// 1 CRITICAL · 3 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H
Dragos' Q2 2026 report records 1,140 ransomware incidents against industrial organizations. The key finding: production halts without ICS access, striking through enterprise IT — ERP, virtualization, identity, and remote access — while the IT/OT firewall holds firm.

Dragos' quarterly report, published August 11, 2026, records 1,140 ransomware incidents against industrial organizations in the second quarter, a 12% increase over the 1,020 logged in Q1. The story isn't the count; it's the mechanism. Most production stoppages stem from compromise of enterprise IT systems — ERP, virtualization, identity services, remote-access gateways — without attackers ever touching industrial controllers. Dragos calls it the "false comfort" of IT/OT segmentation: the firewall holds, yet the plant still grinds to a halt.

Key Takeaways
  • 1,140 ransomware incidents against industrial organizations in Q2 2026, up 12% from Q1; 65% hit manufacturing.
  • Compromise of ERP, virtualization, identity services, and remote-access gateways triggers cascading production shutdowns without direct ICS access.
  • Mackay Sugar, Australia's second-largest sugar producer, halted production on June 10, 2026; Dragos found no evidence of industrial control system access or OT manipulation.
  • Qilin is the most active group in the industrial sector with 140 claimed victims, followed by Akira (129) and The Gentlemen (125).

The Mechanism of Functional Dependency

Enterprise IT systems are no longer mere "neighbors" of OT. According to Dragos researchers Lexie Mooney and Abdulrahman H. Alamri, "platforms such as ERP, virtualization infrastructure, identity services, and remote access gateways represent high-value targets because their compromise can rapidly propagate into production stoppages and supply-chain impacts." This is functional dependency: industrial operators rely on ERP for production planning, virtualized HMI stations for process monitoring, Active Directory for access management, and VPNs for remote maintenance. When these pillars fall, the plant can no longer operate safely even if the PLCs remain untouched.

The Mackay Sugar case is emblematic. On June 10, 2026, the group suffered an attack that forced a production stoppage. Dragos analyzed the incident and found no evidence that attackers reached ICS systems or directly manipulated OT. The source does not establish with certainty whether the shutdown was caused directly by the attack or by post-intrusion containment measures. The outcome, however, is identical: days of downtime, operational costs, and broken supply contracts.

Q2 2026 by the Numbers: Manufacturing and North America on the Front Lines

Of the 1,140 total incidents, 747 — 65% — struck manufacturing. The geographic breakdown confirms a North American concentration: 514 incidents in North America (+34 vs. Q1), with the United States alone accounting for 38% of the global total (431 incidents). Europe recorded 316 cases (+64), with a particularly sharp rise in Germany: from 37 to 68 incidents, 76% of them in manufacturing.

The geography reflects industrial structure, but also reporting maturity. Dragos notes the data comes from "publicly disclosed victim data and posts made by ransomware groups on their data leak sites." This is not a count of unknown incidents, but a measure of public claims. The reporting bias is acknowledged, yet the quarter-over-quarter trend remains indicative of mounting pressure.

"The risk to industrial organizations is shaped less by new ICS-specific malware and more by adversary focus on the enterprise IT systems that sustain OT environments."

This quote from Dragos researchers crystallizes the paradigm shift. Ransomware doesn't need exotic firmware for Schneider or Siemens controllers. It needs compromised credentials, vulnerable VPNs, and enterprise collaboration platforms.

Tactics of the Three Most Active Groups

Qilin, Akira, and The Gentlemen claimed 140, 129, and 125 industrial victims respectively in Q2. Tactics overlap but don't coincide. Qilin leverages compromised credentials and vulnerable internet-facing infrastructure; this pattern is corroborated by a separately documented case in which a Qilin affiliate exploited CVE-2026-50751 (CVSS 9.3 CRITICAL, per NVD) on Check Point VPN devices via IKEv1. Akira focuses on compromised VPN devices, while The Gentlemen target edge devices.

The initial-access vector shows significant evolution. Social engineering was the most consistently reported initial-access theme of the quarter, but it has changed form: from email to "interactive impersonation on enterprise collaboration platforms," specifically Microsoft Teams. Attackers no longer send emails with malicious attachments; they enter chats, pose as colleagues, and demand immediate action. The collaboration platform thus becomes a direct attack vector, exploiting user familiarity with the interface.

Meanwhile, extortion is migrating from file encryption to data theft. Double extortion — publishing stolen data if the ransom isn't paid — is now standard, though the Dragos report does not quantify the success rate of this strategy.

What to Do Now

The Dragos report concludes with a precise operational principle: organizations must assume that "all internet-exposed assets are discoverable and actively targeted by adversaries, making continuous external attack surface management a necessity." Four priorities emerge from the data:

  • Map IT-to-OT dependencies: identify which enterprise IT systems (ERP, virtualization servers, domain controllers, VPN gateways) are single points of failure for OT operability; their unavailability must be treated as a production-interruption risk, not just a data-loss risk.
  • Extend monitoring to "functional bridges": ERP-to-OT connections for planning data flows, remote maintenance sessions, and operator authentications require visibility equivalent to that of industrial protocols.
  • Segment beyond the firewall: IT/OT segmentation reduces lateral-propagation risk but does not eliminate functional dependency; CISA has documented this principle in dedicated guidance and an infographic. Segmentation must be paired with resilience of the IT systems that feed operational decisions.
  • Revisit defenses against the Teams vector: interactive impersonation on collaboration platforms demands identity controls and out-of-band verification that go beyond visual username recognition.

The Perimeter Boundary Shifts Upward

The report's reading is unambiguous: the industrial security perimeter is no longer the controller network. It is the entire chain of systems that make plant operation possible, from ERP planning to remote maintenance. Investing in enterprise IT security — mature for decades in finance and tech — becomes directly and measurably productive for industrial operational continuity.

The Mackay Sugar case isn't an anomaly; it's a template. The attack was "ordinary" in the sense that it required no knowledge of Modbus or OPC-UA protocols. It required access to standard IT systems, sufficient to force a line stoppage. For companies that still treat the air gap or the IT/OT firewall as a silver bullet, Q2 2026 delivers a mandatory course correction.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. cisa.gov
  3. shopify.com
  4. cve.org