

APT Campaigns – 5.6
10 of 57 campaigns (18%), down from a 26% share as total APT activity doubled. Unusually balanced actor mix with no dominant cluster. Leviathan’s maritime and resource supply chain focus indicates targeted rather than incidental interest. Database targeting points to commodity and pricing data collection.
Cyber Incidents – 6.0
Only 3 incidents in 90 days, all ransomware, all unattributed. A title search across 695 reports confirms under-reporting rather than low exposure. FortiBleed leaked credentials for 73,932 FortiGate devices sitting at the IT/OT boundary, later linked to Inc and Lynx ransomware operations.
Dark Web Chatter – 5.9
903 mentions, placing 9th of 14. Breach and leak chatter shows V-shaped recovery rather than the collapse seen in other sectors, suggesting genuine renewed targeting rather than forum disruption. Claimed hacks the only category rising uninterrupted across all periods.
Vulnerabilities – 4.9
1.37% of industry-linked disclosures, ranking 13th of 14, the lowest volume in the report. DoS emerged from near zero to the second-highest category in the final period, carrying outsized weight for continuous production processes. Memory and buffer vulnerabilities trending steadily upward.
Ransomware – 4.6
97 victims, down 29.2% Q-on-Q, with share falling from 6.0% to 4.38%. Country spread contracted from 43 to 34, the largest reduction of any sector this period. 31% gang participation is low, and volume leaders Thegentlemen and Qilin show minimal sector share, indicating opportunistic targeting.
The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each week for a quarter. This report focuses on the materials industry, presenting key trends and statistics in an engaging infographic format.
Welcome to the CYFIRMA infographic industry report, where we delve into the external threat landscape of the materials industry over the past three months. This report provides valuable insights and data-driven statistics, delivering a concise analysis of attack campaigns, public reports, underground & dark web chatter, vulnerabilities, and ransomware incidents targeting materials organizations.
We aim to present an industry-specific overview in a convenient, engaging, and informative format. Leveraging our cutting-edge platform telemetry and the expertise of our analysts, we bring you actionable intelligence to stay ahead in the cybersecurity landscape.
CYFIRMA delivers pre-emptive cybersecurity, cyber threat intelligence, and external threat landscape management through its platforms, DeCYFIR and DeTCT. These platforms have been purpose-built over many years to continuously collect, correlate, and analyse large volumes of external threat data, combining proprietary intelligence automation with deep, hands-on cyber threat research.
For the purpose of this report, the analysis draws on intelligence generated from CYFIRMA’s platforms. The data referenced has been processed through automated correlation and enrichment mechanisms, informed and validated by human-led research and investigative expertise, and sourced from both structured and unstructured external intelligence channels.
While this report contains data collected and processed by our in-house AI and ML, all charts, statistics, and analyses are done by human CYFIRMA CTI analysts to ensure the highest quality and provide accurate insights.
Materials organizations featured in 10 out of the 57 observed campaigns, which is a presence in 18% of all campaigns.An increase from the previous period, when materials organizations were present in 7 out of 27 campaigns. However, a decline from the presence in 26% of observed campaigns.


APT activity targeting Materials has been continuous. Most of the campaigns have been active and have been updated with new detections as recently as July.

Observed APT campaigns show a balanced nation-state actor distribution this period, with no single actor or country cluster dominating heavily. China-linked actors lead through Leviathan and TICK jointly recording the highest campaign counts, with APT27 and Stone Panda providing additional representation.
Russia-linked Fancy Bear and Cozy Bear both feature across multiple campaigns, alongside North Korea-associated Lazarus Group and Iran-linked OilRig. Financially motivated actor TA505 also appears, reflecting the sector’s exposure to both state-sponsored and opportunistic targeting.

Victim distribution spans 28 countries, with the United States recording the highest victim count, followed closely by Japan. Taiwan, Singapore, Malaysia, Thailand, South Korea, Australia, Germany, and Indonesia all feature in the mid-frequency tier, reflecting broad targeting across both major economies and emerging markets.
Southeast Asia is more prominently represented than in most sectors, with Singapore, Malaysia, Thailand, Indonesia, Myanmar, Cambodia, Brunei, Timor-Leste, and Laos all recording victims, consistent with Leviathan’s known focus on maritime routes and resource supply chains in the region. European presence is also broader than typical, with Germany, Spain, Belgium, France, and the Netherlands all recording multiple victims, consistent with the Russian actor presence observed this period.
Middle Eastern presence is noted through Saudi Arabia and the UAE. China recording two victim entries is higher than the single instances seen in most other datasets this period.

