Dive Brief:
- While cyberattacks aimed at the manufacturing sector have declined significantly compared to last year, risks remain high as factories open up new entry points for hackers to exploit, according to a new report from California-based cybersecurity company SonicWall.
- Manufacturing had a 56.2% year-over-year decline in malicious traffic in the first half of 2026, marking the steepest drop of any vertical tracked by SonicWall. However, the overall volume of threats on the industry remains high at 474 million over the period.
- The biggest threats are coming from networked security cameras, industrial sensors and smart building controls as manufacturers bring more operational technology online. The report drew data from SonicWall’s global network of more than 1 million security sensors.
Dive Insight:
As manufacturers scale advanced monitoring and maintenance technology to enhance their operations, they are also expanding the “attack surface” for hackers, according to SonicWall’s report. At the same time, security models are not keeping up with the rapid changes.
“Every connection added for operational convenience, remote monitoring, predictive maintenance, vendor access to production systems, is also a connection an attacker can walk through,” Michael Crean, SonicWall’s senior vice president of managed services, said in a statement.
Many factories today use connected devices that were not designed with modern security in mind. For example, a Hikvision camera flaw from five years ago is still one of the most common threats detected in factory networks, according to the report. The Hikvision vulnerability generated 43 million hits in the first half of 2026. This was the largest internet-connected attack signature across any industry tracked by SonicWall. Internet of Things attacks made up the second-largest attack category by volume.
While malware detections are down significantly compared to last year, SonicWall attributed this to better detection tools, not fewer attacks. The risk of disruption has increased as manufacturers began connecting their corporate offices to physical plant floors, Crean said.
“Until we start continuously verifying every user and restricting their access to only the specific apps they need, one stolen password will continue to be enough to shut down a plant,” he said.
Ten ransomware groups were active against manufacturing networks during the first half of 2026, according to the report, with the Zhen family of malicious software accounting for 22.2 million hits on just two devices. The sector also had the highest supervisory control and data acquisition attack detection rate of any tracked vertical, including retail, education, financial services, professional services and healthcare.
“A stolen credential shouldn’t be able to reach the production floor, but in most manufacturing environments today, it can,” Crean said.
In 2025, the manufacturing sector was the most targeted by hackers for the fifth year in a row, according to a separate report from IBM X-Force. The New York-based company recommended a number of steps that manufacturers can take to shore up their operations, such as keeping their information technology and operational technology systems separate, updating software quickly, prioritizing threats, and planning for downtime scenarios.