SonicWall
Reports
All Statistics
Professional services generated 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry tracked.
Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
Directory traversal, malformed request probes and remote code execution signatures accounted for 72% of all IPS volume in the professional services sector.
IoT attacks generated 46.2 million hits in manufacturing, making IoT the sector's second-largest attack category by volume.
Ten ransomware families were active against manufacturing networks in H1 2026.
Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.
Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.
The GoodTech Telnet Server Buffer Overflow vulnerability generated 42.2 million detection events in the financial services industry in the first half of 2026.
Log4Shell generated 35.6 million detection events in the first half of 2026 in the financial services industry, more than two years after disclosure.
61% of hackers use new exploit code within 48 hours of discovering a vulnerability.
Ransomware was responsible for 95% of all breaches in the healthcare industry, impacting more than 198 million US patients.
Companies faced an average of 68 days of critical cyber-attacks.
SIPVicious VoIP exploitation generated 332 million combined hits in professional services, with the related signatures ranked #3 and #6 by volume.
Ten active ransomware families operated simultaneously against the professional services sector in the first half of 2026, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
Apache Log4j2 (Log4Shell) generated 107 million hits in the professional services sector, 2.5 years after public disclosure and emergency patching across the industry.
460 organizations in the professional services sector are actively detecting ransomware campaigns, representing the broadest exposure of any vertical.
Manufacturing recorded 474 million intrusion prevention events in the first half of 2026.
The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260) generated 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks.
Manufacturing recorded a 56.2% year-over-year decline in intrusion prevention (IPS) volume in the first half of 2026, the steepest drop of any tracked vertical.
The Zhen ransomware family generated 22.2 million hits concentrated on just two devices in manufacturing networks.
Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.
Financial services experienced more than double the cross-sector average of cyberattack attempts per device in the first half of 2026.
Financial services saw 132,378 IPS hits per device in the first half of 2026, the highest attack intensity of any industry SonicWall tracks.
Bad bot traffic accounts for 37% of all global internet traffic.
Identity, cloud, and credential compromise accounted for 85% of actionable security alerts.
A single SMB breach can exceed $4.91 million when downtime and recovery are included.
VPN Common Vulnerabilities and Exposures (CVEs) grow 82.5% over the analyzed period.
Automated bots generate more than 36,000 vulnerability scans per second.
SMBs account for nearly half of private sector employment.
In 2025, 88% of SMB breaches involved ransomware, more than double the rate at large enterprises.
The average breach goes undetected for 181 days.
Automated bots account for more than half of all internet traffic.
Log4j generated 824.9 million IPS hits in 2025.
High- and medium-severity attacks surged 20.8% to more than 13 billion hits.
IoT attacks climbed 11% to 610 million hits.
North America saw an 8% rise in ransomware, while Latin America experienced a 259% spike.
IoT attacks increased 124% year-over-year.
Business Email Compromise (BEC) accounted for 33% of reported cyber insurance events, up from 9% in 2023.
38% of detected malicious files were HTML-based, while PDFs followed closely at 22%.
SonicWall identified 210,258 never-before-seen malware variants, averaging 637 new threats daily.
Server-side request forgery (SSRF) attacks rose by 452%.