Security researchers at Huntress reported on 21 September that a new wave of the Settra ransomware variant is being deployed against UK retail and manufacturing organisations. It’s the same group that claimed a Leeds PR agency as a victim back in August, but this campaign is different: it’s targeting the sectors directly, moving through networks with a specific, repeatable playbook of lateral movement, credential theft and data exfiltration, all happening before a single file gets encrypted.

That detail matters more than it might sound. Most SME cyber planning still centres on “what if we get encrypted and can’t access our files.” Good backups fix that problem. But if attackers are already inside your network stealing customer records, supplier contracts and financial data days before they trigger the encryption that finally gets noticed, backups solve only half the problem. The other half, the leaked or sold data, doesn’t come back no matter how good your restore process is.

Why retail and manufacturing specifically

Both sectors carry a particular kind of exposure. Retail businesses run point-of-sale systems, loyalty databases and supplier integrations that often sit on older infrastructure, patched less often than head-office IT because nobody wants to risk downtime on the tills during trading hours. Manufacturing firms increasingly connect operational technology, the systems that actually run machinery, to the same network as office computers and email, which means a phishing click in accounts can end up a hop away from the shop floor. Attackers know this. Huntress’s research specifically flagged credential theft as a first-stage technique, meaning a single compromised login in either sector can be the entry point for everything that follows.

What to check this week

You don’t need a security team to close the obvious gaps. Three things are worth doing now:

  • Segment what you can. If your till systems, warehouse equipment or production line controls sit on the same network as staff laptops and email, ask whether they need to. Even basic network segmentation slows lateral movement enough to matter.
  • Turn on alerting for unusual data movement, not just malware. Exfiltration before encryption often looks like a large, unusual transfer to an external location. Many modern endpoint tools flag this as standard, but only if they’re switched on and someone is watching the alerts, which is exactly the kind of gap continuous monitoring services like KeepSafe exist to close for businesses without an in-house security team.
  • Rotate and review credentials, especially any shared logins for suppliers, POS vendors or remote access tools. Credential theft only works if the stolen credential still works.

The takeaway

A ransom note is the last stage of an attack that’s often been running for days. If your business fits the retail or manufacturing profile Huntress is describing, the useful question this week isn’t “do we have backups” but “would we know if someone was already inside, quietly copying files, right now.” If the honest answer is no, that’s the gap to close first.