Ransomware surge targets Industrial Control Systems

Ransomware surge targets Industrial Control Systems

According to a new Kaspersky ICS CERT report, in the second quarter of 2026, the percentage of ICS computers on which malicious objects of various types were blocked continued to decline, reaching its lowest level since 2022. However, at the same time, the percentage of ICS computers targeted by ransomware increased across almost every region worldwide.

The top regions by the number of ICS computers attacked by ransomware were Africa, the Middle East, Central Asia and South Caucasus, East Asia, Southern Europe and South Asia. The most notable increases in the number of ICS machines attacked by ransomware fromQ1 to Q2 2026 were observed in Africa (a 31% increase), the Middle East (11%), Central Asia (31%), Southeast Asia (50%), South America (38%), and Australia and New Zealand (67%). The only exceptions to this rising trend were Western Europe, Southern Europe, and Canada.

“Ransomware remains a challenge for industrial enterprises, with its operational dynamics increasingly shifting toward highly evasion-prone tactics while exploiting legitimate administrative tools to blend in with normal network traffic. As we have previously mentioned, with legacy operational systems deeply embedded in critical infrastructure, a single localised failure can paralyse entire supply chains and trigger catastrophic physical shutoffs. While ransomware operators rely on these critical operational halts to leverage massive payouts, it is vital that targeted organisations refuse to pay the ransom and instead reinvest those resources into proactive, dedicated security solutions and robust containment procedures that protect their environments from future compromise,” comments Evgeny Goncharov, Head of Kaspersky ICS CERT.

In terms of all recorded threats (not just ransomware), the biometrics sector remained the most targeted industry globally, with malicious objects blocked on 26% of its ICS computers during the second quarter, which is slightly more than in the first quarter. Biometrics systems are characterised by the availability of internet access, extensive email use, and, in many cases, minimal cybersecurity controls within the organisations that use these systems. Regionally, Southern Europe led the ranking based on the percentage figures for biometrics, with malicious objects blocked on 33% of ICS computers, followed by Africa and Central Asia.

To keep OT computers protected from various threats, Kaspersky experts recommend:

  • Conducting regular security assessments of OT systems to identify and eliminate possible cybersecurity issues.
  • Establishing continuous vulnerability assessment and triage as a foundation for an effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
  • Performing timely updates to the key components of the enterprise’s OT network; applying security fixes and patches, or implementing compensating measures as soon as technically possible, is crucial for preventing a major incident that could cost millions due to the interruption of the production process.
  • Using EDR solutions such as Kaspersky Next EDR Expert for timely detection of sophisticated threats, investigation, and effective incident remediation.
  • Improving the response to new and advanced malicious techniques by building and strengthening teams’ skills in incident prevention, detection, and response. Dedicated OT security training for IT security staff and OT personnel is one of the key measures helping to achieve this.
  • To build proactive cyber defence, it is essential to track developments in the modern threat landscape and fix errors others made before they are exploited in your infrastructure. Kaspersky Threat Intelligence set of services is a unique source of insights into the evolution of threats and commonly exploited weaknesses, which we recommend for both strategic and tactical cybersecurity enhancements

 

SMB cyber readiness is the road to resilience

SMB cyber readiness is the road to resilience

Phil Muncaster, guest writer at ESET, alerts that your business may…
62% of developers now shape purchasing decisions

62% of developers now shape purchasing decisions

Tareq Masoud, Country Manager, UAE, Snowflake, explains how developers are…
Designing data sovereignty without slowing innovation

Designing data sovereignty without slowing innovation

Sivaprakash V S, Technical Evangelist at ManageEngine, explains that Middle East…
AMD to acquire Canadian startup Taalas

AMD to acquire Canadian startup Taalas

AMD has announced the acquisition of Canadian startup Taalas, a pioneer…
Batch 11 announced for Sanabil Accelerator by 500 Global

Batch 11 announced for Sanabil Accelerator by 500 Global

500 Global and Sanabil Investments announce the eleventh batch of the Sanabil Accelerator…
NanoClaw Creator Rejects $20M Buyout, Raises $12M Seed

NanoClaw Creator Rejects $20M Buyout, Raises $12M Seed

NanoCo, the startup behind the fast‑rising secure AI agent framework NanoClaw,…