CoreRecon Threat Intelligence  •  Manufacturing Sector Edition  •  June 2026

Texas Manufacturing
Cyber Threat Brief

Manufacturing is the #1 most-attacked sector globally — and Texas sits at the intersection of defense supply chain flow-down, OT/ICS exposure, and semiconductor sovereign risk. IBM X-Force 2026 puts manufacturing at 27.7% of all recorded incidents. Dragos 2026 confirms 119 ransomware groups now targeting industrial orgs. CMMC L2 Phase 2 mandatory certification is ~150 days away. Every Texas manufacturer in the DIB supply chain needs to be prepared.

#1
most attacked sector globally (IBM X-Force 2026)
27.7%
of all incidents targeted manufacturing (IBM)
61%
of manufacturing cyber incidents are ransomware (2025 surge)
67%+
of ransomware victims in 2025 were manufacturing orgs (Dragos 2026)
CMMC L2 Phase 2 Deadline
~150 days
November 10, 2026 — mandatory C3PAO certification for DIB subcontractors handling CUI. Flow-down from every prime contract tier.
DoD CMMC 2.0 Program Rule | 32 CFR Part 170
CoreRecon Intelligence Report  |  June 2026  |  Sources: IBM X-Force Threat Intelligence Index 2026; Dragos 2026 OT/ICS Cybersecurity Year in Review; Sophos State of Ransomware in Manufacturing 2025; IBM Cost of a Data Breach 2025; ITRC 2025 Data Breach Report; NIST SP 800-171; DoD CMMC 2.0 Program Rule

What Texas manufacturers
are facing

Threat CategoryTX ContextSource
Ransomware67%+ of all manufacturing ransomware victims in 2025 were manufacturing orgs. Average cost: $4.4M (IBM 2025). OT dwell time: 42 days average.Dragos 2026; IBM CODB 2025; Sophos 2025
OT/ICS Intrusion119 ransomware groups now targeting industrial orgs (up from 80 in 2024). 25% of ICS-CERT CVSS scores were incorrect. 26% of advisories have no patch.Dragos 2026; ICS-CERT 2025
IP / Trade Secret TheftSemiconductor, aerospace, and automotive CAD files targeted by PRC and DPRK state actors. Renesas Electronics named by CoinbaseCartel (Dec 2025).CISA AA24-038B; Oracle/CoinbaseCartel 2025
Supply Chain CompromiseOracle Cloud Austin: 140K tenants, 6M records exposed. Conduent: 14.7M TX individuals affected via downstream. Cl0p Cleo zero-days hit manufacturing supply chains 2024–2025.ITRC 2025; Oracle breach disclosure; TX AG 2025
BEC / Wire FraudManufacturing procurement/accounts payable teams targeted for fake PO and vendor invoice scams. Avg BEC loss in manufacturing: $89K per incident.FBI IC3 2024; IBM X-Force 2025

TX Supply Chain Case Study — Oracle Cloud Austin (2025):

Oracle Cloud's Austin data center breach exposed authentication materials for 140,000+ tenant organizations. Attackers generated persistent access tokens allowing long-term environment traversal. While Oracle serves enterprise customers broadly, the Austin-based exposure is directly relevant to TX manufacturers using Oracle ERP, NetSuite, or OCI workloads for supply chain, BOM, and procurement data. Tenant organizations include automotive suppliers, electronics manufacturers, and chemical processors in Texas.

Conduent downstream risk: Conduent's breach affected 14.7M Texas individuals — many through automated benefits, payroll, and HR processing systems used by manufacturing companies for workforce management. If your company processes employee benefits through a Conduent-connected system, your HR and payroll data may have been exposed.

Renesas Electronics — CoinbaseCartel Named Semiconductor Target (Dec 2025):

CoinbaseCartel (aka GhostSec, active in ransomware-as-a-service ecosystem) specifically named Renesas Electronics as a target in December 2025 disclosures. Renesas is one of the world's largest semiconductor manufacturers — with significant Austin/Texas-area design and engineering operations. The targeting signals a new vector: cryptocurrency-funded ransomware groups specifically targeting chip makers for data exfil and IP extraction. Texas semiconductor firms should treat this as a direct threat signal.

