According to a new Kaspersky ICS CERT report, in the second quarter of 2026 the total percentage of ICS computers on which malicious objects of different types were blocked continued to decrease, reaching its lowest level since 2022. However, at the same time, the percentage of ICS computers targeted by ransomware increased across almost every region worldwide.
The top regions by the number of ICS computers attacked by ransomware were Africa, the Middle East, Central Asia and South Caucasus, East Asia, Southern Europe and South Asia. The most notable increases in the number of ICS machines attacked by ransomware from Q1 to Q2 2026 were observed in Africa (a 31% increase from Q1 to Q2), the Middle East (11%), Central Asia (31%), Southeast Asia (50%), South America (38%), and Australia and New Zealand (67%). The only exceptions to this rising trend were Western Europe, Southern Europe, and Canada.
“Ransomware remains a challenge for industrial enterprises, with its operational dynamics increasingly shifting toward highly evasion-prone tactics while exploiting legitimate administrative tools to blend in with normal network traffic. As we have previously mentioned, with legacy operational systems deeply embedded in critical infrastructure, a single localized failure can paralyze entire supply chains and trigger catastrophic physical shutoffs. While ransomware operators rely on these critical operational halts to leverage massive payouts, it is vital that targeted organizations refuse to pay the ransom and instead reinvest those resources into proactive, dedicated security solutions and robust containment procedures that protect their environments from future compromise,” comments Evgeny Goncharov, Head of Kaspersky ICS CERT.
In terms of all recorded threats (not just ransomware), the biometrics sector remained the most targeted industry globally, with malicious objects blocked on 26% of its ICS computers during the second quarter, which is slightly more than in the first quarter. Biometrics systems are characterized by the availability of internet access, extensive email use, and, in many cases, minimal cybersecurity controls within the organizations that use these systems. Regionally, Southern Europe led the ranking based on the percentage figures for biometrics, with malicious objects blocked on 33% of ICS computers, followed by Africa and Central Asia.
Full information is available in the report on Kaspersky ICS CERT website.
To keep OT computers protected from various threats, Kaspersky experts recommend:
- Conducting regular security assessments of OT systems to identify and eliminate possible cyber security issues.
- Establishing continuous vulnerability assessment and triage as a foundation for effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
- Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.
- Using EDR solutions such as Kaspersky Next EDR Expert for timely detection of sophisticated threats, investigation, and effective remediation of incidents.
- Improving the response to new and advanced malicious techniques by building and strengthening teams’ skills in incident prevention, detection, and response. Dedicated OT security trainings for IT security staff and OT personnel is one of the key measures helping to achieve this.
- For building proactive cyber defense it is essential to keep track of the modern threat landscape developments and fixing errors the others made before they are exploited in your infrastructure. Kaspersky Threat Intelligence set of services is a unique source of incites of the evolution of threats and commonly exploited weaknesses we recommend for both strategical and tactical cybersecurity enhancements
About Kaspersky ICS CERT
Kaspersky ICS CERT is primarily focused on identifying and addressing potential and existing threats to industrial automation systems and the Industrial Internet of Things (IloT). The team has successfully identified and helped eliminate hundreds of vulnerabilities in widely used OT/IoT products and key components, enhancing the security and resilience of these critical systems against sophisticated cyberattacks.