Cyber attacks on manufacturers rise 51% as criminals and other threat actors turn to AI, cloud systems and voice phishing to gain access to confidential information.  

Voice Phishing (Vishing) attacks against manufacturers and other organisations by cyber criminals are rising rapidly around the world, according to a leading cybersecurity provider.  

US-based cybersecurity company CrowdStrike says that the number of criminals and other threat actors using their own human voices to deceive targets has already eclipsed in 2025 the total number of recorded attacks in 2024. 

“Voice phishing (vishing) attacks increased by 442% from the first to the second half of 2024, marking a significant and effective evolution in eCrime tactics,” the report says.  

“These attacks are successful because they exploit human vulnerabilities and leverage compromised credentials and social engineering to bypass traditional security measures, gain initial access and move laterally within organisations at speed.” 

CrowdStrike head of counter adversary operations Adam Meyers said these attacks often take place through a voice call to a company help desk. 

“Typically, the call is pretending to be a user, they will do it out of hours to limit the possibility the user is online or something gets detected,” he said.  

The caller will frequently pretend to have forgotten their access password and will have some information about their location and manager in order to circumvent the company’s verification procedures, Meyers said.  

“I have listened to hundreds of hours of these calls… in some cases the helpdesk says ‘That’s not who I have here,’ and the threat actor starts back pedalling… and you can hear them typing in the background, and they’re going through their data or searching through the information they can find online. 

“You can hear the relief in the threat actor’s voice and the helpdesk’s voice when they figure out the right answer so they can both move on with their day.” 

Meyers said that while cyber-criminals had changed their techniques in recent years, “the goal is still the same, to deploy as much ransomware as possible to disrupt the operations of the target, bring them to their knees and then force them to pay an extortion demand to get their files back.” 

Cyber criminals were also acting more quickly, Meyers said, with some criminal organisations now able to deploy ransomware within 24 hours of first gaining access to company systems – eschewing malware as it was typically more easily detected. 

Cyber-attacks were up 27% year-on-year in 2025, with 73% of all reports made in 2024-25 associated with eCrime activity.  

While manufacturing was the third-most targeted sector, behind technology and consulting and professional services, attacks against manufacturers were up 51% in the 2024-25 financial year when compared to the year prior, a rise CrowdStrike said was “a notable increase”. 

“Manufacturing and retail entities remain high-value targets for eCrime intrusions because these entities’ operating nature incentivises them to pay ransoms quickly,” the report said. 

“Manufacturers cannot afford production delays, and retailers risk losing customer data and sales, especially during busy shopping seasons. These industries typically have larger budgets and complex computer systems that can be outdated, which also makes them attractive targets.”  

For other types of threat actors, those connected to foreign governments or to political activists or terror organisations, the goal was much more insidious – to commit espionage, sabotage or other destructive attacks.  

One entity associated with North Korea had been able to infiltrate more than 320 companies by getting their operatives hired as remote software developers, using AI to assist in the creation of CVs and conducting deepfake interviews under false identities. 

While some lower-tier criminal and civil actors had used AI to generate scripts and build malware, other groups were using AI agents to gain unauthenticated access, harvest credentials and deploy both malware and ransomware.  

Attacks on the Cloud rose 136% over the 2024-25 financial year, CrowdStrike said, with China-linked adversaries responsible for 40% of the increased activity. 

Meyers said the group was now seeing threat actors use AI to work faster and lower the barrier for entry.  

“At the same time, adversaries are targeting the very AI systems organizations are deploying. Every AI agent is a superhuman identity: autonomous, fast, and deeply integrated, making them high-value targets,” he said.  

“Adversaries are treating these agents like infrastructure, attacking them the same way they target SaaS platforms, cloud consoles, and privileged accounts. Securing the AI that powers business is where the cyber battleground is evolving.”