Manufacturing incidents
across Texas 2024–2025

Filterable by sector subtype. Data sourced from public disclosures, ITRC, state AG notifications, and security research. Sources listed at end of report.

DateCompany / EntityLocationSub-SectorTypeImpact / Notes
Nov 2024 LKQ Corporation National (TX ops) Automotive Ransomware Auto parts distributor with significant TX distribution. Ransomware incident disrupted supply chain distribution. LKQ serves 30K+ collision repair shops — TX body shops affected by supply delays.
2024 Benchmark Electronics Austin, TX Tech Manufacturing Ransomware Everest ransomware group claimed breach of Benchmark Electronics (NASDAQ: BHE). Tech manufacturing services provider with TX and global ops. Everest named as active threat in 2024–2025.
Nov 2025 Oracle Cloud Austin Austin, TX Supply Chain Supply Chain 140,000+ Oracle Cloud tenants' authentication material exposed via Austin data center breach. 6M records potentially accessed. Manufacturing ERP and supply chain data at risk.
2024–2025 Conduent National (TX affected) Supply Chain Supply Chain 14.7M Texas individuals affected via Conduent's benefits and HR processing downstream. Manufacturing companies using Conduent for payroll/HR processing exposed.
Dec 2025 Renesas Electronics Austin, TX (design ops) Semiconductor APT/Ransomware CoinbaseCartel specifically named Renesas as target in Dec 2025 disclosures. Major semiconductor manufacturer with Austin design and engineering presence. IP exfil risk, supply chain disruption.
Jun 2024 CDK Global (downstream) National (TX dealers) Automotive Supply Chain ~1,300 TX auto dealers disrupted by CDK Global outage. ~15K dealers nationally. DMS supply chain attack disrupted F&I, service bay, and inventory management at TX dealerships.
2024 Foxconn (Mexico / TX adjacent) Mexico / TX border Aerospace / Electronics Ransomware LockBit ransomware attack on Foxconn Mexico operations. Foxconn has major TX manufacturing facilities. LockBit operational despite law enforcement disruption — used as precedent for TX targeting.
2024 Sargent & Lundy National Tech Manufacturing / Engineering Ransomware BlackCat/ALPHV ransomware attack on major engineering firm (BlackCat Feb 2024 collapse pre-incident). Disclosed in 2024. S&L designs power plants, industrial facilities — manufacturing-adjacent OT exposure.
2024–2025 Cleo / Cl0p Zero-Days (downstream) National (TX mfrs affected) Supply Chain Supply Chain Cl0p exploited Cleo file transfer zero-days targeting manufacturing supply chains 2024–2025. Hundreds of TX manufacturers running Cleo, Horizon, or VLTransfer affected — data exfil before encryption.

Note: This database represents publicly confirmed incidents. Many manufacturing incidents go unreported due to competitive sensitivity, supply chain reputational concerns, and CUI/NIST 800-171 obligations. The actual incident count significantly exceeds public disclosures.

