In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1. Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms, and virtualization infrastructure, versus direct manipulation of control systems.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft, and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact. The extortion model continued its shift from encryption toward data theft-only operations. Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualization systems on which OT depends.
Dragos assesses with high confidence that ransomware will continue to impact industrial organizations globally, and that these intrusions can cascade into OT environments, producing operational downtime, precautionary shutdowns, loss of view, and safety risk even without any ICS-native capability. By examining victimology, sector concentration, observed TTPs, and real-world operational impacts, Dragos provides defenders with insight into the evolving ransomware threat to industrial organizations.
- Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, an 12% increase over the 1,020 recorded in Q1.
- Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors
- ICS-related organizations (engineering firms, system integrators, and equipment manufacturers) accounted for the second-most-impacted sector, with 117 incidents, reflecting persistent industrial supply chain exposure.
- Transportation and logistics ranked third with 95 incidents.
- North America and Europe remained the most affected regions. The U.S. consistently ranks as the most impacted country by ransomware by a far margin (431 incidents in Q2, or 38% of all incidents). However, the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany.
- Similar to previous quarters, a small number of ransomware groups accounted for a disproportionate share of activity, with Qilin, Akira, and The Gentlemen responsible for the largest victim volumes in Q2.
- The extortion model continued to shift away from encryption toward data theft-only operations, and geopolitically influenced activity, including state-aligned actors operating behind ransomware branding, persisted throughout the quarter.
Established and Emerging Groups
This quarter’s ransomware activity against industrial organizations remained concentrated among a small number of established RaaS operations, even as the broader ecosystem continued to shift, with new brands emerging and disappearing between reporting periods.
Qilin
Qilin remained the most active ransomware brand targeting industrial organizations, a position it has held since March 2025. Its continued prominence reflects the scale of its affiliate network and its ability to leverage multiple access vectors rather than any single technical innovation. Affiliates primarily gained access via internet-facing infrastructure, including Palo Alto appliances, by exploiting a Check Point Remote Access VPN authentication-bypass vulnerability and compromised credentials. Post-compromise activity frequently involved disabling endpoint security tools and harvesting credentials stored in browsers before ransomware deployment. Microsoft’s disruption of the Fox Tempest malware-signing service removed one component of the affiliate ecosystem during the quarter but had little visible impact on Qilin’s overall activity, highlighting the operational flexibility of large, well-established affiliate networks.
Akira
Akira placed second among established operations, maintaining its focus on manufacturing and industrial services across North America and Europe. The group continued to rely on compromised VPN devices for initial access and exfiltrated data through legitimate file-sharing services, and in at least one case, accessed a hypervisor within the victim’s environment and created a new server instance, using this new virtual machine to stage and launch the Akira ransomware. A forensic reconstruction of an Akira intrusion published during the quarter confirmed the group’s characteristic operating pattern: entry through a legacy VPN account without multi-factor authentication, followed by several days of quiet credential theft and backup destruction, all before encryption was ever deployed. That dwell time is the operationally significant detail, since it is also the window in which the intrusion is most detectable and most recoverable, well before any ransom note appears.
The Gentlemen
The Gentlemen provided one of the rare opportunities to examine the inner workings of a ransomware operation. The leak of the group’s Rocket database in early May 2026, later analyzed by Check Point, revealed an operation established around mid-2025 and overseen by an actor known as zeta88, who reportedly manages both the affiliate platform and intrusion activity. The leaked records exposed the group’s revenue-sharing model and showed a practice of repurposing data stolen from one victim to facilitate compromises of related organizations, effectively using each intrusion as a source of intelligence for future operations. Initial access consistently targeted Fortinet FortiGate and Cisco edge devices, followed by a repeatable sequence of Active Directory reconnaissance, certificate abuse, and EDR evasion. The group’s ransomware supports Windows, Linux, NAS, BSD, and ESXi environments. The disclosure offered an unusually detailed view of the operational and financial structure of a rapidly growing RaaS enterprise at a time when the group was expanding its victim base.
DragonForce
DragonForce’s activity during the quarter was notable for its use of new tradecraft. One affiliate deployed Backdoor.Turn, a custom Go-based remote access trojan, which was identified as the first known malware to misuse Microsoft Teams’ TURN relay infrastructure for command-and-control communications. By routing malicious traffic through widely trusted collaboration services, the technique reduced the likelihood of detection in many enterprise environments. The same affiliate also exploited a zero-day vulnerability in a Huawei driver, while the group continued exploiting SimpleHelp vulnerabilities to gain access to managed service providers and, in some cases, their downstream customers. Together, these activities suggest a deliberate focus on developing and adopting new intrusion and evasion techniques rather than relying solely on established ransomware playbooks.