Web applications account for the highest number of observed attacks, with operating systems and database management software also featuring across multiple campaigns. Database management software recording three instances points to data exfiltration as a likely objective across several campaigns, consistent with the sector’s concentration of commodity pricing, supply chain, and proprietary materials data.
Remote desktop software appears across two campaigns alongside a single instance of VPN solutions, pointing to persistent remote access as a secondary objective. The relatively narrow technology distribution reflects a more focused intrusion pattern despite the broad geographic and actor spread observed this period.

Based on observed trajectory across the two reporting periods, the materials sector external threat landscape is expected to remain at Elevated through the next 90 days. While campaign presence grew in absolute terms from 7 to 10, the sector’s share of all observed campaigns declined from 26% to 18% as overall APT activity more than doubled across the period. This indicates sustained rather than escalating targeting, with materials organizations maintaining a consistent presence in the threat landscape without attracting disproportionate new attention.
Sustained volume: Campaign presence grew from 7 out of 27 to 10 out of 57 observed campaigns period over period. The apparent concentration in June and July reflects platform update and detection stacking patterns rather than a genuine gap in activity. 9 to 12 materials sector campaigns over the next 90 days is a plausible baseline estimate.
Dominant actor continuity: Leviathan and TICK jointly recorded the highest campaign counts and are expected to maintain operational tempo. Leviathan’s known focus on maritime routes and resource supply chains is directly relevant to the sector, indicating targeted rather than opportunistic interest.
Data exfiltration focus: Database management software recording three instances alongside web applications and operating systems points to commodity pricing, supply chain data, and proprietary materials information as primary collection objectives. Organizations with externally accessible databases or unpatched web infrastructure face the highest immediate risk.
Geographic targeting: The United States and Japan lead in victim count, with broad targeting across Indo-Pacific economies and Southeast Asian maritime corridors. The unusually strong Southeast Asian footprint, spanning Singapore, Malaysia, Thailand, Indonesia, Myanmar, Cambodia, Brunei, Timor-Leste, and Laos, is expected to persist given Leviathan’s regional focus.
Multi-actor threat profile: Russia-linked Fancy Bear and Cozy Bear, North Korea-associated Lazarus Group, and Iran-linked OilRig all feature alongside China-linked actors and financially motivated TA505. Defenders should prioritize TTP-based detection over actor-specific IOC tracking given the breadth of nation-state representation observed this period.
Over the past 90 days, DeCYFIR and DeTCT platforms tracked 699 cyber incidents reported publicly. We could identify the industry for 511 of these incidents (73%).
The materials industry was detected in 3 incidents, which equals 0.59% of the incidents where we knew the industry, ranking 13th out of 14 industries.

