Quick Read Briefing

  • Although cyberattacks against manufacturing have dropped significantly from last year, risks remain high—a new report from California cybersecurity firm SonicWall shows that factories have opened new entry points for hackers.
  • In the first half of 2026, malicious traffic in manufacturing fell 56.2% year-over-year, the largest decline among all industries tracked by SonicWall; however, total threats during the same period still reached 474 million.
  • The biggest threats come from networked security cameras, industrial sensors, and smart building control systems—manufacturers are connecting more operational technology to the network. The report's data comes from over 1 million security sensors worldwide.

Deep Insights

The SonicWall report notes that manufacturers expanding advanced monitoring and maintenance technologies to improve operations are also expanding the "attack surface" available to hackers. Meanwhile, security models have failed to keep pace with rapid changes.

"Every connection added for operational convenience, remote monitoring, predictive maintenance, and supplier access to production systems is a channel attackers can pass through," said Michael Crean, senior vice president of managed services at SonicWall, in a statement.

Many networked devices used in factories today were not designed with modern security needs in mind. For example, a vulnerability in Hikvision cameras from five years ago remains one of the most frequently detected threats in factory networks. The report shows this vulnerability generated 43 million attack hits in the first half of 2026, making it the largest internet-connected attack signature across all industries tracked by SonicWall. IoT attacks ranked as the second-largest attack category by volume.

Although malware detection numbers have dropped significantly from last year, SonicWall attributes this to improved detection tools rather than fewer attacks. Crean said that as manufacturers begin connecting corporate office networks to physical factory floors, the risk of business disruption has risen.

"Unless we start continuously verifying every user and limiting their access to only the specific applications they need, a single stolen password is still enough to shut down a factory," he said.

The report shows that 10 ransomware gangs were active in attacks targeting manufacturing networks in the first half of 2026, with the Zhen malware family generating 22.2 million hits on just two devices. The industry's detection rate for attacks on supervisory control and data acquisition systems was the highest among all tracked industries, including retail, education, financial services, professional services, and healthcare.

"Stolen credentials should not be able to reach the production floor, but in most manufacturing environments today, they can," Crean said.

According to another report from IBM X-Force, manufacturing was the top target for hackers for the fifth consecutive year in 2025. The New York-based company recommends manufacturers take multiple measures to strengthen operational security, including keeping IT and OT systems separate, updating software promptly, prioritizing threats, and preparing contingency plans for downtime scenarios.