AcademyApproachFAQContact Request an assessment
AREN

Are Syrian factories and plants at risk of cyberattacks?

15 September 2026

Industry is a declared global target. Locally there is no documented factory incident — and operational infrastructure has already been hit.

Restart first — security last on the list

Many factories and plants in Syria today are focused entirely on restarting production after years of stoppage. Cybersecurity is last on the list, because it is treated as “a big-company problem” or “a government problem”. That is a dangerous assumption worldwide. Locally, the evidence points the other way — not because we have a publicly documented Syrian factory incident, but because the country’s digital and operational infrastructure has already shown, this year, that it is a real target.

The question is not “was a Syrian factory breached?”. It is narrower: is the exception still a safe assumption, now that industry is a declared global target in published figures, and now that this year’s attacks here reached electricity, water and telecommunications?

The figures are global — the technical cause applies here

These are global figures from Kaspersky’s Industrial Control Systems Cyber Emergency Response Team (ICS CERT), not a Syrian statistic. In the first quarter of 2026, the share of industrial control systems (ICS) on which malware was actually blocked reached 19.6%. In the first three quarters of 2025, Kaspersky and VDC Research estimated that ransomware attacks on industrial organisations had almost cost the sector more than 18 billion dollars in losses — with the actual losses likely much higher once supply-chain disruption, reputation and recovery costs are counted.

The technical cause is not “a sophisticated attack on a large state”. Evgeny Goncharov, head of Kaspersky ICS CERT, points to legacy operational technology (OT) systems that are still widely used in manufacturing environments. They were designed at a time when a connection to the internet was not expected at all. Connecting them to the network today — for efficiency and remote monitoring — opened a gap they were never designed to close.

That description applies to any factory in the world whose production line reaches a monitoring device or a control panel over the network. Including Syria. Size does not exempt. Age does not protect. Connecting for efficiency without a security boundary is the hole, not the country’s name.

Real attacks that happened recently — by name

According to the same source, real attack campaigns recently targeted manufacturing, telecommunications and logistics. The “Salmon Slalom” campaign relied on advanced phishing and the loading of malicious DLL libraries. The “Librarian Ghouls” espionage operation breached engineering colleges and industrial design environments.

This is not a “general threat to the sector”. These are named operations, with a named tactic, against environments a factory or an engineering office actually uses: email, a software library, a design workstation. Whoever reaches the design environment later reaches what runs on the floor. The expert conclusion — paraphrased, not quoted verbatim — is that multinational supply chains and local systems are both in the circle of risk. Any industrial organisation needs to assume it is a potential target, and act on that assumption, not on the assumption of an exception.

Why Syria specifically is not an exception

There is currently no publicly documented incident of a specific Syrian factory being breached. We are not inventing one. The direct Syrian context is not a factory example. It is what we covered in a separate article: in February 2026 the country saw wide cyberattacks that disrupted electricity, water and telecommunications and cut national internet connectivity by 75%.

That is: digital and operational infrastructure has already proved it is a real target — even without a publicly documented incident at a named Syrian factory so far. A plant that restarts a line on an unexamined network, or on a legacy control panel connected “to make monitoring easier”, sits on the same logic described globally: a system not designed for the internet, then joined to it. The safe assumption is “we could be a target”, not “we are exempt because we are small” or “because no incident has yet been announced under a factory’s name”.

The starting point: a periodic assessment — not waiting for an incident

Kaspersky’s practical recommendation from the same source: run periodic security assessments of operational-technology environments to find vulnerabilities before attackers exploit them — not after an incident. An assessment here is not a report for the shelf. It is an inventory: what was connected to the network that was never designed for it, where malware would enter if a phish reached a maintenance machine, and what stops on the shop floor if the control panel falls.

We do not claim a specific Syrian factory was breached. We are not asking anyone to “protect the plant from catastrophe”. The message is narrower and calmer: industry is a global target, with figures and named campaigns. Operational infrastructure in Syria was targeted this year. The starting point for whoever is restarting a plant is a periodic OT assessment — before the incident becomes the first measurement.

Abdulrahman

Abdulrahman

Founder & General Manager

Related

Contact

Was the operating environment examined before it was reconnected?

We do not claim a Syrian factory incident that does not exist. Describe what you run on the line and the network. We start with a periodic OT assessment — before the incident, not after it.

Request an assessment
Hours
Sunday — Thursday · 9:00 — 17:00