You’ve invested millions in equipment that turn rolls and sheets into cash. You track uptime religiously. But there’s a threat growing faster than any equipment failure, and most packaging plants aren’t prepared for it.

Manufacturing is the most targeted industry for ransomware attacks on the planet.

In 2025, attacks on manufacturing facilities surged 56%, jumping from 937 incidents to 1,466. Manufacturing absorbed more than half of all ransomware hits across every industrial sector. When attackers got in, the average ransom demand hit $1.16 million, more than double the prior year’s figure.

These aren’t Fortune 500 stats. Independent corrugated folding carton plants are in the crosshairs, and they’re getting hit.

Why Packaging Plants Are Uniquely Exposed

Here’s the problem most owner-operators don’t want to talk about: the same infrastructure decisions that once saved money are now creating dangerous vulnerability.

On-premise ERP and MES systems, the kind that were installed on servers in your IT closet 10 years ago, were not developed by software engineers who had time machines into the present world of AI-accelerated ransomware. Eighty percent of manufacturing firms still carry critical vulnerabilities in legacy systems. Roughly one-quarter of all documented losses in the sector trace back to a single preventable failure: misconfigured or missing multi-factor authentication.

In a corrugated or folding carton environment, the OT/IT convergence problem is especially acute. You want your software to talk with your hardware. Your production planning data feeds your finishing lines. Your estimating tools connect to customer order portals. That integration, the thing that makes modern plant operations efficient, is also the attack surface that ransomware actors are exploiting right now.

When a plant goes down from a cyberattack, it doesn’t look like a machine breakdown. It looks like paralysis. Schedules freeze. Shipments miss. Customers call. And if your data is held hostage or your system is corrupted, recovery can take weeks.

What Forward-Looking Operators Are Doing

The corrugated and folding carton plants moving fastest on this aren’t necessarily the largest. They’re the ones that have made a strategic shift: from on-premise legacy software to cloud platforms.

Cloud-based ERP and MES platforms deliver what legacy systems structurally cannot: security designed and maintained by people whose idea of OEE is 99.9%+ system uptime and 100% failsafe data redundancy..

Cloud-native doesn’t mean generic. The most effective platforms are purpose-built for packaging, connecting estimating, order management, production planning, and plant-floor execution in environments that are seamlessly connected for end-users and properly secured against external threat actors.

What to Do This Week

The $1.16 million average ransom demand doesn’t factor in downtime, customer attrition, or remediation costs. For most independent packaging operations, a single successful ransomware attack is an existential event.

Two actions worth taking before next Monday:

  1. Audit your MFA coverage today. Pull up every system your team accesses, ERP, scheduling, order portal, plant floor terminals. If any of them don’t require MFA, that’s your most urgent gap to close. One-quarter of manufacturing ransomware losses trace to this single issue.
  2. Ask your ERP and MES provider a direct question: What are your disaster recovery procedures and how quickly can you get us back up running if our plant is hit with a cyberattack? Treat this with as much urgency as you would unplanned downtime due to a critical machine failure because the impact to your ability to produce is the same.

Amtech’s solutions are purpose-built for corrugated and folding carton operations, connecting every touchpoint from estimate to shipment and up-to-date on the operational and security demands packaging plants face today. If you’re still running on an aging on-premise system, now is the right time to have that conversation.