Manufacturing Ransomware Case Studies: What OT/IT Segmentation Failures Actually Cost
Across the manufacturing ransomware incidents best documented since 2019 — Norsk Hydro, Honda, JBS Foods, the Applied Materials/MKS Instruments supply-chain hit, Clorox, and Nucor — the same structural gap shows up again and again: attackers got in through IT (phishing, a compromised VPN, a helpdesk social-engineering call, a supplier's network), and then moved into OT-adjacent systems largely because there was no meaningful segmentation boundary to stop them. Ransomware itself was rarely OT-native in these cases; the damage came from how far an IT-side compromise was allowed to travel. This article takes six of the most-cited cases and maps each one to the specific segmentation, monitoring, or asset-visibility control — drawn from the framework in our OT Cybersecurity 101 pillar — that would plausibly have contained or slowed it.
Quick Facts
| Question | Answer |
|---|---|
| Most-targeted sector by ransomware | Manufacturing — the most-attacked sector by ransomware for several consecutive years running, per Dragos and other industrial threat trackers (sources vary on the exact count, generally citing four to five years) |
| Root cause common to nearly every case below | A flat or weakly segmented IT/OT boundary that let an IT-side compromise reach OT-adjacent systems |
| Best-documented cost in this list | Norsk Hydro (LockerGoga, 2019) — estimated at $70-71 million depending on the source (Control Engineering, CyOTE/INL case study) |
| Most recent case covered | Nucor (May 2025) — production paused as a precaution; reportedly involved limited data exfiltration per Nucor's public disclosures at the time, the most recent and least-settled case in this list |
Why Manufacturing Keeps Topping the Ransomware Target List
Industry threat trackers have consistently ranked manufacturing as the most-attacked sector for ransomware for several consecutive years running — sources vary on the exact count, generally citing four to five years — and according to Dragos-based reporting cited by Industrial Cyber, manufacturing absorbed roughly 56% of the global ransomware attack surge in 2025 (1,466 incidents). Figures from other trackers such as ZeroFox and Deepstrike vary somewhat and are not blended into that composite figure here. The reasons attackers favor manufacturing are structural rather than incidental: production downtime creates direct, quantifiable revenue pressure that makes victims more likely to pay quickly, legacy OT equipment can't always be patched on a normal cadence, and — most relevant to this article — Dragos OT/ICS assessment data has reported finding no clean separation between IT and OT networks in roughly four out of five environments reviewed, per Dragos's own assessment findings rather than as a universal industry fact.
For readers building an internal case for segmentation or monitoring investment, that last point is the one worth anchoring a budget conversation around: the incidents below aren't really "ransomware problems" in isolation — they're segmentation-gap problems that ransomware happened to expose.
The Root Cause Behind Nearly Every Case: A Flat or Weak IT/OT Boundary
The OT Cybersecurity 101 pillar laid out a four-part baseline framework: asset inventory, network segmentation, monitoring (not just prevention), and incident response built for physical consequences. This article goes one level deeper into the segmentation and monitoring pieces, using the vocabulary a practitioner coming from an OT security background would actually use on a live architecture review:
- Zones and conduits — the Purdue Enterprise Reference Architecture model groups plant systems into numbered levels (from field devices and controllers at the lowest levels up through supervisory and business systems at the top), with "conduits" defining the specific, controlled paths allowed between them. A flat network is one where these levels talk to each other freely instead of only through defined, monitored conduits.
- The IT/OT DMZ — a buffer zone (commonly associated with Purdue Level 3.5) that sits between the business IT network and the industrial control network, so that no system on either side talks directly to a system on the other. Historical/data servers, jump hosts, and remote-access gateways live here instead of directly on the plant floor.
- Passive OT monitoring — reading network traffic off a mirrored span port or tap rather than actively scanning or polling OT devices, because many legacy controllers can crash or misbehave under the kind of active probing that's routine on an IT network.
