Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Manufacturing is currently the best-supported answer for the world’s most-targeted industry when the measure is investigated incidents. IBM X-Force reported that manufacturing represented 27.7% of the incidents it investigated in 2025, making it the leading sector for the fifth consecutive year. But there is no universal ranking: finance, healthcare, government, technology, retail, transport, utilities, and professional services can rank first under different measures, regions, and attack types.
The short answer
The answer depends on what “most targeted” means. A report may count investigated incidents, confirmed data breaches, ransomware victims, attempted attacks, affected organizations, DDoS events, or financial losses. Those measures are not interchangeable.
For global incident investigations, IBM X-Force’s 2026 Threat Intelligence Index found that manufacturing accounted for 27.7% of incidents it investigated during 2025. It described manufacturing as the top targeted sector for the fifth consecutive year.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesThat does not mean 27.7% of all cyberattacks worldwide hit manufacturers. IBM’s figure covers its own investigated cases, while other reports use different samples and definitions.
#1 Best Overall
Why there is no single global ranking
Before comparing industries, check five details in the source:
- Geography: Global, United States, European Union, United Kingdom, or another market.
- Observation base: Vendor-investigated cases, victim disclosures, ransomware leak-site listings, government surveys, or automated security telemetry.
- Time period: The report’s publication year may not match the incident year.
- Unit counted: Incidents, breaches, organizations, attack attempts, victims, or disclosed records.
- Attack type: Ransomware, phishing, fraud, espionage, DDoS, vulnerability exploitation, or data theft.
Reporting also creates bias. Sectors with stronger disclosure obligations may appear more affected. Automated telemetry can overrepresent internet-facing systems. One supply-chain campaign may affect many organizations or appear in multiple databases. A sector with fewer recorded incidents may simply detect or disclose fewer attacks.
Industries attackers target most
1. Manufacturing
Manufacturers combine valuable intellectual property with systems that can be difficult to secure. Plants often depend on legacy technology, industrial control systems, remote maintenance, contractors, suppliers, and connections between corporate IT and operational technology.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDowntime creates immediate pressure: a locked production environment can interrupt orders, contracts, and supply chains. Attackers may also steal designs, formulas, production data, or engineering information.
In Verizon’s 2026 Data Breach Investigations Report, the manufacturing dataset contained 3,627 incidents, including 2,713 with confirmed data disclosure. Ransomware appeared in 61% of manufacturing breaches, while malware appeared in 75%. Vulnerability exploitation was the leading initial-access vector at 38%, followed by phishing at 13% and credential abuse at 11%.
Verizon also identified system intrusion, social engineering, and basic web application attacks as the three patterns accounting for 91% of manufacturing breaches in its dataset. IBM and Verizon should not be combined into one league table: their samples and methods differ.
2. Finance and insurance
Financial institutions are attractive because they control money, payment systems, account credentials, transaction data, credit information, and valuable identities. Attackers pursue fraud, business-email compromise, credential theft, ransomware, data extortion, and DDoS attacks.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Finance is also deeply interconnected with banks, payment processors, fintech companies, brokers, insurers, and technology vendors. A weakness in one provider can create access to many customers.
ENISA identifies finance as a critical and highly targeted European sector. IBM reported that finance and insurance represented 39% of X-Force-investigated incidents in Europe during 2025, followed by professional, business and consumer services at 18% and retail at 13%.
Finance does not lead every global incident-volume measure, but it remains one of the most consistently targeted sectors and one of the most financially consequential.
3. Healthcare and pharmaceuticals
Healthcare organizations hold sensitive medical, insurance, identity, and payment information. Hospitals and clinics also have limited tolerance for prolonged downtime because care may depend on electronic health records, imaging, medication systems, scheduling, and billing platforms.
Medical devices and clinical systems can be difficult to patch or replace. Healthcare attacks commonly involve ransomware, data theft, phishing, stolen credentials, exposed internet-facing systems, and compromise through electronic-record, billing, imaging, or managed-service providers.
“Healthcare” is not one uniform risk category. Hospitals, insurers, pharmaceutical companies, laboratories, clinics, and medical-device manufacturers have different assets, regulations, and attack paths. Verizon’s 2026 DBIR materials identify healthcare as a major industry-specific risk area, but its healthcare chapter should be used for exact sector figures rather than general totals.
