SonicWall: UK manufacturing hit by ransomware surge, SonicWall says

SonicWall: UK manufacturing hit by ransomware surge, SonicWall says

UK Manufacturing Hit Hardest by Ransomware as Attacks Surge 28%

UK manufacturing has emerged as the most targeted sector for ransomware attacks, with 1.84 million incidents recorded between January and May 2025, according to SonicWall. The data, gathered from 364 specialized sensors in industrial environments, reveals a sharp rise in cyber threats against factories, contrasting with declining extortion attempts in other sectors.

Nearly all ransomware activity 1.79 million hits was attributed to the Filecoder malware family, with attacks heavily concentrated on just two sensors, suggesting a targeted approach rather than broad sector-wide campaigns. In addition to ransomware, sensors logged 15.8 million intrusion attempts and 12.2 million malware threats, indicating persistent probing of industrial networks.

Key vulnerabilities exploited by attackers include:

  • Apache Log4j flaws, generating 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, MES, and ERP systems.
  • React Server Components RCE vulnerabilities, detected in 45% of sensors, targeting modern web-based operational dashboards.
  • Legacy infrastructure risks, as manufacturers struggle to patch older systems due to production downtime concerns.

Unlike other sectors, IoT-related attacks were less prevalent, with only 230,000 hits recorded, as threat actors prioritized application vulnerabilities over connected devices.

The surge in attacks reflects the unique challenges of securing industrial environments, where operational technology (OT) systems often tied to physical production processes are difficult to patch without disrupting operations. Meanwhile, the adoption of internet-facing tools, such as customer portals and digital dashboards, has expanded the attack surface, often without equivalent security controls.

SonicWall’s EMEA Executive Vice President, Spencer Starkey, noted the distinct tactics used against UK manufacturing: "Attackers see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos." He highlighted the dual risk of unpatched legacy systems and rapidly scanned new digital frameworks, complicating cybersecurity efforts for manufacturers.

Source: https://itbrief.co.uk/story/uk-manufacturing-hit-by-ransomware-surge-sonicwall-says

SonicWall cybersecurity rating report: https://www.rankiteo.com/company/sonicwall

"id": "SON1785487061",
"linkid": "sonicwall",
"type": "Ransomware",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing',
                        'location': 'UK',
                        'type': 'Manufacturing companies'}],
 'attack_vector': ['Application vulnerabilities', 'Unpatched systems'],
 'data_breach': {'data_encryption': 'Yes (Filecoder malware)'},
 'date_detected': '2025-01-01',
 'date_publicly_disclosed': '2025-05-31',
 'description': 'UK manufacturing has emerged as the most targeted sector for '
                'ransomware attacks, with 1.84 million incidents recorded '
                'between January and May 2025. The data reveals a sharp rise '
                'in cyber threats against factories, with nearly all '
                'ransomware activity attributed to the Filecoder malware '
                'family. Additionally, 15.8 million intrusion attempts and '
                '12.2 million malware threats were logged, indicating '
                'persistent probing of industrial networks.',
 'impact': {'downtime': 'Production downtime',
            'operational_impact': 'Lost revenue and supply chain chaos',
            'revenue_loss': 'Lost revenue',
            'systems_affected': ['SCADA',
                                 'MES',
                                 'ERP systems',
                                 'Operational dashboards']},
 'lessons_learned': 'Manufacturers face unique challenges in securing '
                    'industrial environments due to operational technology '
                    '(OT) systems tied to physical production processes, which '
                    'are difficult to patch without disrupting operations. The '
                    'adoption of internet-facing tools has expanded the attack '
                    'surface without equivalent security controls.',
 'motivation': 'Extortion',
 'post_incident_analysis': {'root_causes': ['Unpatched legacy systems',
                                            'Rapidly scanned new digital '
                                            'frameworks',
                                            'Internet-facing tools without '
                                            'equivalent security controls']},
 'ransomware': {'data_encryption': 'Yes', 'ransomware_strain': 'Filecoder'},
 'references': [{'date_accessed': '2025-05-31', 'source': 'SonicWall'}],
 'title': 'UK Manufacturing Hit Hardest by Ransomware as Attacks Surge 28%',
 'type': 'Ransomware',
 'vulnerability_exploited': ['Apache Log4j flaws',
                             'React Server Components RCE vulnerabilities',
                             'Legacy infrastructure risks']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.