Ransomware Surge Impacts UK Manufacturing, Reports SonicWall

Key Takeaways

  • UK manufacturing is now the primary target for ransomware, with 1.84 million events recorded from January to May.
  • The majority of ransomware attacks originated from the Filecoder malware, indicating a focus on specific sites.
  • Software vulnerabilities, especially in legacy systems, are exacerbating the cyber risks faced by manufacturers.

Ransomware Attacks Target UK Manufacturing Sector

According to SonicWall, UK manufacturing has emerged as the most attacked sector for ransomware, with 1.84 million incidents occurring between January and May 2023. The data was gathered via 364 sensors monitoring British industrial environments. In this same timeframe, there were also 15.8 million intrusion prevention system events and 12.2 million malware threats detected.

This trend indicates a stark contrast between manufacturing and other sectors in the UK, where extortion attempts have declined significantly. For manufacturing, intrusion attempts are now running 28% higher than anticipated full-year totals for 2025. This suggests an ongoing and serious threat from automated probing of production networks and systems.

Most notable among the ransomware activity is the prevalence of the Filecoder malware, responsible for 1.79 million of the total ransomware events. This concentration implies that attackers are zeroing in on a select few facilities rather than a broader range within the sector, suggesting a more strategic approach to targeting.

SonicWall’s research also illuminated specific software vulnerabilities within the industrial landscape. For instance, exploitation of the Apache Log4j vulnerability accounted for approximately 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, manufacturing execution, and enterprise resource planning systems. Additionally, 45% of the sensors documented attacks linked to React Server Components, aimed at modern digital dashboards that sit alongside older control systems.

Although the overall IoT attack traffic was lower in manufacturing compared to other sectors, there were still 230,000 IoT-related hits. Attackers seem to favor exploiting application vulnerabilities and outdated infrastructure over newer, connected devices.

As manufacturers strive to modernize their operations, they face pressing cyber risks. Disruption in manufacturing can halt production and impact supply chains, making it crucial for companies to blend old systems with new technologies while ensuring strong security measures. Legacy systems, such as SCADA and MES, often remain unpatched to avoid production downtimes.

SonicWall’s Executive Vice President for EMEA, Spencer Starkey, commented on the patterns observed in cyberattacks across various industries. He noted a significant trend of intense extortion efforts specifically targeting manufacturing, which stands apart from the more subtle reconnaissance seen in financial sectors or the demanding stress-tests faced by healthcare.

Starkey emphasized the imperative for manufacturers to address legacy vulnerabilities without hampering ongoing operations. The dual challenge of safeguarding traditional operational technologies while embracing new digital frameworks has never been more urgent in the current cyber threat landscape.

The content above is a summary. For more details, see the source article.

Leave a Comment

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Become a member

RELATED NEWS

Become a member

Scroll to Top