Security
AI-powered and automation-driven cyberattacks are increasingly targeting Indian manufacturing plants, raising concerns over production downtime and supply-chain disruption, according to the India Cyber Threat Report 2026 released by Seqrite, the enterprise security arm of Quick Heal Technologies Limited.
Between October 2024 and September 2025, Seqrite recorded 265.52 million detections across more than 8 million endpoints in India, averaging 505 detections every minute. Engineering and Manufacturing alone accounted for 3.79 million detections, or 14.22% of total industry volume, placing it among the top three most targeted sectors alongside education and healthcare, which together contributed nearly 47% of overall detections.
The threat intensity closely mirrors India’s industrial footprint. Maharashtra, home to over 556,000 engineering and manufacturing units, recorded 36.13 million detections, the highest in the country. Gujarat followed with 24.13 million detections, reflecting its dense clusters of chemical and textile manufacturing, while Karnataka reported 11.64 million detections across more than 225,000 manufacturing units, and Tamil Nadu recorded 7.51 million detections, supported by 18,900 automotive units and over 142,000 engineering enterprises. Major industrial cities including Mumbai, Pune, Bengaluru and Chennai ranked among the most targeted urban centres, underscoring how concentrated production and export ecosystems are increasingly in the crosshairs.
Seqrite researchers observed that attackers are shifting from opportunistic malware to structured, automation-driven intrusion chains. High-volume threats such as Trojans (approximately 88.4 million detections) and File Infectors (approximately 71.1 million detections) together formed nearly 70% of all malware activity, often entering through phishing attachments, compromised utilities, exposed SMB services and infected design tools within factory environments. While ransomware accounted for less than one percent of total detections, it carried the highest operational risk. In January 2025 alone, ransomware peaked at 185 incidents and over 113,000 detections, driven by campaigns such as Xelera and Weaxor, highlighting how targeted enterprise intrusions can translate into plant-level disruption.
Network-based exploitation further amplified exposure, with more than 9.2 million exploit scans targeting internet-facing applications such as WordPress plugins, Apache Tomcat servers and enterprise management consoles. At the host level, over 8 million LNK-based exploit detections reinforced how even low-complexity vectors continue to propagate rapidly across shared industrial networks. Notably, 91% of detections originated from on-premise environments, indicating that legacy plant infrastructure and hybrid IT-OT integrations remain the primary attack surface.
Beyond operational disruption, breaches in manufacturing environments carry significant data protection implications. Exposure of design blueprints, supplier contracts, production data and employee records can trigger regulatory scrutiny and reputational risk. As manufacturing environments become increasingly data-intensive, privacy governance is moving closer to the shop floor. Seqrite noted that industrial enterprises must embed data protection into design systems, vendor integrations and plant analytics workflows rather than treating it as a compliance afterthought. Its indigenous Seqrite Data Privacy solution has been built to support Indian enterprises in operationalising privacy controls in line with the Digital Personal Data Protection Act while maintaining continuity across production environments.
As manufacturers accelerate digital adoption and integrate cloud platforms, supplier systems and operational technology, the report underscores that cybersecurity must move beyond perimeter defense. With AI now enabling automated reconnaissance, credential abuse and faster lateral movement, the risk is no longer confined to data theft. It extends directly to operational continuity, intellectual property protection and supply-chain resilience across India’s manufacturing backbone.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.