- East-west visibility — most IT security tooling is built to watch traffic entering and leaving a network (north-south). OT environments need visibility into traffic moving laterally between machines and zones on the plant floor (east-west), because that's exactly the path ransomware uses once it's inside.
Every case study below gets mapped back to one or more of these specific controls.
Six Incidents, Mapped to the Segmentation Control That Would Have Helped
Norsk Hydro (2019) — LockerGoga
In March 2019, the Norwegian aluminum and renewable-energy company Norsk Hydro was hit by LockerGoga ransomware that spread across its IT systems, affecting operations reported to touch roughly 35,000 employees across around 40 countries. Hydro chose not to pay the ransom and instead ran a recovery effort estimated at $70-71 million depending on the source, per Control Engineering's retrospective coverage and the CyOTE/INL technical case study. Several plants were forced into manual or semi-manual operation while systems were rebuilt from clean backups.
Control that would plausibly have helped: A properly enforced IT/OT DMZ with defined conduits between business systems and plant-floor systems. Hydro's recovery approach — isolating and rebuilding rather than paying — is itself consistent with having (or building, under pressure) a clear zone boundary; the case is frequently cited in OT security training precisely because the company's transparent, methodical response showed what containment looks like once a boundary is in place, even though the initial spread illustrates what happens when IT-side compromise isn't stopped before it reaches production-adjacent systems.
Honda (2020) — EKANS/Snake
On June 8, 2020, Honda's global operations were disrupted by an EKANS (also known as Snake) ransomware attack. Per an Idaho National Laboratory (INL)/CyOTE technical case study, EKANS was used in a broader campaign against at least five critical infrastructure asset owners — including Honda and the Italian energy company Enel — across Europe, Asia, and South America between December 2019 and July 2020, and the malware itself was coded to specifically check for Honda's internal network name (mds.honda.com) before executing. Honda's networks in Japan, the US, and Europe were affected, and a Honda spokesperson confirmed to Forbes that production was affected "at some U.S. plants." EKANS has been widely discussed in security research as a strain designed with awareness of industrial-control-system environments, but this article does not assert specific technical capabilities beyond what the INL/CyOTE case study documents above — including any claim about an ICS-process-kill-list, which remains a separate, unconfirmed technical detail not addressed by that source.
Control that would plausibly have helped: Asset inventory combined with zone segmentation. Because EKANS is widely discussed as ransomware built with industrial-control-system awareness, the relevant defense isn't just "keep ransomware out" — it's knowing precisely which hosts on the network run ICS-related software (asset inventory) and ensuring those hosts sit behind a conduit boundary that a generic IT-originated ransomware infection can't reach without crossing a monitored chokepoint.
JBS Foods (2021) — REvil
In May 2021, JBS Foods — one of the world's largest meat processors — suffered a ransomware attack attributed to the REvil group that forced the shutdown of plants across the US, Canada, and Australia. JBS USA reportedly paid an $11 million ransom in Bitcoin, per Claroty's and other secondary coverage of the incident — company statements and court records were not independently reviewed for this article.
Control that would plausibly have helped: Conduit-level access control between corporate IT and plant-floor operational systems. JBS's decision to proactively shut down affected plants — rather than risk ransomware reaching production control systems — is itself a real-world (if costly) version of segmentation: cutting the conduit manually, after the fact, because no automated boundary existed to do it in advance.
Applied Materials / MKS Instruments (2023) — A Supply-Chain Hit, Not a Direct One
This case is worth stating precisely, because it's easy to blur: in February 2023, ransomware struck MKS Instruments, a supplier that provides critical subsystems to semiconductor equipment makers including Applied Materials. Applied Materials' own OT network was not directly breached. The incident happened inside MKS Instruments' systems. Applied Materials was affected downstream — through disrupted supply of components it depended on from MKS — and reported the disruption had a material negative financial impact in a single fiscal quarter, estimated at roughly $250 million, per The Record's reporting on the incident.
