Threat Research

SonicWall Research Finds Manufacturing Cybersecurity at a Breaking Point as Factory Floors and Corporate Networks Collide

New Manufacturing Protect Brief reveals 43 million camera attacks and the highest industrial control attack rate of any industry

MILPITAS, Calif. — July 22, 2026 — SonicWall today released its 2026 Manufacturing Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report. The findings show that factories are increasingly opening up critical new entry points for hackers. Consequently, while the total volume of cyberattacks on the manufacturing sector has actually decreased, hackers are executing much more precise, highly targeted strikes on these digital gaps. 

Manufacturing recorded a 56.2% year-over-year decline in intrusion prevention (IPS) volume in the first half of 2026, the steepest drop of any tracked vertical. But the decline does not reflect reduced risk. Absolute volume remains significant at 474 million events, and as more operational technology connects to IT infrastructure, the attack surface is expanding even as attackers grow more selective about where they strike. 

"Manufacturing’s attack surface looks nothing like it did even five years ago, and the security model hasn’t caught up," said Michael Crean, SonicWall SVP of Managed Services. "Every connection added for operational convenience, remote monitoring, predictive maintenance, vendor access to production systems, is also a connection an attacker can walk through. A stolen credential shouldn’t be able to reach the production floor, but in most manufacturing environments today, it can." 

SonicWall’s Manufacturing Protect Brief draws on data from SonicWall’s global network of more than one million security sensors to document the specific attack patterns, legacy vulnerabilities and ransomware campaigns defining the manufacturing threat landscape in the first half of 2026. 

Key Findings from the 2026 SonicWall Manufacturing Protect Brief 

  • The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260), disclosed in 2021, continued to generate 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks.
  • IoT attacks were manufacturing’s second-largest attack category by volume, generating 46.2 million hits, with more than half of manufacturing networks detecting exploitation attempts.
  • Manufacturing recorded the highest SCADA attack detection rate of any tracked vertical.
  • Ten ransomware families were active against manufacturing networks in H1 2026; the Zhen family alone generated 22.2 million hits concentrated on just two devices, a pattern consistent with an active, ongoing incident rather than a broad campaign.
  • Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.

Unlocked Doors 

Between networked security cameras, industrial sensors, and smart building controls, today's factories are packed with connected devices that were never designed with modern security in mind. They run on old software, are rarely patched, and sit on the exact same networks as critical production lines. This means old vulnerabilities never really go away. For example, a well-known Hikvision camera flaw from five years ago is still one of the most common threats detected on factory networks today. 

The danger multiplied as companies connected their corporate offices to their physical plant floors to allow for remote monitoring and automated maintenance. Because these networks are linked, a single employee password stolen through a phishing email is often all a hacker needs to jump from the front office straight into the systems that control physical machinery. 

"Manufacturing doesn’t have a sophistication problem, it has an architecture problem," continues Crean. "The factory floor is now part of the corporate network. Until we start continuously verifying every user and restricting their access to only the specific apps they need, one stolen password will continue to be enough to shut down a plant." 

The Architecture Problem Has a Known Solution 

The vulnerabilities documented in the Manufacturing Protect Brief are well understood, and the controls that address them exist. SonicWall Cloud Secure Edge applies Zero Trust principles to every access request, granting application-level access only and continuously re-verifying identity and device posture rather than treating a validated credential as a blanket pass to the network behind it. 

For manufacturers managing vendor and maintenance access to production systems, remote monitoring tools and ERP integrations, replacing broad VPN-based access with application-level Zero Trust removes the condition that makes credential compromise consequential: a stolen login no longer grants a path to the systems that run the production floor. 

To learn more, visit SonicWall at www.sonicwall.com.   

About SonicWall 
For more than 30 years, SonicWall has championed a partner-first model that combines purpose-built technology, cloud-delivered security services and real-time threat intelligence to help businesses prevent breaches, reduce risk and stay operational in the face of evolving modern threats. We are committed to deliver the best security outcomes for our customers where others deliver features and functions.  Through its unified cybersecurity portfolio and global community of over 17,000 partners, SonicWall enables managed service providers to actively manage, continuously optimize and measurably protect networks, cloud environments, endpoints and applications. The company is redefining cybersecurity around outcomes that matter to business leaders, including breach prevention, compliance achievement, cost efficiency and reduced human error, because protection is not about what a product can do but about what it actually delivers. 

Latest Stories

  • SonicWall, MSP를 위한 차세대 네트워크 보안 솔루션으로 사이버 보안을 재정의하고 새로운 기준을 정립
    계층화된 보안, 공동 관리 서비스, 통합 관리 플랫폼으로 든든한 보안을 제공하는 SonicWall은 차세대 방화벽을 활용한 지속적인 혁신으로 파트너가 수익성 있는 서비스를 키울 수 있도록 돕고 있습니다.캘리포니아주 밀피타스 — 2025년 5월 5일 — SonicWall은 날로 늘어나는 오늘 관리형 서비스 제공자(MSP) 및 고객의 포괄적인 보호 및...
    Read More
  • SonicWall 위협 데이터로 드러난 사이버 공격의 깊이 - 높아지는 관리형 서비스 제공자(MSP)의 필요성
    총 침해 공격 건수 증가(+20%), 위협 행위자의 전술 다각화 - 전 세계에서 공격 증가 랜섬웨어는 한 해 내내 거셌으며(하반기 +27%) 여름철에 절정(+37%) 총 크립토재킹 공격 건수 – 전 세계에서 +659% 급증 IoT 취약점 공격(+15%)와 암호화된 위협(+117%)도 상승세 '기존에 없었던' 맬웨어 변종 SonicWall...
    Read More
  • SonicWall, 관리형 엔드포인트 보안서비스로 확대하고 있습니다,
    SonicWall은 파트너 성장을 더욱더 촉진하기 위해 연중무휴24x7 보안운영센터(SOC)를 갖춘 관리형 탐지 및 대응(MDR) 제품군을 새롭게 확장합니다. 캘리포니아주 밀피타스 — 2024년 2월 8일 —소중한 채널 파트너의 피드백을 반영하여 SonicWall은 오늘, MSP를 위해 맞춤 구성된 여러 관리형 서비스가 제공된다고 발표했습니다. SonicW...
    Read More