Manufacturers face rising ransomware and supply chain attacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


UK manufacturers are facing growing cyber pressure as attackers target industrial systems and trusted supplier connections, according to research from SonicWall and e2e-assure.

SonicWall recorded 1.84 million ransomware events across 364 sensors in UK manufacturing environments between January and May 2026. The figure represents detected activity rather than successful breaches, but the concentration indicates sustained campaigns against some facilities. Annualised intrusion activity was running around 28% above the total recorded in 2025.

“With 1.8 million ransomware hits – heavily concentrated on individual facilities – attackers clearly see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos,” said Spencer Starkey, executive vice-president for EMEA at SonicWall. 

Separate e2e-assure research found that 76% of critical national infrastructure respondents had experienced repeated supply-chain compromise, while 75% reported repeated credential theft. More than 40% of surveyed organisations give at least six external suppliers remote access to operational technology. However, 39% only review or monitor that access after an incident.

“The easiest way into a critical environment is no longer breaking through the front door; it’s walking through a trusted supplier connection,” said Dominic Carroll, director of portfolio and marketing at e2e-assure.

The research also identified a widening security divide across industrial supply chains. While 68% of businesses employing between 5,000 and 10,000 people are increasing spending on third-party risk management, 32% of suppliers with 250 to 499 employees expect their investment to fall.

This could leave larger manufacturers exposed through smaller partners that have trusted access to operational systems but fewer resources to secure and monitor those connections.  The risk was demonstrated by the September 2025 cyberattack on Jaguar Land Rover, which forced the UK manufacturer to suspend production. Operations took several weeks to return to normal, disrupting vehicle output and the wider supply chain.

The findings point to a need for continuous monitoring of supplier connections, stronger credential controls and greater visibility across operational and IT environments.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW