Industrial Ransomware Analysis for Q2 2026
ID: 746ae812-a22e-5883-ba16-f19f4d8c9fbc
STIX ID: report--746ae812-a22e-5883-ba16-f19f4d8c9fbc
Feed Name: Dragos Blog
In Q2 2026 Dragos recorded 1,140 ransomware incidents affecting industrial organizations (a 12% increase from Q1), with manufacturing most impacted and a small number of RaaS operations (notably Qilin, Akira, and The Gentlemen) accounting for the majority of claims; adversaries relied on internet-facing device exploitation, compromised credentials, social-engineering via collaboration platforms and RMM tools, and increasingly favored data-theft extortion over encryption—causing enterprise IT outages, precautionary OT shutdowns, and significant data exposure while law-enforcement takedowns and state-aligned false-flag activity complicated attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
