Industrial ransomware is growing while ICS system threats decline

Ransomware is increasing its presence in industrial control systems (ICS) despite the overall volume of threats detected in these environments continuing to decline. Data from Kaspersky ICS CERT for the second quarter of 2026 shows this uneven trend: the total percentage of industrial devices where malicious objects were blocked dropped to its lowest level since 2022, while ransomware attacks grew in nearly all regions analyzed.

Key facts about ransomware in industrial systems in 20 seconds

  • Kaspersky detected an increase of industrial ransomware in most regions during Q2 2026.
  • Australia and New Zealand experienced the highest quarterly growth, at 67%, followed by Southeast Asia with 50%.
  • Western Europe, Southern Europe, and Canada were the exceptions.
  • Biometrics was the sector with the highest overall exposure to threats, with detections in 26% of the analyzed ICS devices.

This evolution is particularly significant given the characteristics of operational technology (OT). An attack on a corporate computer can lock documents and applications, but compromising certain industrial systems can end up affecting production lines, machinery, and other physical processes.

It also prompts cautious interpretation of overall cybersecurity statistics. A reduction in the total number of threats detected does not necessarily mean a corresponding decrease in risk, especially when the presence of attacks capable of causing operational disruptions increases.

Ransomware grows by up to 67% in some regions

The largest variations between the first and second quarter of 2026 occurred in Australia and New Zealand, where the proportion of ICS devices attacked by ransomware increased by 67%.

Southeast Asia saw a 50% increase, South America 38%, while Africa and Central Asia reached 31%. The Middle East experienced an 11% growth.

These percentages reflect the change compared to the previous quarter. They do not mean, for example, that 67% of all industrial devices in Australia and New Zealand were affected by ransomware.

When analyzing the percentage of affected ICS computers instead of quarterly growth, the regions appearing at the top are Africa, the Middle East, Central Asia and South Caucasus, East Asia, Southern Europe, and South Asia.

A notable point about Europe: Southern Europe ranks among the regions with the highest proportion of attacked devices but did not see ransomware growth compared to the previous quarter. Western Europe and Canada were the other exceptions to the upward trend.

Overall, the data reveals a heterogeneous landscape, but with a common characteristic in much of the world: ransomware still has the capacity to reach industrial networks even when other threat categories retreat.

OT networks face different challenges than IT networks

Industrial security has unique challenges that help explain why ransomware is especially problematic.

A conventional information technology (IT) infrastructure can update servers and applications during scheduled maintenance windows. In a factory, power plant, or industrial site, stopping certain equipment can directly impact production.

This results in some systems remaining operational for many years, and applying security updates requires beforehand verifying compatibility with industrial equipment and applications.

The increasing connection between IT and OT networks adds another difficulty.

Industrial systems are no longer necessarily isolated. Remote maintenance, centralized monitoring, management services, and various enterprise applications can create links between the two environments.

Attackers do not always need to use specially developed tools for industrial systems.

Kaspersky highlights that ransomware operations are increasingly using detection-evading techniques and legitimate administrative tools, which can be mistaken for normal network activity.

The challenge for security teams is then to identify when a tool commonly used by an administrator is being exploited by an attacker.

This is one reason why OT protection is evolving from a primarily malware-blocking approach to one that includes monitoring, behavior detection, segmentation, and incident response.

Biometrics is the most exposed sector

The study also considers threats beyond ransomware.

Within that scope, systems related to biometrics again had the highest percentage of ICS computers affected by malicious objects.

In Q2 2026, detections occurred in 26% of systems in this sector, slightly above the previous quarter.

Southern Europe led this regional ranking, with malicious objects blocked in 33% of biometric-related industrial systems. Africa and Central Asia followed.

Kaspersky correlates this exposure with typical features of these facilities, including internet connectivity, significant email usage, and, in some cases, limited security controls.

This data also illustrates how the traditional concept of industrial infrastructure has expanded.

Connected sensors, biometric systems, Industrial Internet of Things (IIoT) devices, supervisory platforms, and numerous devices exchanging information with IT systems have been added to direct factory control systems.

Each additional connection offers new operational capabilities but also increases the items that must be inventoried, updated, and monitored.

Patches, segmentation, and recovery gain importance

One of the challenges in protecting these environments is balancing availability and security.

Applying each update immediately may be unfeasible if it risks disrupting an industrial process. Indefinitely maintaining vulnerable systems is also not a reasonable alternative.

Kaspersky recommends periodic security assessments of OT networks, continuous vulnerability evaluation and prioritization processes, and applying patches when technically feasible.

When immediate patching isn’t possible, compensatory measures can be used to reduce exposure.

Preparing for ransomware also requires reviewing recovery plans. Having backups alone does not guarantee that a plant can quickly restore operations.

Organizations need to understand system dependencies, properly segment networks, establish incident containment procedures, and test that critical services can be restored.

Training IT and OT teams is another essential element. Both use different technologies and procedures, but an incident can transfer from one to the other.

Data from Q2 2026 leaves a warning for infrastructure and cybersecurity leaders: the total number of detections may decrease while the nature of threats reaching industrial networks changes.

Ransomware continues to find space precisely in environments where system availability is part of the organization’s physical operation. This difference means that protecting operational technology can no longer rely solely on metrics used for traditional servers and workstations.

Frequently Asked Questions

Is ransomware against industrial systems increasing?

Yes, according to Kaspersky ICS CERT. During Q2 2026, the proportion of ICS devices attacked by ransomware increased in most analyzed regions.

Which region saw the largest growth in industrial ransomware?

Australia and New Zealand experienced the highest increase from the previous quarter, with 67%, followed by Southeast Asia with 50%.

What is the difference between IT and OT?

IT mainly involves systems dedicated to data processing, while OT includes technologies that oversee or control physical equipment and processes. In industrial companies, these environments are increasingly interconnected.

Which sector had the most ICS devices affected by threats?

The biometric sector led Kaspersky’s global ranking during the second quarter, with malicious objects blocked in 26% of analyzed ICS devices.

Scroll to Top