Control that would plausibly have helped: This is the one case in this list where internal IT/OT segmentation at the affected company wouldn't have prevented the impact, because the affected company (Applied Materials) wasn't the one breached. The relevant control is third-party and supply-chain risk visibility — treating a critical vendor's OT security posture as an extension of your own risk surface, not a boundary where your responsibility ends. Segmentation principles still apply, just one hop further out: know which suppliers' operational disruptions can stop your own production, the same way you'd map internal zones and conduits.
Clorox (2023) — When Social Engineering Bypasses Segmentation Entirely
In August 2023, Clorox disclosed a cyberattack initiated through social engineering — reported to involve impersonating an employee to a support helpdesk to gain initial access — that led to significant IT system disruptions. The company has reported it took roughly seven weeks to return to full production across all manufacturing sites, with hundreds of millions of dollars in lost sales, per The Record's coverage of the incident. Clorox subsequently filed a lawsuit against its IT services provider, Cognizant, on July 22, 2025 in Alameda County Superior Court, seeking $380 million in damages over alleged helpdesk failures during the attack, per CSO Online's reporting on the filing.
Control that would plausibly have helped: This case is a useful reminder that segmentation defends against lateral movement — it does not defend against a social-engineering compromise of credentials that are already trusted on both sides of a boundary. The relevant lesson maps to monitoring rather than segmentation alone: east-west visibility and anomaly detection on the OT side would still have value here, because even a socially-engineered IT compromise has to cross into OT-adjacent systems somehow before it can affect production — and a monitored conduit gives a chance to catch that crossing even when the initial access method bypassed traditional perimeter defenses entirely.
Nucor (2025) — Segmentation as the Reason a Shutdown Could Be Precautionary, Not Forced
In May 2025, US steelmaker Nucor disclosed a cybersecurity incident in which IT systems were compromised. Nucor proactively halted production at multiple sites as a precautionary measure while it investigated, and reportedly involved limited data exfiltration per Nucor's public disclosures at the time — this is the most recent and least-settled case in this list, and details may evolve as investigation continues.
Control that would plausibly have helped: This case illustrates the framework working in reverse from the others. A company that can confidently say "we paused production as a precaution while we confirmed our OT environment wasn't affected" is describing what a real IT/OT boundary and passive monitoring make possible: the ability to make that determination with evidence, rather than being forced into an uncontrolled, reactive shutdown because there's no visibility into whether the compromise has spread.
Incident Summary: Vector, Spread, and the Control That Would Plausibly Have Helped
| Incident (Year) | Initial Access | What It Disrupted | Segmentation/Monitoring Control Mapped |
|---|---|---|---|
| Norsk Hydro (2019) | LockerGoga ransomware on IT systems | Manual/semi-manual operation at multiple plants | IT/OT DMZ with defined conduits |
| Honda (2020) | EKANS/Snake ransomware | Multi-site production pause | Asset inventory + zone segmentation |
| JBS Foods (2021) | REvil ransomware | US/Canada/Australia plant shutdowns | Conduit-level access control, IT-to-plant-floor |
| Applied Materials / MKS (2023) | Ransomware at supplier MKS Instruments, not Applied Materials directly | Downstream supply disruption, reported quarterly financial impact | Third-party/supply-chain risk visibility |
| Clorox (2023) | Social engineering via support helpdesk | Multi-site production disruption, weeks-long recovery | East-west OT monitoring/anomaly detection |
| Nucor (2025) | IT systems compromised | Precautionary multi-site production pause | Segmentation + passive monitoring enabling confident scoping |
What This Means for Your Segmentation Roadmap
None of these six companies lacked a security budget or a security team. What each case has in common is that an IT-side compromise found a path — whether through a missing conduit boundary, an unmapped asset, or a trust relationship with a third party — into something that mattered for production. If you're building an internal case for OT segmentation or monitoring investment, the most defensible argument isn't an abstract "ransomware is rising" statistic — it's this pattern: the companies in this list that recovered fastest and with the clearest public communication (Norsk Hydro, and arguably Nucor) are the ones that could describe, in specific terms, where their IT/OT boundary was and what it did during the incident. The ones with the longest or most contested recoveries are the ones where that boundary either didn't exist or wasn't tested until the day it mattered.
