Jessica Entwistle
September 21 2026
Infosecurity Magazine reports that researchers at Huntress have identified a new ransomware variant named Settra, which has been deployed in recent attacks targeting retail and manufacturing organisations. The researchers highlighted the post-compromise techniques used in the attacks, which involved lateral movement, credential theft and data exfiltration before encryption. Retail and manufacturing sectors continue to be attractive targets for ransomware groups due to operational pressures, reliance on legacy systems, the business impact of downtime and the sensitivity of customer, supplier and operational data. The Huntress research noted that attackers spent time inside networks before deploying ransomware, using techniques such as privilege escalation, credential dumping and network reconnaissance to maximise the impact of the attack.
This matters operationally because retail and manufacturing organisations in the UK often operate with tight margins, complex supply chains and limited tolerance for disruption. Ransomware attacks in these sectors can halt production, disrupt logistics, compromise customer data and cause significant financial and reputational damage. The post-compromise techniques described in the Huntress research reflect the reality that ransomware is rarely the first stage of an attack. Attackers typically spend time inside networks, escalating privileges, stealing credentials and exfiltrating data before deploying encryption. This means that detection and response capabilities are critical. Organisations that can detect and respond to the early stages of an attack, such as unusual credential access, lateral movement or data exfiltration, have a much better chance of preventing ransomware deployment than those that only discover the attack when encryption begins. For UK businesses in retail and manufacturing, this reinforces the importance of network segmentation, privileged access controls, security monitoring and offline, tested backups.
For UK businesses in retail and manufacturing, this is a prompt to review whether backup and recovery processes are tested regularly, whether backups are stored offline or immutably to prevent attacker access, and whether incident response plans account for the operational impact of prolonged downtime in production or point-of-sale environments. Consider whether network segmentation limits lateral movement, whether privileged access is tightly controlled and monitored, and whether security monitoring can detect credential theft, unusual data movement or reconnaissance activity before ransomware is deployed. Review whether your organisation has visibility into how long it would take to restore critical systems from backup, whether recovery processes have been tested under realistic conditions, and whether business continuity plans account for the possibility of losing access to production systems, customer data or supply chain systems for an extended period. Consider whether your security awareness training includes guidance on recognising and reporting unusual system behaviour, and whether your organisation has a clear process for escalating potential security incidents quickly.
Source: Infosecurity Magazine