SonicWall data exposes factory floors as top target for cyber extortion

SonicWall data exposes factory floors as top target for cyber extortion

The UK manufacturing sector has become the nation’s primary battlefield for ransomware attacks. Threat intelligence data from SonicWall reveals that while other key British industries have seen extortion attempts drop significantly, threat actors are aggressively targeting industrial facilities and critical operational technology (OT) environments with highly concentrated ransomware strikes.

According to SonicWall’s Threat Research team, monitoring across 364 specialised sensors in UK manufacturing environments between January and May 2026 recorded 15.8 million Intrusion Prevention System (IPS) events and 12.2 million malware threats.

Ransomware remains stubbornly high

On an annualised basis, intrusion attempts against UK factories are running roughly 28% higher than 2025 full-year totals, signalling a rising tide of automated network probing aimed at British production lines.

The sector recorded 1.84 million ransomware events in just five months, establishing manufacturing as the single most ransomware-impacted industry in the United Kingdom. Almost the entirety of these attacks stem from the Filecoder ransomware family, with 1.79 million hits focused on just two specialised sensors.

SonicWall analysts note that this extreme concentration highlights active, dedicated campaigns aimed at bringing specific high-value manufacturing plants to a grinding halt, rather than the broad, speculative scattergun activity seen elsewhere.

More key intelligence:

  • Apache Log4j exploitation generated 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, MES and ERP interfaces.
  • Forty-five percent of monitored manufacturing sensors recorded attacks exploiting React Server Components (RCE), targeting newly digitised operational dashboards.
  • Unlike other UK verticals heavily targeted via smart physical surveillance, IoT volume in manufacturing remained low (230K hits), proving hackers favour application and legacy infrastructure flaw-vectors.

“Our data this year shows a clear pattern: silent reconnaissance against financial services, relentless stress-testing of healthcare and direct, heavy-handed extortion against UK manufacturing,” said Spencer Starkey, Executive Vice President, EMEA, SonicWall. “With 1.8 million ransomware hits – heavily concentrated on individual facilities – attackers clearly see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos.

“UK manufacturers are navigating a toxic mix of old and new digital risk,” Starkey continued. “Legacy Java sits unpatched in SCADA and MES systems because plant managers can’t afford production downtime. Meanwhile, new digital frameworks are being scanned by attackers at speed. Manufacturers have got to secure legacy OT without slowing modern operations.”

Browse our latest issue

Intelligent CISO

View Magazine Archive