SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Industrial ransomware hits 1,140 incidents in Q2 2026

Industrial ransomware hits 1,140 incidents in Q2 2026

Wed, 12th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Dragos has published its industrial ransomware analysis for the second quarter of 2026, recording 1,140 incidents affecting industrial organisations worldwide.

That was up 12% from 1,020 incidents in the previous quarter and continued the high level of ransomware activity seen throughout 2025. Manufacturing was again the hardest-hit sector, with 747 incidents, or 65% of the total identified by the OT cybersecurity company.

Organisations that support industrial control system environments, including engineering firms, system integrators, and equipment manufacturers, recorded 117 incidents during the quarter. Transportation and logistics groups accounted for another 95 cases.

Australia and New Zealand saw 19 industrial ransomware incidents in the period, unchanged from the first quarter. Most affected manufacturing and logistics organisations.

Operational risk

The analysis points to a pattern in which operational disruption stems not from direct interference with industrial control systems, but from attacks on the connected IT systems industrial sites rely on. Dragos observed no ransomware operator directly manipulating an industrial control system during the quarter.

Instead, disruption usually followed the encryption of enterprise IT systems or precautionary shutdowns of virtualisation and related infrastructure. In many industrial environments, production depends on enterprise software and services such as ERP systems, identity services, and remote-access tools. That makes those systems a route to operational disruption even when attackers do not reach operational technology.

One example came in Australia, where a cyber incident forced Mackay Sugar to stop milling and cane haulage at two of its three Queensland mills shortly after the start of the 2026 crushing season. The company later appeared on the leak site of ransomware group The Gentlemen.

Dragos found no evidence that attackers reached industrial control systems or directly manipulated operational technology in that incident. It remains unclear whether operational technology was affected indirectly after IT systems were taken offline.

Changing tactics

Attackers continued to exploit internet-facing infrastructure, compromised VPN devices, and stolen credentials during the quarter. The analysis also found growing use of social engineering and legitimate remote-management tools to gain access to targets.

According to the findings, that social engineering has shifted away from conventional email lures towards interactive impersonation. Dragos observed several groups contacting employees through Microsoft Teams while posing as internal IT support staff and persuading them to install remote monitoring and management tools or run malicious payloads.

The most active ransomware operation targeting industrial organisations in the quarter was Qilin, with 140 claims. Akira followed with 129, while The Gentlemen recorded 125.

Together, those three groups represented a large share of the ransomware activity tracked across industrial organisations. Their prominence underlines how a relatively small number of operators can have an outsized impact across sectors that depend on continuous operations.

Extortion model

Dragos also reported a further shift away from traditional file encryption towards data-theft-only extortion. Under that model, attackers steal sensitive information and threaten to publish it rather than focusing solely on locking systems.

For industrial organisations, that creates a different kind of risk. Even when operations continue without interruption, stolen material can include engineering documents, technical specifications, network information, and credentials, exposing both the victim and parts of its supply chain.

The findings suggest ransomware now poses a broader business threat to industrial companies than system downtime alone. Theft of sensitive data can create pressure on operators, contractors, and suppliers, particularly where industrial processes depend on shared technical information and trusted access across multiple organisations.

Industrial exposure

The report highlights how closely linked IT and OT environments have become in modern industrial settings. As companies have connected production environments to enterprise systems for planning, maintenance, identity management, and remote support, they have also widened the paths through which cyber incidents can disrupt physical operations.

That means attackers do not need deep expertise in industrial control systems to cause real-world effects. A compromise of core business systems can still trigger downtime, precautionary shutdowns, loss of visibility, and safety concerns if operators cannot rely on connected digital services.

For manufacturers, logistics operators, and industrial service providers, the figures are another sign that ransomware remains a persistent operational issue rather than a purely IT matter. The concentration of incidents in manufacturing also shows that cyber criminals continue to focus on sectors where downtime can quickly translate into commercial pressure.

Dragos warned that ransomware attacks on industrial organisations are likely to continue globally and that incidents can cascade into OT environments even when attackers lack specialised industrial control system expertise.