If you’re an industrial operator and you’re wondering when the impact of ransomware attacks on the sector is going to ease off, OT cyber security firm Dragos has some bad news.
Nothing’s going to change soon.
“In the second quarter of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on data leak sites identified 1,140 ransomware incidents affecting industrial organisations worldwide, a 12 per cent increase over the 1,020 incidents recorded in Q1,” the company said in its just-released Industrial Ransomware Analysis for Q2 2026 report.
The tactics employed throughout the quarter remained generally the same; exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, and credential theft were all in evidence during the quarter.
In addition, ransomware actors are continuing to routinely deploy EDR-killer tooling and bring-your-own-vulnerable-driver (BYOVD) techniques.
Other trends included a continued shift away from encryption towards pure data theft, with most disruptions caused by limited encryption attacks or precautionary shutdowns.
Qilin remained the most active ransomware operator throughout the quarter, with its affiliates leveraging a range of initial access vectors.
“Post-compromise activity frequently involved disabling endpoint security tools and harvesting credentials stored in browsers before ransomware deployment,” Dragos said.
“Microsoft’s disruption of the Fox Tempest malware-signing service removed one component of the affiliate ecosystem during the quarter but had little visible impact on Qilin’s overall activity, highlighting the operational flexibility of large, well-established affiliate networks.”
Akira placed second, with a particular focus on manufacturing and industrial services throughout Europe and North America, while DragonForce was observed employing several new techniques, including a custom, Go-based RAT deployed by one affiliate.
That same hacker also exploited a zero-day vulnerability in a Huawei driver, while the group at large continued to take advantage of several SimpleHelp vulnerabilities.
“Together, these activities suggest a deliberate focus on developing and adopting new intrusion and evasion techniques rather than relying solely on established ransomware playbooks,” Dragos said.
Geopolitics and ransomware
One noteworthy trend observed by Dragos is the growing overlap between traditionally criminal ransomware operations and state-based hacktivism.
Quite a lot of this is driven by what the company calls the “geography of enforcement and the alignment of victims”.
“The largest ransomware ecosystems continue to operate in jurisdictions where enforcement against actors targeting foreign entities is minimal or politically constrained, and victim distribution skews toward regions with adversarial relations with an affiliate’s home country,” Dragos said.
That said, the lines between financial motivation and political ideology are definitely blurring. The Chaos ransomware group, for instance, is a traditional, financially motivated operation; however, a threat actor linked to Iran’s Ministry of Intelligence and Security was observed using Chaos branding to obscure its espionage operations.
Other groups, such as Stormous and World Leaks, also blurred the lines between criminal and state-based activity.
“This blending of ideological presentation with extortion procedures tracks the broader market shift toward data theft-only operations, in which leverage comes from publication rather than encryption,” Dragos said.
Who was hacked, and where
Perhaps unsurprisingly, North America remained the most targeted region for the quarter, with 514 recorded incidents, up from 480 in the previous quarter. Manufacturing, construction, and engineering were the most targeted sectors.
That’s followed by Europe, with 316 incidents (up from 252), Asia, which steadily increased ot 172 incidents, and South America with 64. The Middle East suffered 44 recorded ransomware incidents.
One region that did not see an increase was Australia and New Zealand, which remained steady at 19 observed incidents.
Dragos concluded that the main entry points remain internet-facing edge devices and remote management tooling.
“Organisations should assume that all internet-facing assets are discoverable and actively sought by adversaries, making continuous external attack surface management a necessity,” Dragos said.
“The consistent abuse of compromised credentials and remote management tools, including SimpleHelp, AnyDesk, and QuickAssist, underscores the importance of credential hygiene, MFA enforcement, and strict tooling policies.”
You can read the full report here.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.