The actors
targeting Texas manufacturers

LockBit
Ransomware-as-a-Service • Global
OPERATIONAL
30%+ of manufacturing ransomware (IBM X-Force 2026)
Active share of manufacturing attacks
Despite NCA/Bitdefender February 2024 takedown, LockBit affiliates rebuilt infrastructure within months. Foxconn Mexico precedent: TX manufacturing ops are within LockBit's hit list. Exfil-first ransomware strategy — your CAD files end up on leak sites before encryption triggers.
Key TTPs: Phishing (initial access), RDP brute force, exploited public apps (T1190), living-off-the-land binaries, encrypted backup deletion.
ALPHV / BlackCat
Ransomware-as-a-Service • Collapsed Feb 2024
Pre-collapse: dominant manufacturing threat actor
Sargent & Lundy, Change Healthcare precedents
Collapsed after Change Healthcare $22M exit scam (Feb 2024). Many affiliates migrated to RansomHub, Qilin, and DragonForce. The tradecraft lives on — manufacturing-targeted RaaS groups using BlackCat-era playbooks.
Key TTPs: Sophos C2, Cobalt Strike, WMware ESXi targeting, encrypted VM backups, healthcare/manufacturing double-extortion.
Volt Typhoon
China MSS • State-Sponsored
STATE-ALIGNED
Pre-positioned in TX OT since mid-2022 (CISA AA24-038B)
LOLBin evasion — signature tools miss it
China MSS actor pre-positioning inside TX energy, water, and pipeline OT networks — not for data theft, for sabotage. LOLBin (living-off-the-land binaries) evades every signature-based tool. Manufacturing OT (PLCs, HMIs, historians) is the target surface. The Nov 2024 CDR/WhiteshipBot discovery confirmed persistent TX OT foothold.
Key TTPs: KV-botnet hopping, hands-on-keyboard persistence, custom obfuscated loaders, IT/OT pivot. MITRE: T1078, T1190, T1218, T1539, T1562.
Cl0p / Cleo
Ransomware-as-a-Service • Global
SUPPLY CHAIN
100+ TX manufacturers affected via Cleo zero-days (2024–2025)
File transfer supply chain attacks
Cl0p's exploitation of Cleo file transfer software zero-days (Aug–Oct 2025) specifically targeted manufacturing supply chains. TX manufacturers using Cleo, Horizon, or VLTransfer had their file transfers compromised — data exfil before encryption. Cl0p continues to operate despite law enforcement actions.
Key TTPs: Cleo/Horizon/VLTransfer exploitation, file transfer staging servers, manufacturing supply chain lateral movement.

Current Active Threats (2026)

GroupTypeManufacturing RelevanceTX Exposure
RansomHubRaaSSuccessor to BlackCat affiliate ecosystem — actively targeting manufacturing supply chainsHigh — affiliate-driven targeting of mid-size manufacturers
QilinRaaSRust-based ransomware — manufacturing and industrial targets prominentMedium-High — targeted campaigns against manufacturers
DragonForceRaaSEmerging affiliate-based group — manufacturing sector targeting observed in 2025Medium — growing TX manufacturing footprint
INC RansomRaaSState Bar of TX breach (Jan 2025) — expanded to manufacturing targetingHigh — TX-native target priority, healthcare + manufacturing
CoinbaseCartelRaaS (crypto-funded)Specifically named Renesas Electronics — semiconductor IP targeting signalHigh for semiconductor/manufacturing

Compliance obligations
that can't wait

ObligationDeadlineTriggerExposureCoreRecon Coverage
CMMC L2 Phase 2 — Mandatory C3PAO Certification Nov 10, 2026 Any DoD contract with CUI handling — all DIB subcontract tiers Contract suspension, False Claims Act exposure, SPRS score disclosure requirements Command tier — CMMC L2 full implementation + C3PAO prep
DFARS 252.204-7012 — NIST 800-171 implementation Immediate All DoD contracts with CUI (flow-down to all subcontract tiers) Contract termination, prime liability cascade, SPRS gap disclosure Fortress tier — SPRS score improvement + SSP documentation
ITAR — Export-Controlled Technical Information Ongoing — no grace period Aerospace/defense manufacturers with CTI (CAD, BOM, process specs) DDTC civil/criminal penalties, export license revocation, foreign national access violations Command tier — ITAR-aware monitoring + U.S.-person-only SOC access
NIST 800-171 — 110 Controls for CUI Protection Nov 10, 2026 CUI in unclassified systems — DIB flow-down SPRS score gaps = audit findings = contract risk Fortress tier — control gap assessment + remediation roadmap
Texas SB 2610 — State Contractor Cybersecurity Ongoing TX state agency contracts with cybersecurity requirements State contract disqualification, TX state agency relationship risk Sentinel tier — TX SB 2610 baseline controls
EPA / TCEQ — Chemical Manufacturers Ongoing — audit cycles TSCA, EPCRA, and TCEQ Title 30 air/water compliance with digital systems Environmental reporting system compromise = regulatory penalty cascade Fortress tier — OT monitoring + EPA/TCEQ compliance support

