Ransomware Is Rising in Industrial Systems Even as Overall ICS Threats Fall

Ransomware is gaining ground in industrial control systems (ICS) even as the overall volume of threats in these environments keeps falling. Figures from Kaspersky ICS CERT for the second quarter of 2026 show the split clearly: the share of industrial devices where malicious objects were blocked fell to its lowest level since 2022, while ransomware attacks grew in almost every region studied.

The 20-second version

  • Kaspersky recorded a rise in industrial ransomware across most regions during Q2 2026.
  • Australia and New Zealand saw the sharpest quarterly jump, at 67%, followed by Southeast Asia at 50%.
  • Western Europe, Southern Europe, and Canada were the exceptions.
  • Biometrics was the most exposed sector, with detections on 26% of the ICS devices analyzed.

That split matters because of how operational technology (OT) works. An attack on an office computer can lock documents and applications. Compromising some industrial systems can reach production lines, machinery, and other physical processes.

It is also a reason to read overall security stats with care. Fewer total detections doesn’t automatically mean less risk, especially when attacks that can halt operations are on the rise.

Ransomware grows by up to 67% in some regions

The biggest swings between the first and second quarter of 2026 came in Australia and New Zealand, where the share of ICS devices hit by ransomware rose 67%.

Southeast Asia saw a 50% increase, South America 38%, and Africa and Central Asia 31%. The Middle East grew 11%.

These figures show the change from the previous quarter. They don’t mean that 67% of all industrial devices in Australia and New Zealand were hit by ransomware.

Look instead at the percentage of ICS computers actually affected, and the regions at the top are Africa, the Middle East, Central Asia and the South Caucasus, East Asia, Southern Europe, and South Asia.

Europe stands out on one point: Southern Europe is among the regions with the most attacked devices, yet it saw no ransomware growth over the previous quarter. Western Europe and Canada were the other exceptions to the upward trend.

The overall picture is uneven, but one trait shows up across much of the world: ransomware can still reach industrial networks even when other threat categories pull back.

OT networks face different problems than IT networks

Industrial security carries its own constraints, and they help explain why ransomware hurts so much here.

A normal information technology (IT) setup can update servers and applications during scheduled maintenance windows. In a factory, a power plant, or an industrial site, stopping certain equipment hits production directly.

So some systems stay in service for many years, and rolling out a security update means first checking that it won’t break the industrial equipment and applications around it.

The tighter link between IT and OT networks adds another layer.

Industrial systems aren’t necessarily isolated anymore. Remote maintenance, centralized monitoring, management services, and various business applications can all connect the two worlds.

Attackers don’t always need tools built specifically for industrial systems.

Kaspersky notes that ransomware crews increasingly rely on detection-evading techniques and legitimate administrative tools, which can pass for normal network activity.

The job for security teams becomes spotting when a tool an administrator uses every day is being turned against them.

That is one reason OT protection is moving from mostly blocking malware toward monitoring, behavior detection, segmentation, and incident response.

Biometrics is the most exposed sector

The study looks beyond ransomware too.

There, systems tied to biometrics again showed the highest share of ICS computers hit by malicious objects.

In Q2 2026, detections reached 26% of systems in this sector, slightly above the previous quarter.

Southern Europe topped that regional ranking, with malicious objects blocked on 33% of biometrics-related industrial systems. Africa and Central Asia came next.

Kaspersky links this exposure to common traits of these facilities: internet connectivity, heavy email use, and, in some cases, limited security controls.

The numbers also show how much the idea of industrial infrastructure has stretched.

Direct factory control systems now sit alongside connected sensors, biometric systems, Industrial Internet of Things (IIoT) devices, supervisory platforms, and plenty of devices swapping data with IT systems.

Every extra connection brings new capabilities, and more items to inventory, update, and monitor.

Patching, segmentation, and recovery matter more

One of the hardest parts of protecting these environments is balancing availability against security.

Applying every update the moment it lands may not be workable if it could disrupt an industrial process. Leaving vulnerable systems in place indefinitely isn’t a reasonable option either.

Kaspersky recommends regular security assessments of OT networks, ongoing vulnerability evaluation and prioritization, and patching when it is technically feasible.

When you can’t patch straight away, compensating measures can cut the exposure.

Getting ready for ransomware also means revisiting recovery plans. Backups on their own don’t guarantee a plant can get back up and running quickly.

Organizations need to understand system dependencies, segment networks properly, set incident containment procedures, and test that critical services actually come back.

Training IT and OT teams is another must. The two use different technologies and procedures, but an incident can jump from one to the other.

The Q2 2026 data leaves a warning for infrastructure and security leaders: total detections can fall while the kind of threat reaching industrial networks shifts.

Ransomware keeps finding room exactly where system availability is part of the organization’s physical operation. That is why protecting operational technology can no longer lean only on the metrics used for ordinary servers and workstations.

Frequently Asked Questions

Is ransomware against industrial systems on the rise?

Yes, according to Kaspersky ICS CERT. During Q2 2026, the share of ICS devices attacked by ransomware grew in most of the regions studied.

Which region saw the biggest growth in industrial ransomware?

Australia and New Zealand had the largest jump from the previous quarter, at 67%, followed by Southeast Asia at 50%.

What is the difference between IT and OT?

IT mostly covers systems for processing data, while OT covers technologies that watch over or control physical equipment and processes. In industrial companies, the two are increasingly linked.

Which sector had the most ICS devices affected by threats?

Biometrics led Kaspersky’s global ranking in the second quarter, with malicious objects blocked on 26% of the ICS devices analyzed.

Scroll to Top