Skip to main content

Share story

Security

Dragos publishes Q1 2026 industrial ransomware analysis report

Ransomware Blog Hero Image: Primary
Ransomware remained a persistent and disruptive threat to industrial organizations into the first quarter of 2026. Dragos identified 1,020 ransomware incidents impacting industrial organizations worldwide through analysis of publicly disclosed victim data and ransomware groups postings on data leak sites. Manufacturing, transportation, industrial control system equipment manufacturers, and engineering firms represented the most affected sectors. North America continued to account for the majority of incidents with nearly 500 reported victim organizations. Europe remained the second most affected region with more than 250 incidents. North America and Europe collectively accounted for more than half of all observed victims. Manufacturing accounted for 62 percent of all observed industrial ransomware victims and 633 incidents across all subsectors. Construction related manufacturing, industrial equipment producers, and food and beverage manufacturers were particularly affected. ICS adjacent organizations including engineering firms, system integrators, and equipment suppliers accounted for 139 incidents. No ransomware variants specifically engineered to manipulate industrial control protocols or process environments were observed during the quarter. Ransomware incidents continued to produce substantial operational consequences through the loss of IT systems, enterprise resource planning platforms, and virtualization infrastructure. The continued convergence of IT and OT environments further amplified the impact. Ransomware groups continued to rely on well established tactics, techniques, and procedures including credential theft, abuse of valid accounts, exploitation of remote access services, lateral movement via common enterprise protocols, and double extortion models. Qilin and Akira accounted for the highest volume of ransomware claims against industrial organizations. The Gentleman operation accounted for 83 incidents in the first quarter, a sharp increase from 18 in Q4 2025.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Dragos and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

CISA adds two exploited Check Point flaws to federal fix list

The U.S. Cybersecurity and Infrastructure Security Agency added two Check Point Security Gateway flaws to its list of known exploited vulnerabilities and told federal agencies to apply fixes or mitigations by September 25. Check P...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...

Security
Security

FBI investigates ShinyHunters claim of employee data theft

The FBI is investigating ShinyHunters' claim that it stole personal information about thousands of current and former agency employees after exploiting a previously unknown flaw on FBIJobs.gov, Ars Technica reported. The group als...