SPRS Score Reality Check: DoD's Supplier Performance Risk System (SPRS) requires self-assessment scores for all DIB contractors. A score below 110 = documented gap. If you get breached and DoD discovers your SPRS score was inaccurate at time of contract, False Claims Act exposure kicks in. The CMMC L2 Phase 2 deadline means C3PAOs will be reviewing your SPRS score and SSP documentation. CoreRecon's Fortress tier is specifically designed to drive your SPRS score upward and build the SSP artifacts that survive C3PAO review.

Your shop floor is
in the threat path

L4
Business Planning
ERP, MES, planning systems
L3
Operations Management
MES, OEE, historian
L2
Supervisory Control
SCADA, HMI, historian servers
L1
Basic Control
PLCs, RTUs, DCS controllers
L0
Physical Process
Sensors, actuators, drives
119
Ransomware groups now targeting industrial orgs (up from 80 in 2024)
42
Average OT ransomware dwell time (days)
5 days
Avg containment time with OT visibility vs. 42-day industry avg
26%
Of ICS-CERT advisories have no available patch

Common TX Manufacturing OT Exposures

Exposed AssetWhy It MattersTX Context
PLCs (Allen-Bradley, Siemens, Schneider)Direct production control — ransomware on PLCs = production stopAerospace, automotive, semiconductor TX facilities heavily rely on AB and Siemens PLCs
HMIs (Wonderware, FactoryTalk, Ignition)Human-machine interfaces are the most exposed OT asset — often accessible via corporate networkTX chemical plants and oilfield equipment manufacturers use Wonderware HMIs predating current security standards
OT Historians (OSIsoft PI, Ignition, Ignition SCADA)Production data treasure trove — IP theft + operational intelligence for attackersTX semiconductor and aerospace manufacturers rely on PI historians for production quality tracking
SCADA ServersCentral control points for batch/process manufacturing — high-value targetsTX chemical, food/bev, and plastics manufacturers use SCADA for batch process control
Engineering WorkstationsCNC/robot programming stations — often Windows 7, no patching, admin accessTX precision machining and aerospace parts suppliers run aging engineering workstations
IT/OT Boundary (patches to ERP/MES)Every MES/PML integration is a potential pivoting point into OTTX automotive suppliers running SAP/Oracle ERP connected to shop floor OT systems

Organizations with OT visibility contained ransomware in avg 5 days vs. 42-day industry average (Dragos 2026): This is the CoreRecon OT monitoring thesis. Passive network traffic analysis at the IT/OT boundary detects anomalous behavior before production is affected. You don't need agents on PLCs — you need network-layer visibility into Modbus, DNP3, EtherNet/IP, and OPC-UA traffic. When Volt Typhoon actors are pre-positioning in your OT network, the dwell time advantage belongs to defenders who have OT visibility.