Geopolitics shapes industrial ransomware less through the professed ideology of individual operators than through the geography of enforcement and the alignment of victims. The largest ransomware ecosystems continue to operate in jurisdictions where enforcement against actors targeting foreign entities is minimal or politically constrained, and victim distribution skews toward regions with adversarial relations with an affiliate’s home country. Two dynamics observed in Q2 2026 further complicate this picture. The first is the use of criminal ransomware branding as cover for state-aligned operations, and the second is the appropriation of ransomware and OT attack imagery by hacktivist personas for propaganda.
Chaos Ransomware
Beyond the major ransomware brands, one notable development during the quarter involved Chaos ransomware. Activity attributed to Chaos diverged into two distinct operations during Q2. The first was a conventional, financially motivated RaaS operation targeting sectors including construction, oil and gas, and manufacturing across North America. The second was a state-sponsored espionage campaign in which MuddyWater, an adversary linked to Iran’s Ministry of Intelligence and Security (MOIS) by the U.S. government, used the Chaos branding as a cover for credential theft and persistence activities unrelated to extortion. The overlap illustrates how ransomware branding can obscure very different adversaries and objectives, complicating attribution and threat assessment.
In May 2026, researchers reassessed an intrusion that had initially appeared to be a routine Chaos ransomware attack, concluding it was likely the work of MuddyWater. Rather than deploying an encryptor, the adversary used Microsoft Teams social engineering to harvest credentials, then pursued data exfiltration, account takeover, and persistence through legitimate remote access tooling before attempting extortion in the style of a data theft-only attack. The absence of encryption, the emphasis on durable access, and technical overlaps with known MuddyWater infrastructure were the indicators that separated strategic intelligence collection from financially motivated crime. The case reflects a broader convergence of state-sponsored espionage and criminal tradecraft, in which the ransomware ecosystem supplies plausible deniability and raises the risk that espionage operations are misclassified as routine extortion.
Data Theft by Stormous
The convergence of hacktivist framing and financially motivated extortion advanced over the quarter. Stormous, a group with a longstanding hacktivist streak, expanded from a single industrial claim in Q1 to 15 in Q2 and continued to list manufacturing victims across multiple regions, including a Mexican pharmaceutical manufacturer and the Consumer Goods Council of South Africa. This blending of ideological presentation with extortion procedures tracks the broader market shift toward data theft-only operations, in which leverage comes from publication rather than encryption.
Encryption-less extortion, exemplified by World Leaks and identified in third-party reporting as a primary emerging model, lowers the technical barrier to claiming an industrial victim and raises the propaganda value of a breach, since a DLS posting and a sample dump can manufacture the appearance of impact, whether or not any operational disruption occurred.
Social engineering was the most consistently reported initial access theme of the quarter and shifted from email to interactive impersonation on enterprise collaboration platforms. Multiple groups gained access by contacting employees via Microsoft Teams, posing as internal IT support, then guiding the target through a screen-sharing session to install a Remote Monitoring and Management (RMM) tool, such as AnyDesk/QuickAssist, or to execute a delivered payload. Some adversaries lend legitimacy to the situation by supplying the victim with organization-tailored credential-harvesting domains to capture credentials, SSO credentials, and MFA codes in real time during the attack. Domains and phishing infrastructure reported in open-source closely follow the victim organization’s naming conventions and use deceptive formats. The Payouts King initial access broker paired this Teams pretext with a forged software-update console to deploy the Edgecution browser backdoor, and the state-aligned MuddyWater used the same Teams approach to harvest credentials while operating under the Chaos ransomware brand.
Voice phishing extended the pattern and, in the most aggressive cases, crossed into the physical world. The FBI warned in a late-May FLASH alert that the Silent Ransom Group, also tracked in open-source as Luna Moth and UNC3753, had escalated its campaign against professional-services firms to include operatives visiting offices in person while posing as IT technicians, inserting USB drives, and accessing machines directly. Mandiant documented the same adversary completing the sequence from initial contact to data theft within a single business day, with staging observed in under an hour. These methods deploy no malware at the access stage and leave few host artifacts, so detection depends on monitoring for anomalous use of legitimate remote access tools, unexpected screen-sharing sessions, and out-of-policy removable media events rather than on endpoint signatures.