FAQ
Q: Why is manufacturing the most targeted industry for ransomware?
A: Production downtime creates fast, quantifiable financial pressure that makes manufacturers more likely to pay quickly, legacy OT equipment often can't be patched on a normal IT cadence, and — per Dragos OT/ICS assessment data — roughly four out of five manufacturing environments reviewed have lacked clean IT/OT network separation, giving attackers an easier path from an IT-side compromise into systems that affect production. Sources vary on the exact consecutive-year ranking (generally cited as four to five years running).
Q: What is the OT/IT segmentation gap that shows up in ransomware attacks?
A: It's the absence of a defined, monitored boundary (commonly an IT/OT DMZ with specific allowed "conduits") between business IT systems and industrial control systems — without it, ransomware or an attacker that compromises IT credentials can move laterally into OT-adjacent systems even when the ransomware itself wasn't built to target industrial equipment.
Q: How much did the Norsk Hydro ransomware attack cost?
A: Recovery costs are commonly cited in the range of $70-71 million depending on the source (Control Engineering, CyOTE/INL case study), covering the manual/paper-based operations and system rebuild Norsk Hydro undertook after choosing not to pay the LockerGoga ransom in March 2019.
Q: Was Applied Materials directly hacked in the 2023 ransomware incident?
A: No — the ransomware attack was against MKS Instruments, a supplier to Applied Materials, not against Applied Materials' own network. Applied Materials was affected indirectly, through supply disruption, and reported a downstream financial impact in a subsequent quarter.
Q: How long did it take Clorox to recover from its 2023 cyberattack?
A: Clorox has reported it took roughly seven weeks to return to full production across all of its manufacturing sites, per The Record's coverage of the incident, following an August 2023 attack that began with social engineering against a support helpdesk.
Sources
- Industrial Cyber, "Manufacturing absorbs 56% ransomware surge of global attacks in 2025 as RaaS, legacy OT, supply chains fuel spike"
- Dragos, "Industrial Ransomware Analysis for Q2 2026"
- Control Engineering, "Throwback Attack: Norsk Hydro gets hit by LockerGoga ransomware"
- CyOTE/INL, Norsk Hydro Case Study (technical case study, Idaho National Laboratory)
- CyOTE/INL, "Case Study: EKANS Ransomware Attack on Honda" (INL/RPT-22-67338, Idaho National Laboratory)
- Forbes, Davey Winder, "Honda Hacked: Japanese Car Giant Confirms Cyber Attack On Global Operations" (June 10, 2020)
- Claroty, "JBS Attack Puts Food and Beverage Cybersecurity to the Test"
- The Record (Recorded Future News), "Applied Materials supply-chain MKS ransomware attack"
- The Record (Recorded Future News), "Clorox reports production issues after August cyberattack"
- CSO Online, "Clorox sues Cognizant for $380M over alleged helpdesk failures in cyberattack"
- Cybersecurity Dive, "Steelmaker Nucor restores operations, confirms limited data breach"
- Industrial Cyber, "Nucor reports cybersecurity incident, pauses operations, shuts down production sites temporarily"
Author Bio
The Whitepaper Skeptic has direct experience with OT cybersecurity in industrial and smart-factory environments, including customer-facing security architecture reviews covering network segmentation, asset inventory gaps, and legacy-equipment risk on live production networks — the same zone/conduit and DMZ vocabulary used to map each incident above to a specific control.
Related Posts
Tags
manufacturing ransomware, OT cybersecurity, IT/OT segmentation, ICS security, industrial security

Comments
Post a Comment