Software supply chain attacks dominated the period, with 66 reports, followed by phishing (52) and credential theft (47). Most reports describe a worm called Shai-Hulud that spread through npm and PyPI, infecting official SAP and CheckMarx packages, TanStack, and over 600 npm packages. TeamPCP is linked to this activity.
ShinyHunters, the most reported actor, was involved in the Instructure and Canvas breaches and smaller data disclosures like Vimeo and Zara.
Most reported actors were criminal, with Russia, China, and Iran being the most common countries of origin. The United States was the most affected country, followed by the United Kingdom.
Information Technology accounts for about 40% of industry-tagged reports, reflecting the coverage of software vendors and platforms. AI-assisted attacks appeared 30 times, becoming a common category.
The Materials sector appeared only three times in 90 days, all cases of ransomware with no named attackers or countries of origin. In June, a cyberattack stopped operations at major Australian sugar mills during the harvest, and a ransomware group later claimed it. In July, a Latvian forestry company was still restoring its systems after an attack.
This low number doesn’t mean the sector is safe. It means public sources rarely report on it. I searched 695 titles for words like mining, chemicals, steel, agriculture, cement, paper, packaging, and fertiliser, and found nothing beyond these three. This isn’t a labeling problem in the data. Western security vendors and government CERTs report less on medium-sized industrial and agricultural companies, and both incidents above fit that profile. The small sample shows consistent attacks: opportunistic ransomware, physical production stoppage, and weeks of recovery.
The materials sector shares most of its threat profile with manufacturing. Both run industrial control systems, both depend on continuous physical production, and both lose money by the hour when operations stop. Attackers do not choose targets by sector label; they choose by exposed equipment and by willingness to pay. For this reason, the manufacturing incidents below should be read as directly relevant to materials companies, even though the named victims are not materials firms.
FortiBleed is the most important exposure of the quarter, and it affects every sector equally. From mid-June, a leak of credentials for 73,932 FortiGate devices developed into an active campaign in which attackers deployed a custom Go-language sniffer on the firewalls themselves to collect more credentials. CISA issued an urgent advisory on 19 June. By 2 July, the same actors were reported working with the Inc and Lynx ransomware gangs, which turns a credential problem into a ransomware problem. This is not a materials-specific campaign; it is an infrastructure campaign, but FortiGate appliances are commonly installed exactly at the boundary between office IT and plant OT networks, because that is where segmentation is enforced. Stolen credentials for that device class are a direct route into production networks. Any materials company running FortiGate should treat patching and credential rotation as immediate work.
Iranian OT targeting is the clearest state-linked threat to industrial operations. In mid-April, nearly 4,000 US industrial devices were reported as exposed to Iranian cyberattacks, and on 22 July federal agencies broadened their alert on Iran-linked OT activity. This targeting concentrates on fuel, water and energy systems, but the equipment involved is the same equipment used in mining, chemicals and processing plants.
Ransomware caused the most visible operational damage. Foxconn, the world’s largest electronics contract manufacturer, was hit by the Nitrogen ransomware gang on 13 May. West Pharmaceutical disclosed a ransomware attack affecting business operations on 12 May. Both are attributed only at the level of the ransomware brand, with no wider actor identification.
Data extortion reached industrial companies through the same actors active in every other sector. ShinyHunters claimed Kodak on 17 June, and Tata Electronics confirmed a breach with data leaked on 23 June, with attribution unconfirmed. These are opportunistic extortion campaigns, not sector-specific targeting.
Espionage against aviation suppliers is worth watching. Two reports, on 1 May and 11 May, described cyber-espionage against Russian aviation firms aimed at satellite, GPS and mapping data, most likely connected to the intelligence dimension of the Russia-Ukraine war. The China-attributed Shadow-Earth-053 campaign, reported on 30 April, targeted government and defence organizations across Asia and touched industrial suppliers through defence-adjacent targets.
Two incidents in the period involved materials companies directly, and both follow the same pattern. In June, a cyberattack stopped operations at major Australian sugar mills during the harvest, and a ransomware group later claimed it. In July, a Latvian forestry company was still restoring its systems several weeks after a ransomware attack. Neither has a named attacker or an attributed country. Both were opportunistic ransomware attacks that halted physical production for weeks.
Only three of the 695 reports in this period concern materials companies. That is 0.4 percent. Security vendors and government CERTs rarely report on mid-sized industrial, mining, and agricultural victims, so this number measures reporting coverage rather than real risk. Ransomware leak site monitoring and industry trade media would be needed to see the actual level of activity against this sector.