RMM tooling served as both an access and a persistence mechanism. DragonForce continued to exploit SimpleHelp vulnerabilities to reach managed service providers and their downstream customers, and several groups installed commodity remote monitoring and management tools during social engineering sessions rather than deploying custom malware. Reporting on the WantToCry operation documented remote encryption of exposed SMB services with no local payload at all, a technique of particular concern to the legacy file-sharing infrastructure common in engineering and OT-adjacent environments. Across these cases, the common exposure is the internet-facing management surface, including VPN concentrators, appliance management interfaces, and remote access services reachable from the public internet.
Law enforcement sustained pressure on ransomware infrastructure throughout the quarter, though the disruptions degraded operational enablement rather than reducing incident volume. An international operation dismantled the First VPN anonymization service used across cybercrime investigations, seizing 33 servers across 27 countries and identifying thousands of users. A major phase of Operation Endgame, between 15 and 24 June, disrupted the SocGholish, Amadey, and StealC families that supply initial access and stolen credentials to ransomware operators, taking down hundreds of servers and recovering tens of millions of stolen credentials.
Financial and attribution pressure accompanied the infrastructure takedowns as the U.S. Treasury sanctioned Nobitex, Iran’s largest cryptocurrency exchange, and three other Iranian platforms for processing payments tied to IRGC-affiliated ransomware actors. The UK Metropolitan Police assessed that successive takedowns are fragmenting the ecosystem, pushing operators out of centralized affiliate platforms into smaller peer-to-peer factions. This fragmentation likely does not reduce the structural risk to industrial organizations, since smaller operators generate less observable pre-attack infrastructure and operate with shorter dwell times, and capability-based and behavior-based detection provides more durable coverage than tracking any single brand.
Ransomware disrupted industrial operations across multiple sectors and regions in Q2 2026 through two distinct pathways. In the first, encryption or precautionary isolation of enterprise and virtualization systems forced production stoppages at manufacturers and processors without any direct manipulation of control systems. In the second, data theft-only extortion imposed no operational downtime but exposed customers, suppliers, and partners through leaked schematics, specifications, and credentials.
West Pharmaceutical Services
Date: May 2026
Impact: Precautionary global shutdown and isolation of on-premises infrastructure; shipping, receiving, and manufacturing disrupted across multiple international sites, with core systems restored by 14 May.
Overview: West Pharmaceutical Services manufactures injectable drug packaging and delivery systems for pharmaceutical and biotech firms worldwide. On 04 May 2026, the company disclosed a ransomware attack that prompted a precautionary global shutdown and isolation of the affected on-premise infrastructure. West confirmed a double-extortion incident in which data was exfiltrated before a file-encrypting payload was deployed, and reported disruptions to shipping, receiving, and manufacturing across multiple international sites. By 14 May, it reported that core enterprise systems had been restored and that critical manufacturing and logistics processes were restarting at some sites, with no full restoration timeline set and no group having claimed responsibility. West is the quarter’s clearest case of a critical manufacturer taking an enterprise-wide precautionary shutdown to contain an IT-side intrusion, halting production without any control system compromise.
Foxconn
Date: May 2026
Impact: Roughly two weeks of disrupted production across North American operations (Mount Pleasant, Wisconsin, and Texas); Nitrogen claimed approximately 8 TB and over 11 million files, including technical drawings, project documentation, and network-topology data for major technology clients.
Overview: Foxconn confirmed on 12 May that its Wisconsin and Texas facilities were affected, with the Mount Pleasant complex experiencing a full network outage from 01 May, production systems taken offline, and staff moved to paper-based timekeeping for approximately two weeks before public confirmation. Nitrogen claimed exfiltration of technical drawings, internal project documentation, and network topology data for major technology clients.
Mackay Sugar
Date: June 2026
Impact: Milling and cane haulage halted at the Farleigh and Racecourse mills days into the 2026 crushing season; the third mill, Marian, had not started its season and was unaffected.
Overview: Mackay Sugar, Australia’s second-largest raw sugar producer, disclosed a cybersecurity incident on 10 June that forced the shutdown of milling and cane haulage at two of its three Queensland mills. By 12 June, it had resumed limited manual crushing at one mill to process cane harvested before the incident. The Gentlemen claimed responsibility on 15 June by listing Mackay Sugar on its Tor leak site with an approximately ten day countdown. Dragos assesses with low confidence, based on the leak site claim and the disruption pattern, that this incident primarily affected enterprise IT, with milling halted either by direct disruption or as a precautionary containment measure. Dragos has observed no evidence that the actor reached ICS or directly manipulated OT, and whether OT was affected as a downstream consequence of IT systems being taken offline remains unclear.
