Skip to content
Report: Operational tech remains primary target for hackers

Report: Operational tech remains primary target for hackers

Scworld • November 19, 2025

Trellix reports that manufacturing continues to face the highest volume of operational technology attacks, representing 42% of OT-related detections across its critical-infrastructure customers, with transportation and shipping, utilities, energy companies, and aerospace firms making up the remaining top targeted sectors, according to Cybersecurity Dive .

Based on activity between April and September, the report notes that OT incidents have shifted from unintended spillover from IT breaches to deliberate operations carried out by criminal groups and state- actors. Trellix says intrusions frequently exploit weaknesses in the connection between IT and OT networks, with attackers using Cobalt Strike, PowerShell, stolen credentials, and scans for industrial control system protocols to move within environments. Instead of directly attacking low-level industrial controllers, threat actors increasingly compromise devices that bridge the two network layers, which often contain more common vulnerabilities but still enable interference with industrial equipment.

Some attacks have attempted to corrupt or shut down safety-related systems. Trellix also warns vulnerabilities in legacy protocols such as Modbus, proprietary Supervisory Control and Data Acquisition device-makers' protocols, DNP3, as well as increased targeting of programmable logic controllers, citing past Triton malware activity. The report urges segmentation, zero-trust controls, threat-intelligence sharing, and strong vendor requirements.

Extracted Entities