The materials sector faces an elevated risk over the next 90 days. Current trends, actor capabilities, and observed operational patterns predict the following developments:
FortiGate credential harvesting at the IT/OT boundary. The FortiBleed campaign exposed credentials for 73,932 FortiGate devices, and attackers deployed a custom Go-language sniffer to collect more. These appliances segment office IT and plant OT networks. On July 2, FortiBleed actors collaborated with Inc and Lynx ransomware gangs, converting stolen credentials into production downtime. This is infrastructure-targeted, not materials-targeted, but materials companies should patch and rotate credentials immediately due to CISA’s June advisory.
Sustained Iranian OT reconnaissance. Nearly 4,000 US industrial devices were exposed to Iranian cyberattacks in mid-April, and federal agencies broadened their alert on Iran-linked OT activity on July 22. This remains the most concrete state-linked threat to industrial operations, targeting fuel, water, and energy systems, but the same device classes run in mining, chemical, and processing plants. Current geopolitical conditions make a reduction unlikely.
Supply chain compromise as an indirect route. Software supply chain attacks, driven by the Shai-Hulud worm in npm and PyPI, were the leading technique across all sectors, with 66 reports. Materials companies rarely write their own software, but their plant vendors, ERP integrators, and maintenance suppliers do. The Foxconn ransomware attack on May 13 and the Tata Electronics breach on June 23 show that upstream industrial suppliers are being hit, causing equipment and component delays that disrupt materials operations.
Opportunistic data extortion as a background risk persists, with the ShinyHunters’ claim against Kodak and the unconfirmed Tata Electronics leak reflecting campaigns across sectors, not materials-specific interest. Control-system attack surfaces are expanding faster than defensive maturity in this sector, as a critical flaw in OT Robot OS reported on 20 May gave attackers direct control over industrial robotics, and OT-tagged incidents rose from 4 to 6 across the last two 30-day windows.
Over the past 90 days, CYFIRMA’s telemetry has identified 903 mentions of materials organizations out of a total of 27,648 industry-linked mentions. This is from a total of 300k+ posts across various underground and dark web channels and forums.
Materials organizations placed 9th out of 14 industries in the last 90 days with a share of 3.27% of all detected industry-linked chatter.
Below is a breakdown by 30-day period of all mentions.


Underground & dark web chatter related to the materials sector over the last 90 days shows variable rather than consistently declining activity, distinguishing it from the broader forum disruption pattern observed across other sectors. Data breaches and data leaks decline mid-period sharply before recovering substantially in the final period, suggesting renewed targeting activity rather than a monitoring gap. Ransomware mentions remain present across all periods with moderate fluctuation. DDoS and hacktivism show notable mid-period elevation followed by decline in the final period. Web exploits remain stable throughout, while claimed hacks show a consistent upward trend across all periods.

The materials sector shows a distinct chatter pattern compared to other sectors in this report. The V-shaped recovery in data breach and data leak discussions, rather than the consistent decline seen elsewhere, suggests the final-period rebound reflects genuine renewed targeting activity rather than a forum disruption artifact. This makes the dataset more interpretable than sectors, where visibility gaps complicate trend analysis.
Data Breach and Data Leak: The sharp mid-period drop followed by near-full recovery in the final period is the defining characteristic of this dataset. Unlike sectors where decline aligns cleanly with BreachForums disruptions, the materials sector recovery suggests active and renewed interest in breach and leak activity, with final-period volumes returning close to initial levels.
Ransomware: Present and relatively consistent across all three periods despite moderate fluctuation. No sustained directional trend in either direction, indicating stable rather than growing or declining ransomware interest in this sector. Remains the most consistent threat signal across the full window.
Claimed Hacks: The only category showing an uninterrupted upward trend across all three periods. This gradual escalation against an otherwise variable backdrop is notable, suggesting growing interest in access acquisition and intrusion claims involving materials entities independent of broader forum dynamics.
DDoS and Hacktivism: Both decline in the final period after mid-period elevation. The concurrent timing of their peaks mid-period may indicate a coordinated or geopolitically driven episode rather than sustained campaign activity, with momentum not carrying into the final period.
Web Exploit: Stable and consistent throughout. Reflects persistent but limited probing activity with no escalation signal currently.
Over the past 90 days, CYFIRMA’s telemetry has identified 50 mentions of materials organizations out of a total of 3,652 industry mentions. This is from over 10k CVEs reported and updated in the last 90 days.
Materials organizations ranked 13th out of 14 industries in the last 90 days with a share of 1.37% of all detected industry-linked vulnerabilities.
Below is a breakdown by 30-day period of all mentions.


Reported CVEs in the materials sector over the last 90 days show low overall volume with notable shifts in the final period. Remote and arbitrary code execution vulnerabilities spike mid-period before a partial decline, remaining elevated above initial levels. Denial of service vulnerabilities emerge sharply in the final period after minimal prior activity. Memory and buffer vulnerabilities show a gradual upward trend across all periods. Injection attacks, cross-site scripting, and privilege escalation remain minimal and stable throughout.

