BusinessCybersecurityNewswireTechnology

Ransomware disrupts industry without control system access

▼ Summary

– Ransomware incidents targeting industrial organizations rose 12% quarter-over-quarter to 1,140 in Q2 2026, with manufacturing accounting for 65% of cases.
– Dragos found most risk stems from attacks on enterprise IT systems like ERP and virtualization infrastructure, not ICS-specific malware, as disruptions cascade into production shutdowns.
– Extortion is shifting from file encryption to data theft, with stolen data used for further leverage, while initial access often comes from compromised credentials and internet-facing devices.
– Social engineering via Microsoft Teams, where attackers impersonate IT support to install remote tools, emerged as a top initial access vector, alongside in-person USB attacks by Silent Ransom Group.
– Law enforcement dismantled ransomware infrastructure, including the First VPN service and malware families via Operation Endgame, while the US remained the top target with 431 incidents.

Ransomware groups are increasingly finding that they don’t need to touch industrial control systems to bring production to a halt. New research from Dragos shows that disrupting the enterprise IT backbone of industrial environments is often enough to trigger costly shutdowns, even when operational technology (OT) remains untouched.

During the second quarter of 2026, Dragos tracked 1,140 ransomware incidents involving industrial organizations, a 12% jump from the 1,020 recorded in Q1. The data, pulled from public victim disclosures and ransomware groups’ own leak sites, shows manufacturing bore the brunt of the activity with 747 incidents, representing 65% of all cases. Construction followed with 176, equipment manufacturing logged 114, and food and beverage firms saw 70. Another 117 incidents hit organizations that directly support ICS environments, including engineering firms, system integrators, and equipment makers, while transportation and logistics recorded 95.

According to researchers Lexie Mooney and Abdulrahman H. Alamri, “Ransomware remained the most persistent and disruptive cyber threat to industrial organizations.” The pair noted that the risk picture is shifting away from novel, ICS-specific malware and toward adversaries who are zeroing in on the enterprise systems that underpin OT operations.

“Platforms such as ERP systems, virtualization infrastructure, identity services, and remote access gateways represent high-value targets precisely because disrupting them can rapidly cascade into production shutdowns and supply chain impacts,” they added.

A case in point is Mackay Sugar, Australia’s second-largest raw sugar producer. The company disclosed a cyberattack on June 10 that halted milling and cane haulage at two of its three Queensland mills. One mill managed to resume limited manual crushing two days later. The Gentlemen ransomware group subsequently claimed the company on its leak site. Dragos found no evidence that attackers reached the ICS layer or directly manipulated OT. With low confidence, researchers assessed the incident primarily affected enterprise IT, and it remains unclear whether the shutdown stemmed from the attack itself or from containment actions taken in response.

Data theft is now the dominant extortion tactic, according to Dragos, as the pressure point moves away from file encryption. This shift means an intrusion can keep exposing an organization long after systems are restored, because stolen employee records, customer details, supplier contracts, financial data, or operational information can be published or weaponized for follow-on demands.

Initial access continues to flow through familiar channels: internet-facing devices, remote management tools, compromised accounts, and stolen credentials.

Among the most active groups, Qilin posted the largest number of industrial victim claims in Q2 with 140, though that was down from 198 in Q1. Akira climbed to 129 from 100, and The Gentlemen rose from 83 to 125. The three finished within 15 claims of one another. Qilin affiliates leaned on compromised credentials and vulnerable internet-facing infrastructure, Akira exploited compromised VPN devices, and The Gentlemen targeted edge devices before working deeper into corporate networks.

Social engineering took a notable turn this quarter, moving from email-based lures to interactive impersonation on enterprise collaboration platforms. Several groups contacted employees over Microsoft Teams while posing as internal IT support, walking targets through screen-sharing sessions to install remote monitoring tools like AnyDesk or Quick Assist. Some attackers also registered credential-harvesting domains that mimicked victim organizations’ naming conventions, capturing passwords and MFA codes as employees typed them in.

The threat even went physical. In late May, the FBI warned that Silent Ransom Group, also known as Luna Moth, had begun dispatching operatives to offices disguised as IT technicians, plugging USB drives directly into machines.

Law enforcement kept up pressure on ransomware infrastructure throughout the quarter. An international operation dismantled the First VPN anonymization service, seizing 33 servers across 27 countries and identifying thousands of users. A phase of Operation Endgame in mid-to-late June targeted the SocGholish, Amadey, and StealC malware families, which supply stolen credentials and initial access to ransomware operators. That effort also recovered tens of millions of stolen credentials.

Geographically, North America remained the top target with 514 incidents, up from 480 in Q1. Europe followed with 316, up from 252. The United States alone accounted for 431 incidents, or 38% of the global total. Germany saw one of the sharpest quarter-over-quarter increases, with alleged incidents rising from 37 to 68, and manufacturing organizations made up 76% of the country’s claimed victims. Asia recorded 172 incidents, led by Taiwan and Thailand, while South America logged 64, the Middle East 44, Australia and New Zealand 19, and Africa 11.

The takeaway from Dragos is straightforward: “Organizations should assume that all internet-facing assets are discoverable and actively sought by adversaries, making continuous external attack surface management a necessity.”

(Source: Help Net Security)

Topics

ransomware attacks 98% industrial cyber threats 95% data theft extortion 92% initial access vectors 90% social engineering 88% ransomware groups 86% manufacturing sector attacks 84% law enforcement operations 82% geographic attack distribution 80% it/ot convergence risks 78%
Show More