In Q2 2026, ransomware activity impacting industrial organizations remained steady across all regions, reinforcing the global and persistent nature of the threat. Manufacturing, construction, and engineering continued to be targeted worldwide. North America remained the most impacted region by a wide margin, while Europe and Asia also saw increased activity compared to Q1. Dragos noted an increase across most regions in Q2, with the exception of the Middle East and Africa, which saw slight decreases.
Regional Distribution
North America: Recorded 514 incidents in Q2 2026 (up from 480 recorded in Q1 2026), maintaining its position as the most impacted region. Activity was driven by sustained targeting of industrial organizations across manufacturing, construction, engineering, transportation, and government sectors.
Europe: Reported 316 incidents (up from 252 in Q1), remaining the second-most impacted region. The country with the greatest overall increase in Q2 was Germany, with 68 alleged ransomware incidents (37 recorded in Q1), making it the second-most-impacted country after the U.S. 76% of the organizations claimed by ransomware operators in Germany were in the manufacturing sector.
Asia: Documented 172 incidents, showing a steady increase since Q4 2025 and into 2026. Taiwan and Thailand led this region in incident volume. Ransomware activity in this region primarily impacted manufacturing, transportation, and engineering organizations.
South America: Experienced 64 incidents. Organizations in Brazil and Argentina accounted for half of the ransomware activity against this region.
The Middle East: Recorded 44 incidents primarily affecting the manufacturing and energy sectors.
The ANZ region: Observed 19 incidents, exactly the same as Q1, primarily impacting manufacturing and logistics organizations.
Africa: Recorded 11 incidents. While reporting volume remained limited with no focused targeting, the presence of industrial victims across multiple countries reflects continued opportunistic targeting of emerging markets.
Ransomware activity in Q2 2026 continued to significantly impact industrial organizations, reinforcing adversaries’ sustained focus on sectors with tight operational dependencies and low tolerance for downtime. Manufacturing remained the most heavily targeted sector by a wide margin, while transportation and ICS equipment and engineering providers continued to experience persistent activity, ranking as the second- and third-most-impacted sectors, respectively. Energy-related sectors, including Oil and Gas and electric utilities/renewables, also remained consistently targeted throughout the quarter.
Manufacturing
Manufacturing was the most heavily impacted sector in Q2 2026, with 747 claimed victim organizations spanning a wide range of subsectors. Suppliers of building materials, construction services, and equipment were repeatedly targeted, consistent with their reliance on ERP systems, distributed locations, and tight project timelines.
Breakdown of Top Manufacturing Subsectors:
· Construction: 176 incidents
· Equipment: 114 incidents
· Food and Beverage: 70 incidents
Industrial Control System (ICS) Ecosystem
Organizations directly supporting OT environments, including engineering services, integrators, and ICS equipment manufacturers, experienced 117 ransomware incidents in Q2 2026.
Breakdown of ICS Subsectors:
- ICS Equipment: 27 incidents
- ICS Engineering: 90 incidents
Transportation and Logistics
These organizations remain attractive targets due to their dependence on scheduling platforms, reservation systems, fleet management software, and time-sensitive operations. Disruption in these sectors often creates immediate cascading effects well beyond the victim organization itself. Within the 95 transportation-related incidents observed in Q2, activity was distributed across the following subsectors.
Breakdown of Transportation Subsectors:
- Logistics: 78 incidents
- Maritime: 8 incidents
- Aviation: 6 incidents
- Rail: 3 incidents
Government, Energy, and Utilities
Government entities accounted for 64, largely at the municipal and regional level.
Electric utilities (8 incidents) and water utilities (4 incidents) continued to appear in ransomware victim disclosures, although at lower volumes than manufacturing and transportation.
Oil and Natural Gas (ONG) experienced 45 incidents, demonstrating persistent targeting of upstream, midstream, and downstream energy organizations and the service providers that support them.
Renewable energy organizations (12 incidents) and mining organizations (15 incidents) were also impacted, indicating continued adversary interest in energy production and resource extraction environments.
Dragos’ analysis of Q2 2026 activity shows continued concentration among a small number of established RaaS operations, alongside persistent turnover among smaller and newly appearing brands. The three most active groups (Qilin, Akira, and The Gentlemen) finished within 15 claims of one another, and no single operation dominated the quarter as Qilin had in Q1. Qilin and Akira have consistently ranked as the top operations impacting industrial organizations over the last year.
Several dominant groups expanded their operational tempo during the quarter, while many emerging or rebranded identities remained low-volume and operationally limited:
- Qilin: 140 claims (198 in Q1). Remained the most active operation impacting industrial organizations despite a decline in volume, with continued exploitation of internet-facing infrastructure and persistent targeting of manufacturing and supply-chain-dependent environments.