4. Government and public administration
Government agencies offer political, strategic, and intelligence value. They hold citizen, diplomatic, law-enforcement, defense, and public-service information, while their public-facing websites and large user populations create many opportunities for attackers.
Rank #3
In the European Union, ENISA’s 2025 threat landscape placed public administration first, representing 38.2% of reported incidents. Transport followed at 7.5%, digital infrastructure and services at 4.8%, finance at 4.5%, and manufacturing at 2.9%.
ENISA analyzed 4,875 incidents from July 1, 2024, through June 30, 2025. Its public-administration result is therefore an EU incident-distribution figure, not proof that government is the most-targeted industry globally.
5. Technology, communications, and digital infrastructure
Technology providers, cloud companies, hosting firms, telecommunications operators, software companies, and identity providers can offer attackers concentrated leverage over many downstream customers.
Internet-facing infrastructure is continuously scanned. A single unpatched product, compromised administrator account, stolen cloud secret, or software-supply-chain weakness can expose multiple organizations.
In the UK government’s 2025–2026 Cyber Security Breaches Survey, 63% of information and communications businesses said they had identified a breach or attack in the previous 12 months—the highest rate among the sectors surveyed. That measures the percentage of surveyed organizations reporting an identified event, not the total number of attacks.
6. Professional, scientific, technical, and business services
Law firms, accountants, consultants, engineering companies, IT providers, and managed-service providers often hold sensitive client information or privileged access to customer systems. They can be valuable targets directly or stepping stones into larger organizations.
Smaller service firms may have fewer security staff and less monitoring than the clients they serve. The UK survey recorded a 54% identified breach-or-attack rate for professional, scientific, and technical businesses.
Rank #4
7. Retail and hospitality
Retailers and hospitality companies process payments and customer identities across many stores, websites, point-of-sale terminals, loyalty programs, booking systems, delivery platforms, and third-party services.
Large or seasonal workforces can increase phishing, credential-stuffing, and account-takeover opportunities. Retail often attracts financially motivated fraud and web-application attacks, although ransomware and supply-chain compromise also matter.
The UK survey reported a 31% identified breach-or-attack rate for retail and wholesale businesses. That lower figure should not be treated as a global measure of low risk because reporting practices and attack types vary.
8. Transport and logistics
Airlines, shipping companies, rail operators, ports, couriers, and logistics providers depend on booking, cargo, fleet, warehouse, supplier, and operational systems. Disruption can quickly affect customers, trade, and public services.
Transport ranked second in ENISA’s EU 2025 incident dataset at 7.5%. The sector can face ransomware, DDoS, supply-chain compromise, and state-linked attacks intended to create strategic disruption.
9. Energy, utilities, and other critical infrastructure
Utilities and energy companies are targeted because disruption can affect essential services and public safety. Operational technology may be specialized, old, difficult to patch, or connected to remote-access systems and vendors.
Recommended Free Tools
Threats include ransomware, vulnerability exploitation, espionage, and attacks against industrial control environments. Energy, transport, digital infrastructure, finance, and public administration should be analyzed separately rather than treated as one identical “critical infrastructure” category.
Best Value
How attack types change the ranking
| Attack type | Industries often exposed | Why attackers choose them |
|---|---|---|
| Ransomware | Manufacturing, healthcare, professional services, retail, government | Downtime and sensitive data create pressure to pay or negotiate. |
| Data theft | Finance, healthcare, government, law, technology | Personal, financial, medical, client, and intellectual-property data can be monetized or used for espionage. |
| Phishing and credential attacks | Every sector, especially finance and professional services | Stolen identities can bypass perimeter defenses and enable fraud or lateral movement. |
| DDoS | Finance, professional services, manufacturing, government | Public visibility, disruption, extortion, or political impact. |
| Supply-chain compromise | Technology, manufacturing, healthcare, logistics | A vendor or provider may connect to many valuable organizations. |
| OT and industrial attacks | Manufacturing, utilities, energy, transport | Operational disruption can have physical and economic consequences. |
| State-sponsored espionage | Government, defense, technology, research, energy, telecommunications | Strategic information and long-term access may matter more than immediate profit. |
Verizon’s DDoS data shows why rankings vary: finance, professional services, and manufacturing were recurring leading target industries rather than one sector dominating every category.
