12% ransomware increase at industrial organisations | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


In the second quarter (Q2) of 2026, analysis by Dragos of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organisations worldwide, a 12% increase over the 1,020 incidents recorded in Q1.

Ransomware remained the most persistent and disruptive cyber threat to industrial organisations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms and virtualisation infrastructure, versus direct manipulation of control systems.

Ransomware operators continued to rely on a consistent set of Tactics, Techniques and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact.

The extortion model continued its shift from encryption toward data theft-only operations.

Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualisation systems on which OT depends.

Dragos assesses with high confidence that ransomware will continue to impact industrial organisations globally, and that these intrusions can cascade into OT environments, producing operational downtime, precautionary shutdowns, loss of view and safety risk even without any ICS-native capability.

By examining victimology, sector concentration, observed TTPs and real-world operational impacts, Dragos provides defenders with insight into the evolving ransomware threat to industrial organisations.

Key findings

  • Dragos identified 1,140 ransomware incidents affecting industrial organisations in Q2 2026, an 12% increase over the 1,020 recorded in Q1.
  • Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors.
  • ICS-related organisations (engineering firms, system integrators and equipment manufacturers) accounted for the second-most-impacted sector, with 117 incidents, reflecting persistent industrial supply chain exposure.
  • Transportation and logistics ranked third with 95 incidents.
  • North America and Europe remained the most affected regions. The U.S. consistently ranks as the most impacted country by ransomware by a far margin (431 incidents in Q2, or 38% of all incidents). However, the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany.
  • Similar to previous quarters, a small number of ransomware groups accounted for a disproportionate share of activity, with Qilin, Akira and The Gentlemen responsible for the largest victim volumes in Q2.
  • The extortion model continued to shift away from encryption toward data theft-only operations and geopolitically influenced activity, including state-aligned actors operating behind ransomware branding, persisted throughout the quarter.

Ransomware by region

In Q2 2026, ransomware activity impacting industrial organisations remained steady across all regions, reinforcing the global and persistent nature of the threat. Manufacturing, construction and engineering continued to be targeted worldwide.

North America remained the most impacted region by a wide margin, while Europe and Asia also saw increased activity compared to Q1. Dragos noted an increase across most regions in Q2, with the exception of the Middle East and Africa, which saw slight decreases.

Regional distribution

North America: Recorded 514 incidents in Q2 2026 (up from 480 recorded in Q1 2026), maintaining its position as the most impacted region. Activity was driven by sustained targeting of industrial organisations across manufacturing, construction, engineering, transportation and government sectors.

Europe: Reported 316 incidents (up from 252 in Q1), remaining the second-most impacted region. The country with the greatest overall increase in Q2 was Germany, with 68 alleged ransomware incidents (37 recorded in Q1), making it the second-most-impacted country after the U.S. 76% of the organisations claimed by ransomware operators in Germany were in the manufacturing sector.

Asia: Documented 172 incidents, showing a steady increase since Q4 2025 and into 2026. Taiwan and Thailand led this region in incident volume. Ransomware activity in this region primarily impacted manufacturing, transportation and engineering organisations.

South America: Experienced 64 incidents. Organisations in Brazil and Argentina accounted for half of the ransomware activity against this region.

The Middle East: Recorded 44 incidents primarily affecting the manufacturing and energy sectors.

The ANZ region: Observed 19 incidents, exactly the same as Q1, primarily impacting manufacturing and logistics organisations.

Africa: Recorded 11 incidents. While reporting volume remained limited with no focused targeting, the presence of industrial victims across multiple countries reflects continued opportunistic targeting of emerging markets.

Ransomware by sector

Ransomware activity in Q2 2026 continued to significantly impact industrial organisations, reinforcing adversaries’ sustained focus on sectors with tight operational dependencies and low tolerance for downtime.

Manufacturing remained the most heavily targeted sector by a wide margin, while transportation and ICS equipment and engineering providers continued to experience persistent activity, ranking as the second- and third-most-impacted sectors, respectively.

Energy-related sectors, including Oil and Gas and electric utilities/renewables, also remained consistently targeted throughout the quarter.

Manufacturing

Manufacturing was the most heavily impacted sector in Q2 2026, with 747 claimed victim organisations spanning a wide range of subsectors.

Suppliers of building materials, construction services and equipment were repeatedly targeted, consistent with their reliance on ERP systems, distributed locations and tight project timelines.

Breakdown of Top Manufacturing Subsectors:

  • Construction: 176 incidents
  • Equipment: 114 incidents
  • Food and Beverage: 70 incidents

Industrial control system (ICS) ecosystem

Organisations directly supporting OT environments, including engineering services, integrators and ICS equipment manufacturers, experienced 117 ransomware incidents in Q2 2026.

Breakdown of ICS Subsectors:

  • ICS Equipment: 27 incidents
  • ICS Engineering: 90 incidents

Transportation and logistics

These organisations remain attractive targets due to their dependence on scheduling platforms, reservation systems, fleet management software and time-sensitive operations.

Disruption in these sectors often creates immediate cascading effects well beyond the victim organisation itself. Within the 95 transportation-related incidents observed in Q2, activity was distributed across the following subsectors.

Breakdown of Transportation Subsectors:

  • Logistics: 78 incidents
  • Maritime: 8 incidents
  • Aviation: 6 incidents
  • Rail: 3 incidents

Government, energy and utilities

Government entities accounted for 64, largely at the municipal and regional level.

Electric utilities (8 incidents) and water utilities (4 incidents) continued to appear in ransomware victim disclosures, although at lower volumes than manufacturing and transportation.

Oil and Natural Gas (ONG) experienced 45 incidents, demonstrating persistent targeting of upstream, midstream and downstream energy organisations and the service providers that support them.

Renewable energy organisations (12 incidents) and mining organisations (15 incidents) were also impacted, indicating continued adversary interest in energy production and resource extraction environments.

The full report is available, here.

——————————————————–


Click Here For The Original Source.

.........................