- Akira: 129 claims (100 in Q1). Second-most active, with consistent targeting of manufacturing and industrial services across North America and Europe.
- The Gentlemen: 125 claims (83 in Q1). Largest gain among the established groups; an internal data leak in May exposed the operation’s structure and tooling.
- DragonForce: 76 claims (45 in Q1). Introduced Microsoft Teams TURN-relay command-and-control concealment via Backdoor.Turn.
- LockBit 5.0: 62 claims (71 in Q1). Sustained volume following prior law enforcement disruption.
- Inc Ransom: 50 claims (52 in Q1). Broad targeting across manufacturing, ICS engineering and equipment, and government.
- Deadlock: 45 claims (new in Q2). 33 claims were posted in a single week; the figure reflects a bulk disclosure rather than sustained activity.
- Safepay: 36 claims (19 in Q1).
- Coinbase Cartel: 30 claims (25 in Q1).
- Ralord: 26 claims (6 in Q1).
- Lamashtu: 22 claims (new in Q2).
- Play: 22 claims (53 in Q1), a significant decline.
- Krybit: 20 claims (new in Q2).
- Chaos: 17 claims (4 in Q1). A portion of Chaos-branded activity has been attributed to a state-aligned false-flag operation; see Ransomware Driven by Geopolitical Events.
- World Leaks: 17 claims (8 in Q1).
- CMD Organization: 14 claims (new in Q2). Operates an auction-based extortion model.
- Additional new entrants: Aurora (13), Settra (13), Bavacai (12), M3Rx (10), and 3AM (9), each from no Q1 industrial claims.
- Notable declines and exits: Nightspire (41 to 16) and Sinobi (34 to 2) declined sharply, while Clop (23 to 0) and Tengu (16 to 0) recorded no industrial claims in Q2. Since 2023, Cl0p’s activity has been known to fluctuate, as the group now focuses more on encryption-less extortion campaigns targeting newly disclosed vulnerabilities for data theft.
As illustrated in Figure 6, ransomware activity continues to consolidate, with Qilin leading the charge against industrial organizations over the last year. This reinforces the assessment that ransomware activity in the industrial sector continues to be driven primarily by a small number of reliable, affiliate-supported RaaS operations, rather than by broad ecosystem fragmentation or brand proliferation.
Risk to industrial organizations is being shaped less by novel ICS-specific malware and more by adversaries’ deepening focus on the enterprise IT systems that underpin OT environments. Platforms such as ERP systems, virtualization infrastructure, identity services, and remote access gateways represent high-value targets precisely because disrupting them can rapidly cascade into production shutdowns and supply chain impacts. Internet-facing edge devices and remote management tooling remained the dominant technical entry point into industrial and industrial-adjacent networks in Q2 2026. Organizations should assume that all internet-facing assets are discoverable and actively sought by adversaries, making continuous external attack surface management a necessity. The consistent abuse of compromised credentials and remote management tools, including SimpleHelp, AnyDesk, and QuickAssist, underscores the importance of credential hygiene, MFA enforcement, and strict tooling policies.
References:
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) – Check Point
Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf
Exposing Fox Tempest: A Malware-Signing Service Operation – Microsoft
Akira, LimeWire, and the Sour Taste of Data Exfiltration – Huntress
The Gentleman – Check Point
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden – Symantec
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware – RAPID7
World Leaks – Halcyon
Help on the line: How a Microsoft Teams Support Call Led to Compromise – Microsoft
Welcome to BlackFile: Inside a Vishing Extortion Operation – Mandiant
Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware – Zscaler
Silent Ransom Group Impersonating IT Personnel through Social Engineering – FBI
Seeking Counsel: Ongoing Targeted Campaign Against U.S. Law Firms – Mandiant
The Ruthless Rise of the Gentleman Ransomware – Unit42
How DragonForce Weaponized Legitimate Software – Halcyon
WantToCry Ransomware Remotely Encrypts Files – Sophos
Cybercriminal VPN Dismantled in Global Crackdown – Europol
Operation Endgame – Europol
Economic Fury Targets Iran’s Largest Digital Asset Exchange for Terror Finance and Sanctions Evasion – U.S. Department of the Treasury
Company Alert – West Pharmaceutical Services
Ransomware Attacks on West Pharmaceutical and Foxconn Highlight Growing Cyber Risks to Manufacturing Sector – Industrial Cyber
Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer – SecurityWeek