Manufacturing is the #1 most-attacked sector globally — and Texas sits at the intersection of defense supply chain flow-down, OT/ICS exposure, and semiconductor sovereign risk. IBM X-Force 2026 puts manufacturing at 27.7% of all recorded incidents. Dragos 2026 confirms 119 ransomware groups now targeting industrial orgs. CMMC L2 Phase 2 mandatory certification is ~150 days away. Every Texas manufacturer in the DIB supply chain needs to be prepared.
| Threat Category | TX Context | Source |
|---|---|---|
| Ransomware | 67%+ of all manufacturing ransomware victims in 2025 were manufacturing orgs. Average cost: $4.4M (IBM 2025). OT dwell time: 42 days average. | Dragos 2026; IBM CODB 2025; Sophos 2025 |
| OT/ICS Intrusion | 119 ransomware groups now targeting industrial orgs (up from 80 in 2024). 25% of ICS-CERT CVSS scores were incorrect. 26% of advisories have no patch. | Dragos 2026; ICS-CERT 2025 |
| IP / Trade Secret Theft | Semiconductor, aerospace, and automotive CAD files targeted by PRC and DPRK state actors. Renesas Electronics named by CoinbaseCartel (Dec 2025). | CISA AA24-038B; Oracle/CoinbaseCartel 2025 |
| Supply Chain Compromise | Oracle Cloud Austin: 140K tenants, 6M records exposed. Conduent: 14.7M TX individuals affected via downstream. Cl0p Cleo zero-days hit manufacturing supply chains 2024–2025. | ITRC 2025; Oracle breach disclosure; TX AG 2025 |
| BEC / Wire Fraud | Manufacturing procurement/accounts payable teams targeted for fake PO and vendor invoice scams. Avg BEC loss in manufacturing: $89K per incident. | FBI IC3 2024; IBM X-Force 2025 |
TX Supply Chain Case Study — Oracle Cloud Austin (2025):
Oracle Cloud's Austin data center breach exposed authentication materials for 140,000+ tenant organizations. Attackers generated persistent access tokens allowing long-term environment traversal. While Oracle serves enterprise customers broadly, the Austin-based exposure is directly relevant to TX manufacturers using Oracle ERP, NetSuite, or OCI workloads for supply chain, BOM, and procurement data. Tenant organizations include automotive suppliers, electronics manufacturers, and chemical processors in Texas.
Conduent downstream risk: Conduent's breach affected 14.7M Texas individuals — many through automated benefits, payroll, and HR processing systems used by manufacturing companies for workforce management. If your company processes employee benefits through a Conduent-connected system, your HR and payroll data may have been exposed.
Renesas Electronics — CoinbaseCartel Named Semiconductor Target (Dec 2025):
CoinbaseCartel (aka GhostSec, active in ransomware-as-a-service ecosystem) specifically named Renesas Electronics as a target in December 2025 disclosures. Renesas is one of the world's largest semiconductor manufacturers — with significant Austin/Texas-area design and engineering operations. The targeting signals a new vector: cryptocurrency-funded ransomware groups specifically targeting chip makers for data exfil and IP extraction. Texas semiconductor firms should treat this as a direct threat signal.
Filterable by sector subtype. Data sourced from public disclosures, ITRC, state AG notifications, and security research. Sources listed at end of report.
| Date | Company / Entity | Location | Sub-Sector | Type | Impact / Notes |
|---|---|---|---|---|---|
| Nov 2024 | LKQ Corporation | National (TX ops) | Automotive | Ransomware | Auto parts distributor with significant TX distribution. Ransomware incident disrupted supply chain distribution. LKQ serves 30K+ collision repair shops — TX body shops affected by supply delays. |
| 2024 | Benchmark Electronics | Austin, TX | Tech Manufacturing | Ransomware | Everest ransomware group claimed breach of Benchmark Electronics (NASDAQ: BHE). Tech manufacturing services provider with TX and global ops. Everest named as active threat in 2024–2025. |
| Nov 2025 | Oracle Cloud Austin | Austin, TX | Supply Chain | Supply Chain | 140,000+ Oracle Cloud tenants' authentication material exposed via Austin data center breach. 6M records potentially accessed. Manufacturing ERP and supply chain data at risk. |
| 2024–2025 | Conduent | National (TX affected) | Supply Chain | Supply Chain | 14.7M Texas individuals affected via Conduent's benefits and HR processing downstream. Manufacturing companies using Conduent for payroll/HR processing exposed. |
| Dec 2025 | Renesas Electronics | Austin, TX (design ops) | Semiconductor | APT/Ransomware | CoinbaseCartel specifically named Renesas as target in Dec 2025 disclosures. Major semiconductor manufacturer with Austin design and engineering presence. IP exfil risk, supply chain disruption. |
| Jun 2024 | CDK Global (downstream) | National (TX dealers) | Automotive | Supply Chain | ~1,300 TX auto dealers disrupted by CDK Global outage. ~15K dealers nationally. DMS supply chain attack disrupted F&I, service bay, and inventory management at TX dealerships. |
| 2024 | Foxconn (Mexico / TX adjacent) | Mexico / TX border | Aerospace / Electronics | Ransomware | LockBit ransomware attack on Foxconn Mexico operations. Foxconn has major TX manufacturing facilities. LockBit operational despite law enforcement disruption — used as precedent for TX targeting. |
| 2024 | Sargent & Lundy | National | Tech Manufacturing / Engineering | Ransomware | BlackCat/ALPHV ransomware attack on major engineering firm (BlackCat Feb 2024 collapse pre-incident). Disclosed in 2024. S&L designs power plants, industrial facilities — manufacturing-adjacent OT exposure. |
| 2024–2025 | Cleo / Cl0p Zero-Days (downstream) | National (TX mfrs affected) | Supply Chain | Supply Chain | Cl0p exploited Cleo file transfer zero-days targeting manufacturing supply chains 2024–2025. Hundreds of TX manufacturers running Cleo, Horizon, or VLTransfer affected — data exfil before encryption. |
Note: This database represents publicly confirmed incidents. Many manufacturing incidents go unreported due to competitive sensitivity, supply chain reputational concerns, and CUI/NIST 800-171 obligations. The actual incident count significantly exceeds public disclosures.