Why attackers choose particular industries
- Money: Finance, retail, healthcare, and business services hold assets that can be converted directly into cash.
- Operational leverage: Factories, hospitals, transport operators, and utilities cannot easily tolerate downtime.
- Concentrated access: Technology providers and managed-service firms may provide a route into many customers.
- Sensitive information: Medical, financial, government, legal, research, and customer data support extortion, fraud, or espionage.
- Large attack surfaces: Multiple locations, users, devices, applications, contractors, and legacy systems create more opportunities.
- Weak links: Attackers commonly exploit unpatched internet-facing systems, stolen credentials, phishing, remote-access tools, suppliers, or third parties.
What highly targeted organizations should prioritize
- Maintain an accurate asset inventory. Include cloud workloads, internet-facing applications, remote-access tools, endpoints, operational technology, clinical devices, payment systems, and vendor connections.
- Protect identities. Require multifactor authentication, especially phishing-resistant MFA for administrators and other privileged users. Remove stale accounts and limit privileges.
- Patch and prioritize vulnerabilities. Focus first on exposed systems, actively exploited vulnerabilities, and assets that provide a path to critical operations.
- Segment critical environments. Separate corporate IT from OT, clinical, payment, production, and administrative networks. Control and monitor remote vendor access.
- Build recoverable backups. Keep offline or immutable copies, protect backup administration, and test restoration rather than assuming backups work.
- Improve email and endpoint defenses. Combine filtering, device protection, identity monitoring, and technical controls with staff training.
- Control third parties. Review supplier access, security requirements, authentication, logging, breach notification, and offboarding.
- Practice incident response. Define who isolates systems, contacts providers, communicates with customers, preserves evidence, and handles regulatory reporting.
- Centralize useful logs and detection. Alerts are valuable only when someone can investigate and contain them quickly.
These are general priorities, not substitutes for a sector-specific framework or professional security assessment. A manufacturing plant, hospital, bank, and cloud provider need different controls and recovery plans.
How to judge a “most-targeted industries” claim
Use this checklist before relying on a ranking:
- What country or region does it cover?
- What exact dates does it measure?
- Does it count incidents, breaches, victims, attempts, or organizations?
- Who collected the data and how were cases observed?
- Are industry categories defined consistently?
- Could disclosure, monitoring, or reporting practices skew the result?
- Are attack types mixed together?
- Are organization sizes comparable?
- Could duplicate records or one campaign inflate the count?
For example, Verizon’s 2026 DBIR analyzes incidents from November 1, 2024, through October 31, 2025, despite being published in 2026. Treating its figures as “all attacks in 2026” would be incorrect.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What the rankings mean for individuals and small businesses
Industry statistics are useful for risk awareness, but they do not predict whether a particular company or household will be attacked. Criminals often choose the easiest profitable target, regardless of sector. A small accounting firm, clinic, online retailer, contractor, or manufacturer may be attractive because it has valuable access but limited security resources.
The practical question is not only “Which industry is attacked most?” It is also:
- Which systems would cause the greatest financial or operational harm if unavailable?
- Which accounts or vendors can reach those systems?
- Where are internet-facing vulnerabilities and reused passwords?
- Can the organization detect and contain a stolen identity?
- Can it restore essential operations without paying an attacker?
For consumers, the same sector trends explain why financial accounts, healthcare portals, retail accounts, and email identities deserve strong, unique passwords, multifactor authentication, prompt software updates, and careful scrutiny of unexpected payment or password-reset requests.
Bottom line
Manufacturing is the strongest current answer for the most-targeted industry globally when measured by IBM X-Force’s investigated incidents: 27.7% in 2025 and the leading sector for five consecutive years. But finance, healthcare, public administration, technology, professional services, retail, transport, and utilities may lead under different measures or in different regions. The reliable way to interpret any ranking is to identify its geography, dates, dataset, industry definitions, attack type, and unit of measurement before drawing conclusions about risk.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

