started · updated
Kaspersky reports rise in ransomware attacks on Industrial Control Systems
A new report from Kaspersky ICS CERT reveals that ransomware attacks targeting Industrial Control Systems (ICS) increased globally during the second quarter of 2026. While the rate of blocked malicious objects in ICS computers has dropped to its lowest level since 2022, the proportion of ICS computers targeted by ransomware has risen significantly across most regions.
Notable increases in ransomware-targeted ICS computers between the first and second quarters of 2026 include Australia and New Zealand (67%), Southeast Asia (50%), South America (38%), Africa (31%), Central Asia (31%), and the Middle East (11%). The only exceptions to this rising trend were Western Europe, Southern Europe, and Canada.
Evgeny Goncharov, head of Kaspersky ICS CERT, noted that ransomware remains a persistent threat to industrial organizations. He highlighted that attackers are increasingly using legitimate management tools to blend in with normal network traffic, making detection more difficult. Goncharov warned that because legacy operational systems are deeply integrated into critical infrastructure, a single point of failure can paralyze entire supply chains and cause serious physical disruptions.