Materials registers low overall CVE volume relative to other sectors in this report, but two converging factors prevent a moderate score: the emergence of DoS vulnerabilities in the final period against a sector reliant on continuous production processes, and the broader OT and infrastructure threat context that applies directly to materials operations regardless of sector-specific CVE volume.
Remote & Arbitrary Code Execution: The dominant category despite low absolute numbers, with a mid-period spike partially persisting into the final period. Remains the primary CVE-driven risk signal given direct compromise potential against materials processing and industrial control systems.
Denial of Service: The sharpest trend in this dataset, emerging from near zero to become the second-highest category in the final period. In a sector reliant on continuous production processes, DoS-enabling vulnerabilities carry disproportionate operational risk relative to their disclosure volume.
Memory & Buffer Vulnerabilities: The only category showing a consistent upward trend across all three periods. Likely reflects vulnerabilities in embedded systems or industrial software components common in materials processing environments.
FortiGate and IT/OT Boundary Exposure: The FortiBleed campaign exposed credentials for tens of thousands of FortiGate devices, which sit at the segmentation boundary between office IT and plant OT networks. Confirmed linkage between FortiBleed actors and Inc and Lynx ransomware groups converts stolen credentials directly into production downtime risk. Materials companies running FortiGate should treat patching and credential rotation as immediate priorities given CISA’s June advisory.
OT Attack Surface: A critical flaw in OT Robot OS reported in May gave attackers direct control over industrial robotics. OT-tagged incidents increased across the final two periods of the window. The attack surface in materials-relevant industrial environments is expanding, and the DoS emergence in the final period of this CVE dataset aligns with that broader trend.
Injection Attacks, Cross-Site Scripting, and Privilege Escalation: All remain minimal throughout, with no escalation signal and do not currently contribute meaningfully to the sector’s CVE risk profile.
In the past 90 days, CYFIRMA has identified 97 verified ransomware victims in materials organizations. This accounts for 4.38% of all 2,214 ransomware victims during the same period, placing this sector 9th out of 14 industries.

Furthermore, a quarterly comparison shows that the number of victims in materials organizations has declined. It went from 137 to 97 victims, a -29.2% decline. The overall interest, represented by the share, also dropped significantly from 6.0% to 4.38% of all victims.


Monthly activity has been declining steadily since the December 2025 peak of 64 victims. February and April 2026 showed minor jumps in activity.

A breakdown of monthly activity per gang reveals which gangs were most active each month. For instance, The Gentleman gang was mostly active in May and, after a lower number in June, picked up pace again in July.
On the other hand, LockBit and Settra recorded nearly all victims during June.

Out of the 86 gangs, 27 recorded victims in materials organizations in the last 90 days, representing a 31% participation.
Thegentlemen and Qilin had the highest numbers of victims but a minimal share of their victims in this industry, recording 5.0% and 4.2% of all their victims in the materials industry.
Lamashtu (17.6%) and Settra (16.1%) stand out as gangs with the highest shares of materials victims.
On average, gangs active in this industry recorded an 8.34% share of their victims from this industry. That is about 1 in 12 victims.

Raw Agricultural Products and Specialty Chemicals dominated victim counts, reflecting persistent threat actor interest in commodity supply chains and chemical manufacturers holding sensitive formulation and client data. Packaging Materials and Construction Materials also recorded notable activity, rounding out a clear top tier across the sector.
Paper & Forest Products, Metals & Mining, and Steel & Iron Products formed a consistent mid-tier, while the remaining subsectors saw only isolated incidents.

The geographic distribution heatmap underscores the widespread impact of ransomware, highlighting the countries where victims in this industry have been recorded.

Materials victimology shows the USA being the most targeted, accounting for 31% of all victims. The remaining activity is distributed among 33 countries for 67 victims.
Spain and the UK recorded the highest elevations in the last 90 days.
The USA, Brazil, Switzerland, and Chile saw the largest declines.
In the last 90 days, 34 countries recorded material industry victims, 9 fewer than the 43 countries in the previous period.
Risk Level Indicator:

