
In May 2026, Foxconn, the world’s largest electronics contract manufacturer, suffered a major cybersecurity incident.
It started with a single infected computer. However, the malware did not remain confined to that device. It spread across the network like water, infecting other PCs, servers and production systems. By the time the factory detected the breach, the Manufacturing Execution System (MES) and production scheduling systems had completely failed, forcing several high-end production lines to shut down for approximately one week. Frontline staff resorted to recording production data manually with pen and paper.
Worse still, the malware exfiltrated 8 terabytes of data during propagation, including more than 11 million internal files — among them product design drawings for major clients such as Google and Intel.
During the same period, Fairlife, a dairy brand owned by The Coca-Cola Company, fell victim to a similar attack. Malware moved laterally across the internal network and locked core servers, disrupting product supply across 17 U.S. states. Production lines remained offline for over 72 hours, with roughly 1.8 million gallons of dairy products unable to be processed and shipped on schedule.
One compromised computer leads to full factory shutdown. This is the destructive power of ransomware’s lateral movement.
Imagine this scenario: your residential compound gate has a high-security lock (a firewall) that keeps burglars out.
But if an intruder sneaks inside — for example, posing as a courier and following a resident through the gate — they can move freely within the community. They can access every building, as all entry doors are unlocked.
This is exactly how lateral movement works.
Once malware compromises one computer, it uses that device as a stepping stone to roam the intranet: scanning other endpoints, attempting server logins and hunting for valuable data. Traditional firewalls only guard the “main gate” and have no oversight over traffic “between buildings.” After entering the internal network, malware operates within an unprotected environment.
One infected endpoint puts the whole network at risk — this is the biggest vulnerability of conventional networks.
Ransomware typically propagates through three main channels:
Simply put: once malware enters the intranet, it can move freely.
Antivirus deployed on each computer detects and cleans malware locally, yet it cannot monitor or stop malware moving from one host to another. Lateral propagation traffic remains invisible to endpoint protection tools.
Conventional firewalls sit at the network ingress and block external attacks. However, they do not restrict internal east-west traffic between servers. Malware hopping across the intranet is permitted by default.
Some enterprises implement VLAN segmentation to separate departments into distinct network segments. Nevertheless, VLANs rely on manual switch configuration, which easily contains omissions when adding devices or relocating workstations. Attackers can also forge VLAN tags to bypass isolation rules.
When one PC becomes infected and takes down the whole factory network, the root cause is not overly sophisticated malware, but an overly open internal network.
AINOPOL all-optical networks follow a straightforward principle: prevent malware from roaming freely inside the intranet.
All-optical networks enforce dual binding of ONU ports and MAC addresses. Every connected device must verify its port and MAC identity before gaining network access, similar to building access control where only registered residents may enter.
If an infected PC attempts to target other devices, the all-optical network identifies anomalous behavior and cuts off its connectivity. Malware cannot jump laterally across endpoints.
Many factories connect office PCs and production systems to the same network. Malware infiltrating via office workstations can directly reach production servers.
AINOPOL all-optical networks use VLAN logical segmentation to create isolated zones for office, production and R&D environments. Inter-zone communication is blocked by default; office endpoints cannot access production servers. Even if attackers take over office computers, they cannot reach production systems.
The all-optical network records all network access activities: which user or device accessed which host, at what time and from which source.
In the event of an attack, administrators can rapidly identify the initial compromised endpoint, the start time of propagation and all affected hosts. Forensic tracing is precise, eliminating the need for full-network inspection.
The AINOPOL Dream Gateway M1 integrates firewall, Intrusion Prevention System (IPS), Anti-Virus (AV) and other security capabilities within a single appliance. The IPS directly mitigates common ransomware tactics including SMB vulnerability exploitation, RDP brute-force attacks and lateral movement attempts before threats reach target assets. Real-world testing confirms it blocks over 95% of ransomware-related attacks.
For industrial manufacturers and commercial campuses, stable production, secure data and resilient supply chains form the core foundation of business development. Deploying a proactively defended, fully controllable all-optical secure network safeguards daily operations and delivers indispensable cybersecurity resilience for the digital era, ensuring robust protection for every network connection.
Q: What is ONU port plus MAC binding, and what threats can it block?
A: Every connected device must verify a matching ONU access port and MAC address. This works like employee ID verification for office entry: invalid credentials are rejected, and valid credentials cannot grant access through an unauthorized port. An infected device attempting to spread via another port will still be blocked.
Q: Can the system respond after a PC is already infected?
A: The Dream Gateway M1 analyzes traffic for abnormal host behavior, such as sudden mass scanning of intranet IP addresses or repeated login attempts to other devices. It will immediately isolate the compromised endpoint. Malware cannot propagate outward once blocked.
Q: Do ransomware attackers only target large enterprises? Are small and medium businesses safer?
A: The opposite is true. The National Computer Virus Emergency Response Center confirms SMEs are the hardest-hit group with the highest infection rates. Large corporations maintain dedicated security teams, while small businesses generally have weaker defenses, making them easier targets for threat actors.