SOFIAH NICHOLE SALIVIO
News Editor
UK manufacturing was the country’s most targeted sector for ransomware attacks, according to SonicWall. The cyber security company recorded 1.84 million ransomware events in factories in the first five months of the year.
Data gathered by SonicWall’s Threat Research team from 364 sensors in UK manufacturing environments also showed 15.8 million Intrusion Prevention System events and 12.2 million malware threats between January and May. Intrusion attempts against factories were running about 28% above full-year 2025 levels on an annualised basis.
The figures point to a sharp concentration of attacks on industrial sites rather than a broad spread across the sector. Of the ransomware hits, 1.79 million came from the Filecoder family and were focused on just two specialised sensors.
That pattern suggests attackers are concentrating on a small number of higher-value facilities where disruption could halt production. SonicWall contrasted this with the broader, less focused attack patterns seen in other industries.
Legacy exposure
Apache Log4j exploitation generated 1.1 million hits across 34% of monitored manufacturing sensors, exposing unpatched SCADA, Manufacturing Execution Systems and Enterprise Resource Planning interfaces used in industrial operations.
SonicWall also found that 45% of monitored sensors recorded attacks exploiting React Server Components remote code execution issues. According to the data, those attempts targeted more recently digitised operational dashboards.
Internet of Things attack volume in manufacturing was far lower by comparison, with 230,000 hits across the monitored environments. This suggests attackers are favouring application weaknesses and older infrastructure over connected surveillance and other smart physical systems.
The findings highlight the pressure on manufacturers as they run older operational technology alongside newer web-based tools. Many industrial businesses have modernised parts of their systems while continuing to rely on long-standing software in plant environments, where outages can interrupt output.
Ransomware remains a persistent threat to manufacturers because production stoppages can quickly affect revenue, customer deliveries and supply chains. A successful attack on a factory can also create wider knock-on effects if it disrupts suppliers linked to automotive, aerospace, food and other sectors.
Targeted campaigns
The distribution of events across a small number of sensors suggests dedicated campaigns rather than speculative scanning. SonicWall’s data indicates attackers are not simply casting a wide net, but concentrating their efforts where disruption might offer the greatest leverage.
A brief breakdown from the company also pointed to differences in how industries are being targeted. Manufacturing is facing direct extortion attempts, while other sectors are seeing different forms of network probing and pressure.
Spencer Starkey, Executive Vice-President, EMEA, at SonicWall, said: “Our data this year shows a clear pattern: silent reconnaissance against financial services, relentless stress-testing of healthcare, and direct, heavy-handed extortion against UK manufacturing.
“With 1.8 million ransomware hits, heavily concentrated on individual facilities, attackers clearly see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos.
“UK manufacturers are navigating a toxic mix of old and new digital risk. Legacy Java sits unpatched in SCADA and MES systems because plant managers can’t afford production downtime. Meanwhile, new digital frameworks are being scanned by attackers at speed. Manufacturers have got to secure legacy OT without slowing modern operations.”
Click Here For The Original Source.
