Industrial Ransomware Climbs 12% in Q2 — Manufacturing Takes 65% of Incidents

The figure, drawn from publicly disclosed victim data and ransomware group postings on data leak sites, comes from OT cybersecurity firm Dragos in its Q2 2026 Industrial Ransomware Analysis, released Monday. Accenture acquired a majority stake in Dragos earlier this year.

Manufacturing absorbed the largest share of incidents: 747 of the 1,140 documented cases, or 65%. Construction (176 incidents), equipment suppliers (114), and food and beverage (70) led the manufacturing subsectors. ICS-related organisations — engineering firms, system integrators, and equipment makers — accounted for 117 incidents, followed by transportation and logistics at 95.

The clearest line in the report is one of restraint on the attacker side, at least in OT terms. Dragos observed no case in Q2 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Operational disruption — precautionary shutdowns, loss of view, downtime — followed from encryption or shutdown of the enterprise and virtualisation layers that OT depends on. The industry IT stack, not ICS capability, is the attack surface doing the damage.

The tactics stayed consistent: exploitation of internet-facing edge devices, abuse of valid accounts, credential theft, EDR-killer tooling, and Bring Your Own Vulnerable Driver techniques. The extortion model continued its shift from encryption toward data theft-only operations, a pattern that first gained traction in 2024.

Geopolitically influenced activity — state-aligned actors operating behind ransomware branding — also persisted through the quarter. Qilin, Akira, and The Gentlemen accounted for the largest victim volumes.

Regionally, North America recorded 514 incidents (up from 480 in Q1), with the US responsible for 431, or 38% of all global incidents. Europe reported 316 incidents, up from 252 in Q1. Germany recorded 68 incidents in Q2 against 37 in Q1 — an 84% quarterly increase — with 76% of German victims in manufacturing.

Asia documented 172 incidents, led by Taiwan and Thailand. South America saw 64; the Middle East, 44; ANZ, 19; Africa, 11.

Energy sectors remained in scope. Oil and gas accounted for 45 incidents; electric utilities, 8; renewables, 12; water utilities, 4. Mining registered 15 incidents.

Dragos assesses with high confidence that the pace will persist and that intrusions targeting enterprise IT will continue to cascade into OT environments — producing real operational consequences without any ICS-native capability on the attacker side.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News