Manufacturing Cyber Threats Shift to Identity-Driven Attacks, Doppel Reports - Wiss Manufacturing Cyber Threats Shift to Identity-Driven Attacks

Manufacturing Cyber Threats Shift to Identity-Driven Attacks, Doppel Reports

July 21, 2026


read-banner

Manufacturing Cyber Threats Shift to Identity-Driven Attacks, Doppel Reports

New research from cybersecurity firm Doppel identifies manufacturing as one of the most heavily targeted sectors for cyberattacks, with threat actors shifting away from direct infrastructure compromise toward identity-driven attacks that exploit human workflows, supplier trust, and credential exposure.

The report found that manufacturing and engineering organizations face the highest vishing vulnerability rate of any industry, making phone-based social engineering a growing attack surface alongside more traditional phishing vectors.

Credential Leaks Have Become the Dominant Threat Vector

Doppel’s analysis found that credential leak activity dominated threat data in four of the five months covered in the study period, representing the most consistent finding across the dataset. The firm observed a particularly sharp spike during the week of April 13, resulting in a 47-fold increase in dark web alerts over the prior week. Doppel attributed the spike to a high-volume credential dump or concentrated dark web release, noting that even a single-week event can rapidly concentrate manufacturing sector exposure.

Leaked credentials create several specific risk paths for manufacturers, according to the report, including unauthorized access to supplier and customer portals, VPN and remote access systems, business email compromise enabling invoice redirection, abuse of contractor and logistics partner accounts, and downstream targeting of operational support systems.

Attack Chains Are Multi-Channel and Supply Chain-Focused

Rather than attacking core systems directly, the report describes threat actors increasingly compromising trusted communication channels to impersonate suppliers, logistics partners, and vendors. These tactics enable attackers to reroute shipments, alter invoices, or extend compromise across vendor networks without ever directly penetrating operational technology systems.

Doppel identified a likely attack sequence: exposure of credentials on the dark web, validation of those credentials against business portals and remote access services, deployment of spoofed infrastructure or fraudulent social profiles to impersonate trusted parties, and monetization through payment fraud, data theft, or resale of unauthorized access.

Third-Party Breach Exposure Amplifies the Risk

Doppel’s findings align with data from Black Kite, which reported that 136 major third-party breaches in 2025 affected 719 named companies and an estimated 26,000 additional downstream victims that were never publicly identified. The average third-party breach affected 5.28 downstream victims, the highest figure Black Kite has recorded.

Black Kite separately reported that 62% of the most critical vendors had corporate credentials appearing in stealer logs, making identity exposure a material indicator of supply chain risk. For manufacturers whose operations depend on interconnected suppliers, distributors, contract manufacturers, and field-service providers, a single compromised vendor can expose multiple downstream organizations.

Recommended Defensive Priorities

The Doppel report identifies several defensive actions manufacturers should prioritize. These include continuous monitoring for leaked employee, vendor, and partner credentials; accelerated password resets for VPN, SSO, email, and supplier portal access; multifactor authentication for high-risk access paths; and formal verification processes for supplier payment changes and procurement requests.

The report also flags recurring abuse of legitimate hosting platforms, including GitBook, Webflow, Blogspot, Netlify, and Cloudflare Pages as channels for hosted phishing infrastructure, and identifies Facebook as a consistent secondary channel for manufacturing-related social engineering campaigns.

Doppel’s conclusion frames the risk as no longer primarily domain-led. According to the report, current threat activity in the manufacturing sector is identity-led and ecosystem-driven, requiring defenders to connect credential exposure, dark web signals, social impersonation, and supplier risk into a single external threat view rather than treating each as a separate problem.


Questions?

Reach out to a Wiss team member for more information or assistance.

Contact Us

Share

    LinkedInFacebookTwitter