The Materials sector threat landscape is expected to remain at moderate through the next 90 days. The sector recorded a significant 29.2% decline in victims quarter-on-quarter, with monthly activity falling steadily from the December 2025 peak and showing no signs of recovery. This trajectory distinguishes Materials from most other sectors, where volume has either held steady or grown.
Volume outlook: The consistent downward trend from 64 victims in December to 27 in both June and July represents a genuine structural decline rather than a temporary dip. February and April showed minor upward interruptions but failed to reverse the overall direction. A baseline of 80 to 100 victims over the next 90 days is plausible, though the flattening at 27 victims per month in June and July may indicate the sector is approaching a floor rather than continuing to decline further.
Actor behaviour: 27 of 86 active gangs recorded materials victims, a 31% participation rate that is notably lower than sectors like Healthcare and Manufacturing. Thegentlemen and Qilin led by volume but with low sector share, indicating opportunistic rather than deliberate targeting. Lamashtu and Settra stand out as the groups with the highest proportional focus on materials targets, with roughly 1 in 6 of their victims from this sector, and are the most likely source of continued concentrated activity. LockBit5 and Settra drove a concentrated spike in June, demonstrating that single-group surges can temporarily inflate monthly figures without reflecting broader trend changes.
Geographic targeting: Geographic spread contracted sharply from 43 to 34 countries, the largest country-count reduction observed across any sector in the current reporting period. The USA remains dominant at 31% of victims but also recorded the largest absolute decline. Spain and the UK were the only notable gainers. The contraction in country coverage, combined with declining volume, suggests the sector is becoming less of a priority across the active actor set rather than simply shifting geographically.
Subsector risk: Raw Agricultural Products and Specialty Chemicals remain the highest-exposure subsectors, driven by the leverage ransomware creates in time-sensitive commodity supply chains. These subsectors are unlikely to lose their relative attractiveness even as overall sector volume declines.
APT Campaigns (Sustained): Materials featured in 10 of 57 observed campaigns (18%), up from 7 of 27 in absolute terms but down from a 26% share as overall APT activity more than doubled. Actor distribution is unusually balanced with no dominant country cluster, spanning China, Russia, North Korea, and Iran-linked groups. Leviathan and TICK jointly led campaign counts, with Leviathan’s known maritime and resource supply chain focus directly relevant to the sector. Southeast Asian representation is broader than in most sectors, spanning nine countries, including Myanmar, Cambodia, Brunei, and Laos. Database management software featured across three campaigns, pointing to commodity pricing and proprietary materials data as collection objectives.
Reported Cyber Incidents (Elevated): Only 3 incidents recorded across 90 days, all ransomware with no named attackers. A search of 695 report titles for mining, chemicals, steel, agriculture, cement, paper, packaging, and fertiliser terms found nothing beyond these three, confirming this reflects reporting coverage rather than actual exposure. Both identified incidents follow the same pattern: opportunistic ransomware halting physical production for weeks, at Australian sugar mills during harvest and a Latvian forestry company. FortiBleed is the quarter’s most consequential exposure, with credentials for 73,932 FortiGate devices leaked and subsequently linked to Inc and Lynx ransomware operations, a direct route into plant networks given where those appliances sit.
Underground & Dark Web Chatter (Elevated): Materials placed 9th of 14 industries. The defining feature is a V-shaped recovery in breach and leak discussion, declining sharply mid-period then returning close to initial levels. This distinguishes materials from sectors where decline aligned with forum disruption, suggesting the rebound reflects genuine renewed targeting rather than a visibility gap. Claimed hacks show the only uninterrupted upward trend across all three periods. DDoS and hacktivism peaked mid-period concurrently before falling away, a pattern consistent with a short geopolitically driven episode.
Vulnerabilities (Rebounding): Materials ranked 13th of 14 at 1.37% of industry-linked disclosures, the lowest volume in the report. RCE remains the dominant category despite low absolute numbers. The sharpest trend is denial of service, emerging from near zero to become the second-highest category in the final period, which carries disproportionate weight in a sector dependent on continuous production. Memory and buffer vulnerabilities show the only consistent upward trend across all periods, plausibly reflecting embedded and industrial software components.
Ransomware (Moderate): 97 victims, down 29.2% from 137, with share falling from 6.0% to 4.38%. Monthly activity has declined steadily from a December peak of 64, with February and April providing brief interruptions that failed to reverse direction. Raw Agricultural Products and Specialty Chemicals led victim counts, driven by the leverage ransomware creates in time-sensitive commodity supply chains. Gang participation was 31%, notably below other industrial sectors. Lamashtu and Settra stand out with roughly 1 in 6 of their victims from this sector. Geographic spread contracted from 43 to 34 countries, the largest country-count reduction observed across any sector this period.