Brian Sims
Editor

SonicWall data exposes factory floors as top target for cyber extortion

THE UK’s manufacturing sector appears to have become the nation’s primary battlefield for ransomware attacks. The latest threat intelligence data from SonicWall reveals that, while other key British industries have seen extortion attempts drop significantly, threat actors are aggressively targeting industrial facilities and critical operational technology environments with highly concentrated ransomware strikes.

According to SonicWall’s threat research team, monitoring recorded across 364 specialised sensors in UK manufacturing environments between January and May this year recorded 15.8 million Intrusion Prevention System events and 12.2 million malware threats.

On an annualised basis, intrusion attempts against UK factories are running roughly 28% higher than the 2025 full-year totals, duly signalling a rising tide of automated network probing aimed at British production lines.

The sector recorded 1.84 million ransomware events in just five months, establishing manufacturing as the single most ransomware-impacted industry in the UK. Almost the entirety of these attacks stem from the Filecoder ransomware family, with 1.79 million ‘hits’ focused squarely on just two specialised sensors.

SonicWall’s analysts note that this extreme concentration highlights active and dedicated campaigns aimed at bringing specific high-value manufacturing plants to a grinding halt, rather than broad and speculative scattergun activity that’s witnessed elsewhere.

Key intelligence

Apache Log4j exploitation generated 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, MES and ERP interfaces.

45% of monitored manufacturing sensors recorded attacks exploiting React Server Components, targeting newly digitised operational dashboards.

Unlike other UK verticals heavily targeted via smart physical surveillance, Internet of Things volume in manufacturing remained low (230,000 hits), proving that hackers favour application and legacy infrastructure flaw vectors.

Clear pattern

“Our data this year shows a clear pattern,” explained Spencer Starkey, executive vice-president for the EMEA region at SonicWall. “Silent reconnaissance against financial services, relentless stress-testing of healthcare and direct heavy-handed extortion against UK manufacturing. With 1.8 million ransomware hits heavily concentrated on individual facilities, the attackers clearly see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos.”

Starkey added: “UK manufacturers are navigating a toxic mix of old and new digital risk. Legacy Java sits unpatched in SCADA and MES systems due to the fact that plant managers cannot afford production downtime. Meanwhile, new digital frameworks are being scanned by attackers at speed. Manufacturers have to secure legacy operational technology without slowing modern operations.”

*Further information is available online at www.sonicwall.com

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up