 62443, the international series of standards for industrial automation and control systems security, can help structure a response. Given the high ransom payment rate Check Point identified, organisations should also ensure that incident response and business continuity plans for OT environments do not assume payment as the default path to recovery, since this expectation is part of what the report links to India’s continued targeting.

For executives, the central takeaway is that India’s manufacturing sector is being targeted at a frequency that Check Point characterises in regional superlatives, even though its confirmed incident count remains below that of the United States. Budget and governance discussions should reflect both the frequency of attempted intrusions and the financial exposure implied by the 1.35 million US dollar average ransom payment.

Conclusion

The Check Point and Seqrite findings, both reported within the past two months, describe a manufacturing sector in India where legacy OT systems, IoT devices, and unmanaged endpoints remain significant entry points, and where a high willingness to pay ransoms appears linked to continued targeting. While India’s confirmed 2025 ransomware incident count of 201 sits well below the 713 recorded in the United States, the weekly attack frequency and payment behaviour described in these reports indicate that the underlying exposure is substantial and likely to persist into the rest of 2026.

Leave a Reply

Your email address will not be published.