The 1.84 million ransomware number needs context

SonicWall recorded 1.84 million ransomware events across 364 sensors in UK manufacturing environments between January and May. These are telemetry events rather than counts of successful incidents, victims or compromised factories.

Almost all those events were concentrated on two sensors. For executives, that distribution is more informative than the headline total because it shows where the recorded activity occurred.

Two sensors account for almost all the ransomware telemetry

Filecoder generated 1.79 million of the ransomware events, about 97%. Those hits were focused on just two specialised sensors.

SonicWall says this pattern suggests dedicated campaigns against higher-value facilities, where production disruption could provide greater leverage. The company sells cybersecurity products and services, giving it a commercial stake in how organisations assess cyber threats. Spencer Starkey, Executive Vice-President, EMEA, at SonicWall, describes factories as “prime extortion targets” because downtime can cause lost revenue and supply-chain disruption.

The telemetry supports a narrower conclusion. It establishes concentrated activity at particular sensors. It does not by itself establish confirmed compromises, ransom demands, production outages or attacker intent.

The wider dataset adds context:

Telemetry measure SonicWall finding
Intrusion Prevention System events, January to May 15.8 million
Malware threats, January to May 12.2 million
Annualised January-to-May intrusion-attempt rate versus full-year 2025 About 28% higher

SonicWall’s Threat Research team recorded these figures from the monitored sensors. They count telemetry events rather than successful attacks.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Factories face exposure across older systems and newer interfaces

Apache Log4j exploitation generated 1.1 million hits across 34% of monitored manufacturing sensors. SonicWall associates that activity with unpatched SCADA, or supervisory control and data acquisition, systems; Manufacturing Execution Systems (MES); and Enterprise Resource Planning interfaces used in industrial operations.

Separately, 45% of monitored sensors recorded attacks exploiting React Server Components remote code execution issues. SonicWall says those attempts targeted more recently digitised operational dashboards.

SonicWall therefore observed vulnerabilities involving long-lived industrial technology and newer application interfaces across its monitored manufacturing environments. The figures do not establish that the same sensors experienced both types of activity.

That distinction affects operational planning. Technologies can have different dependencies and maintenance constraints, which security teams need to consider when deciding when and how to remediate vulnerabilities.

Patching can collide with production economics

Taking a SCADA or MES environment offline can require coordination with production operations.

Starkey says: “Legacy Java sits unpatched in SCADA and MES systems because plant managers can’t afford production downtime.” This is SonicWall’s characterization of the operational problem. As a cybersecurity vendor, the company benefits commercially when organisations invest more in managing cyber risk.

Starkey describes a trade-off between remediation and availability. Planned remediation can require production downtime, while delaying it leaves a known exposure in place. Security leaders therefore need to weigh operational constraints alongside technical severity when making industrial vulnerability decisions.

IoT telemetry adds another exposure category

SonicWall recorded 230,000 Internet of Things attack hits, below the Log4j exploitation volume recorded in the same manufacturing telemetry.

The comparison measures event volume within SonicWall’s monitored environments. It does not establish attacker preference or intent, but it identifies another technology category generating hostile telemetry alongside industrial systems and application interfaces.

For executives, the practical question is how each exposed system affects availability and how remediation can fit around operational constraints. The concentration of Filecoder events on two specialised sensors makes that system-level context essential when interpreting aggregate threat counts.

Key takeaways for leaders

  • Ransomware totals need context: SonicWall recorded 1.84 million ransomware events, but these were telemetry hits. Leaders should avoid treating aggregate event counts as incident counts.
  • Ransomware activity was highly concentrated: About 97% of ransomware events came from Filecoder and were focused on two specialised sensors. Security teams should examine where activity is concentrated before using headline totals to assess risk.
  • Legacy and newer systems both face exposure: Log4j exploitation affected 34% of monitored sensors, while React Server Components attacks appeared on 45%. Remediation planning should account for vulnerabilities across both industrial technology and newer application interfaces.
  • Patching decisions must account for production: Taking SCADA and MES systems offline can conflict with availability and production requirements. Leaders should balance vulnerability severity against operational constraints when scheduling remediation.
  • IoT adds another area to assess: SonicWall recorded 230,000 IoT attack hits alongside activity affecting industrial systems and application interfaces. Executives should assess exposed systems based on their operational importance rather than telemetry volume alone.

Alexander Procter

September 3, 2026

4 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.