Intel 471 reports rising extortion attacks targeting supply-chain weaknesses

THE BRIEF
Cybersecurity Dive reports that extortion attacks are rising as hackers prioritize supply-chain weaknesses, citing findings from Intel 471. The report says consulting firms and manufacturing companies accounted for many of the ransomware victims posted to the dark web in 2025. The supplied account does not identify the affected organizations, describe the incidents, or quantify the overall increase. It does, however, point to a pattern in which attackers’ focus on suppliers and other connected businesses is being reflected in public ransomware victim postings. For organizations that rely on external providers, the report is a reminder that supply-chain exposure can shape ransomware risk beyond an individual company’s own systems. The findings are attributed to Intel 471 as reported by Cybersecurity Dive and should be treated as a reported trend rather than a complete measure of extortion activity. Security teams can use the signal to revisit third-party risk assumptions, particularly across consulting and manufacturing relationships, without inferring additional scope from the available information.
WHY IT MATTERS
The reported pattern matters because ransomware exposure may extend through suppliers, contractors, and other connected organizations. Consulting and manufacturing companies appeared frequently among the victims posted to the dark web in 2025, according to Intel 471. That does not establish the scale or details of any individual incident, but it highlights a risk area for organizations whose operations depend on outside providers. Reviewing supply-chain dependencies can help security leaders assess where ransomware-related disruption or extortion concerns may emerge.
WHO SHOULD CARE
Security leaders, third-party risk teams, procurement groups, and executives at consulting, manufacturing, and other organizations that depend on external suppliers should review the reported trend and reassess supply-chain exposure.
WHAT TO DO NOW
- Review critical suppliers and service providers for ransomware and extortion exposure.
- Update third-party risk assessments to account for supply-chain weaknesses and connected dependencies.
- Confirm that supplier security requirements address ransomware preparedness and incident communication.
- Brief leadership on the reported trend without treating public victim postings as a complete measure of activity.