| Group | Type | Manufacturing Relevance | TX Exposure |
|---|---|---|---|
| RansomHub | RaaS | Successor to BlackCat affiliate ecosystem — actively targeting manufacturing supply chains | High — affiliate-driven targeting of mid-size manufacturers |
| Qilin | RaaS | Rust-based ransomware — manufacturing and industrial targets prominent | Medium-High — targeted campaigns against manufacturers |
| DragonForce | RaaS | Emerging affiliate-based group — manufacturing sector targeting observed in 2025 | Medium — growing TX manufacturing footprint |
| INC Ransom | RaaS | State Bar of TX breach (Jan 2025) — expanded to manufacturing targeting | High — TX-native target priority, healthcare + manufacturing |
| CoinbaseCartel | RaaS (crypto-funded) | Specifically named Renesas Electronics — semiconductor IP targeting signal | High for semiconductor/manufacturing |
| Obligation | Deadline | Trigger | Exposure | CoreRecon Coverage |
|---|---|---|---|---|
| CMMC L2 Phase 2 — Mandatory C3PAO Certification | Nov 10, 2026 | Any DoD contract with CUI handling — all DIB subcontract tiers | Contract suspension, False Claims Act exposure, SPRS score disclosure requirements | Command tier — CMMC L2 full implementation + C3PAO prep |
| DFARS 252.204-7012 — NIST 800-171 implementation | Immediate | All DoD contracts with CUI (flow-down to all subcontract tiers) | Contract termination, prime liability cascade, SPRS gap disclosure | Fortress tier — SPRS score improvement + SSP documentation |
| ITAR — Export-Controlled Technical Information | Ongoing — no grace period | Aerospace/defense manufacturers with CTI (CAD, BOM, process specs) | DDTC civil/criminal penalties, export license revocation, foreign national access violations | Command tier — ITAR-aware monitoring + U.S.-person-only SOC access |
| NIST 800-171 — 110 Controls for CUI Protection | Nov 10, 2026 | CUI in unclassified systems — DIB flow-down | SPRS score gaps = audit findings = contract risk | Fortress tier — control gap assessment + remediation roadmap |
| Texas SB 2610 — State Contractor Cybersecurity | Ongoing | TX state agency contracts with cybersecurity requirements | State contract disqualification, TX state agency relationship risk | Sentinel tier — TX SB 2610 baseline controls |
| EPA / TCEQ — Chemical Manufacturers | Ongoing — audit cycles | TSCA, EPCRA, and TCEQ Title 30 air/water compliance with digital systems | Environmental reporting system compromise = regulatory penalty cascade | Fortress tier — OT monitoring + EPA/TCEQ compliance support |
SPRS Score Reality Check: DoD's Supplier Performance Risk System (SPRS) requires self-assessment scores for all DIB contractors. A score below 110 = documented gap. If you get breached and DoD discovers your SPRS score was inaccurate at time of contract, False Claims Act exposure kicks in. The CMMC L2 Phase 2 deadline means C3PAOs will be reviewing your SPRS score and SSP documentation. CoreRecon's Fortress tier is specifically designed to drive your SPRS score upward and build the SSP artifacts that survive C3PAO review.
| Exposed Asset | Why It Matters | TX Context |
|---|---|---|
| PLCs (Allen-Bradley, Siemens, Schneider) | Direct production control — ransomware on PLCs = production stop | Aerospace, automotive, semiconductor TX facilities heavily rely on AB and Siemens PLCs |
| HMIs (Wonderware, FactoryTalk, Ignition) | Human-machine interfaces are the most exposed OT asset — often accessible via corporate network | TX chemical plants and oilfield equipment manufacturers use Wonderware HMIs predating current security standards |
| OT Historians (OSIsoft PI, Ignition, Ignition SCADA) | Production data treasure trove — IP theft + operational intelligence for attackers | TX semiconductor and aerospace manufacturers rely on PI historians for production quality tracking |
| SCADA Servers | Central control points for batch/process manufacturing — high-value targets | TX chemical, food/bev, and plastics manufacturers use SCADA for batch process control |
| Engineering Workstations | CNC/robot programming stations — often Windows 7, no patching, admin access | TX precision machining and aerospace parts suppliers run aging engineering workstations |
| IT/OT Boundary (patches to ERP/MES) | Every MES/PML integration is a potential pivoting point into OT | TX automotive suppliers running SAP/Oracle ERP connected to shop floor OT systems |
Organizations with OT visibility contained ransomware in avg 5 days vs. 42-day industry average (Dragos 2026): This is the CoreRecon OT monitoring thesis. Passive network traffic analysis at the IT/OT boundary detects anomalous behavior before production is affected. You don't need agents on PLCs — you need network-layer visibility into Modbus, DNP3, EtherNet/IP, and OPC-UA traffic. When Volt Typhoon actors are pre-positioning in your OT network, the dwell time advantage belongs to defenders who have OT visibility.
Minimum: 50 endpoints. CMMC L2 flow-down documentation included at all tiers. OT monitoring included at all tiers — no agent installation required on PLCs, CNC controllers, or robots. SOC analysts trained on Allen-Bradley, Siemens, Schneider, and Wonderware environments.