UK manufacturing hit by ransomware surge, SonicWall says
Fri, 31st Jul 2026 (Today)
UK manufacturing has become the country's most targeted sector for ransomware attacks, according to SonicWall. The company recorded 1.84 million ransomware events on British industrial facilities between January and May.
The figures came from 364 specialised sensors in UK manufacturing environments monitored by SonicWall's Threat Research team. During the same period, the sensors also logged 15.8 million intrusion prevention system events and 12.2 million malware threats.
The data points to a sharp divergence between manufacturing and other parts of the British economy. Extortion attempts have fallen significantly in other key sectors, while attacks on industrial sites and operational technology environments have remained concentrated.
On an annualised basis, intrusion attempts against UK factories are running about 28% above full-year 2025 totals, SonicWall said, suggesting a sustained rise in automated network probing of production systems.
Most of the ransomware activity detected in manufacturing was linked to a single malware family. Of the 1.84 million ransomware hits, 1.79 million came from Filecoder, with almost all of those attempts concentrated on two specialised sensors.
That concentration suggests attackers may be focusing on a small number of sites rather than casting a wide net across the sector. The pattern contrasts with the broader, less targeted activity often seen in other industries.
Attack routes
The research also identified widely used software weaknesses in industrial settings. Exploitation linked to Apache Log4j generated 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, manufacturing execution system and enterprise resource planning interfaces, according to SonicWall.
Another 45% of monitored manufacturing sensors recorded attacks exploiting React Server Components remote code execution, aimed at newer digital dashboards used in operations. The finding highlights risks created as factories add web-based tools alongside older control systems.
Internet of Things attack traffic was lower than in some other sectors. SonicWall recorded 230,000 IoT-related hits in manufacturing and said attackers appeared to favour application vulnerabilities and legacy infrastructure flaws over connected surveillance devices and similar equipment.
The figures add to concerns over cyber risk in industrial environments, where disruption can halt output and affect suppliers. Manufacturing groups face growing pressure to modernise plants while keeping existing operational systems running, a balance that can leave older software exposed for longer than in conventional office IT.
Industrial operators often rely on SCADA and MES environments that are tightly linked to physical processes on the factory floor. Patching or replacing these systems can require planned shutdowns, making routine software maintenance more difficult and extending the life of known vulnerabilities.
At the same time, manufacturers have added customer portals, operational dashboards and other internet-facing tools to improve oversight and efficiency. Those additions can widen the potential attack surface if they are not integrated with the same level of security control as back-office systems.
Spencer Starkey, Executive Vice President, EMEA, at SonicWall, said the company's latest monitoring showed clear differences in how attackers were approaching major UK industries.
"Our data this year shows a clear pattern: silent reconnaissance against financial services, relentless stress-testing of healthcare, and direct, heavy-handed extortion against UK manufacturing," Starkey said.
He added that the concentration of ransomware activity on individual facilities stood out in the data.
"With 1.8 million ransomware hits, heavily concentrated on individual facilities, attackers clearly see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos.
"UK manufacturers are navigating a toxic mix of old and new digital risk. Legacy Java sits unpatched in SCADA and MES systems because plant managers can't afford production downtime. Meanwhile, new digital frameworks are being scanned by attackers at speed. Manufacturers have got to secure legacy OT without slowing modern operations," Starkey said.