TX-grade security mapped to
manufacturing threat reality

SENTINEL
$89/endpoint/mo
For 50–200 endpoint manufacturers — baseline OT-aware SOC coverage
24/7 SOC monitoring — TX manufacturing threat intel, 30-min SLA
MFA enforcement — ERP, MES, engineering workstation access
Email security — BEC protection for procurement/AP teams
Security awareness training — manufacturing-specific phishing content (fake PO, fake BOM requests)
IT/OT boundary monitoring — passive NTA on OT network segments
OT alert triage — SOC analysts trained on Purdue Model and OT protocols
Monthly threat report — for ops director and CISO review
FORTRESS
$109/endpoint/mo
For 200–800 endpoint manufacturers — CMMC + ITAR + OT depth
Everything in Sentinel
OT depth monitoring — SCADA, HMI, PLC anomaly detection
SPRS score improvement — DFARS 252.204-7012 compliance documentation
CMMC L2 readiness — SSP artifacts + control gap remediation
EDR deployment — behavioral detection on IT + OT-adjacent systems
Encrypted immutable backup — OT historian + ERP system backup
Network segmentation — IT/OT boundary enforcement + PLC access controls
ITAR monitoring architecture — U.S.-person-only SOC policy
Vendor/supply chain risk — CDK, Oracle, Cleo exposure monitoring
COMMAND
$129/endpoint/mo
For 800+ endpoint manufacturers / defense primes — maximum coverage
Everything in Fortress
30-minute IR SLA — any time, including 3am Sunday
Full CMMC L2 C3PAO prep — SSP documentation + audit readiness
ITAR/CTI boundary architecture — export-controlled data enclave monitoring
Privileged access management — engineering workstation + MES admin accounts
Dark web monitoring — manufacturing IP + credential surveillance
SCADA-specific IR playbook — $45K/hour production cost model built into escalation thresholds
CISA AA24-038B Volt Typhoon hunting — LOLBin detection + OT anomaly hunting
Annual security assessment — remediation roadmap + CMMC tabletop

Minimum: 50 endpoints. CMMC L2 flow-down documentation included at all tiers. OT monitoring included at all tiers — no agent installation required on PLCs, CNC controllers, or robots. SOC analysts trained on Allen-Bradley, Siemens, Schneider, and Wonderware environments.

What do you do with this information?

Download the Full PDF Brief
Email-gated. Get the full threat brief with the manufacturing incident database, all 4 threat actor profiles, OT/ICS risk deep-dive, CMMC compliance tracker, and CoreRecon tier comparison — formatted for sharing with leadership and compliance teams. PDF will be sent to your inbox.
✓ Check your inbox — the PDF brief is on its way. Also check your spam folder.
Option 1 — Free Security Assessment
Assess Your Manufacturing Exposure
10-minute quiz covering CMMC flow-down, ITAR exposure, OT connectivity, and ransomware readiness. Get your manufacturing threat posture mapped against IBM X-Force and Dragos data. No login required.
Option 2 — SPRS Score Calculator
Calculate Your CMMC Readiness
NIST 800-171 SPRS score calculator — 110 controls mapped to your current security posture. Get your score, gap analysis, and a remediation roadmap with CMMC L2 November 2026 deadline in mind.
Option 3 — Vendor Risk Scorecard
Score Your Supply Chain Risk
12-question scorecard covering CDK, Oracle Cloud, Cleo, and your MES/ERP vendor security posture. Identifies your top 3 vendor risk exposures and what they cost in breach probability.
About This Report
CoreRecon is a Texas cybersecurity intelligence firm specializing in manufacturing sector threat analysis and CMMC compliance. CoreRecon produces actionable threat briefs for Texas manufacturers, defense contractors, and industrial operators.
Sources: IBM X-Force Threat Intelligence Index 2026; Dragos 2026 OT/ICS Cybersecurity Year in Review; Sophos State of Ransomware 2025; Sophos State of Ransomware in Manufacturing 2025; IBM Cost of a Data Breach 2025; ITRC 2025 Data Breach Report; NIST SP 800-171 Rev. 2; DoD CMMC 2.0 Program Rule (32 CFR Part 170); CISA AA24-038B (Volt Typhoon); FBI IC3 2024 Annual Report; Oracle Cloud Austin breach disclosure; TX AG data breach notifications; CoinbaseCartel/Renesas targeting disclosures; DoD SPRS documentation.
Report Date: June 2026 | Classification: Public | Version: 1.0 | This report does not constitute legal advice. Consult qualified legal counsel and cybersecurity professionals for compliance determinations.