Manufacturing, Supply Chain, Technology Among Industries at Risk
The report identified a total of 1,885 separate R&DE incidents in Q2 of 2026, an increase in year-on-year incidents from Q2 2025 and Q2 2024, suggesting incidents around this quarter are on the rise. Notably, attacks on North American-based organizations made up nearly 45% of all incidents reported. According to Darrah, these numbers are the result of the geopolitical conflict between America and Iran.
Overall, the manufacturing industry experienced the highest number of R&DE incidents in this quarter, accounting for nearly 20% of all incidents. This too, Darrah says, is connected to the shutdown of the Strait of Hormuz, and a desire from ransomware groups gain notoriety.
“Ransomware groups, especially those aligned either as a fellow traveler or as a direct associate of a military security apparatus, they like doing a couple of things. They love notoriety, they love being obedient to their overlords, they love money,” Darrah explains. “But they also love sitting back and watching civilized, law-abiding people and organizations squirm and be uncomfortable and to watch that pain.”
Similarly, R&DE targeting patterns have shifted away from the retail sector, and have instead turned towards the technology industry. Darrah again notes this is another way of embarassing important organizations.
“There’s a lot of prestige with what’s happening in the world right now in terms of AI,” Darrah says. “I think there’s probably a bit of prestige in going after technology firms, the people associated with that, to embarass the company and the victims.”
While Darrah notes developments in AI have also made the threat landscape more unpredictable, he does say some ransomware groups are still using older technologies, and are yet to convert to AI. In this case, businesses should protect themselves from all kinds of threats.
