Dragos's Industrial Ransomware Analysis for Q2 2026 counted 1,140 ransomware incidents against industrial organizations worldwide — up 12% from the 1,020 recorded in Q1. Manufacturing alone absorbed 747 of them, 65% of the total (Help Net Security, SecurityBrief).

The detail that should worry manufacturing security teams more than the headline count: most of these attacks never touched a control system. They didn't have to.

The numbers, and who's absorbing them

Manufacturing's 747 incidents break down further into construction (176), equipment manufacturing (114), and food and beverage (70) (Help Net Security). Behind manufacturing, the next-most-targeted group wasn't a single industry but the companies that keep industrial environments running: engineering firms, systems integrators, and ICS equipment makers logged 117 incidents, reflecting how ransomware crews are increasingly comfortable working the industrial supply chain rather than just the end customer (Cyber Daily). Transportation and logistics came third with 95.

Energy and utilities stayed on the target list at lower but consistent volumes: Oil and Natural Gas took 45 incidents across upstream, midstream, and downstream operators; electric utilities logged 8; water utilities 4; renewables 12; mining 15. Government entities, mostly municipal and regional, accounted for 64 (SecurityBrief).

Geographically, the US alone accounted for 431 incidents — 38% of the global total — with North America and Europe remaining the two most-targeted regions overall (SecurityBrief).

No single ransomware operation dominated the quarter the way Qilin did in Q1. Qilin still logged the most industrial victim claims at 140, but that's down from 198 in Q1. Akira climbed from 100 to 129, and The Gentlemen — a newer entrant — jumped from 83 to 125. The top three finished within 15 claims of each other, which reads less like one gang pulling ahead and more like a crowded field of capable operators all working the same target list (Help Net Security).

Why IT-only disruption is enough to stop a production line

The finding Dragos leads with matters more than any single incident count: attackers don't need to reach the operational technology layer to interrupt production. Encrypting or knocking out the enterprise IT systems a plant depends on — ERP platforms, order management, virtualization infrastructure, the systems that schedule and route work — is often sufficient to halt output on its own, without a single packet ever touching a PLC or an HMI (Help Net Security).

That's a distinction a lot of manufacturing security programs still get backwards. OT-specific defenses — network segmentation, ICS-aware monitoring, protocol-level anomaly detection — are necessary, but they answer a different threat than the one actually landing in Q2 2026's data. If ransomware operators can stop the line by encrypting the ERP system that tells the line what to build, an air-gapped control network doesn't help. The plant is still down.

This is consistent with where OT incidents have been trending for several quarters: the operational impact increasingly comes from IT/OT interdependency, not from direct manipulation of control logic. A ransomware crew with commodity tooling and no ICS expertise can still take a manufacturer offline, because they're not aiming at the control system — they're aiming at everything the control system depends on to receive instructions.

The extortion playbook is shifting away from encryption

Dragos also flagged a continuing shift toward data-theft-only extortion: attackers steal sensitive material and threaten to publish it rather than relying solely on file encryption to force payment. For industrial victims, what gets stolen is often more sensitive than a typical IT breach — engineering documents, technical specifications, network diagrams, and credentials, any of which can expose not just the victim but its supply chain if published or resold (Help Net Security).

That changes the recovery calculus. Restoring from backup neutralizes an encryption-only attack. It does nothing for a data-theft threat — the exposure persists whether or not systems come back online, and a second extortion attempt using the same stolen data is a real possibility months later.

How attackers are getting in

The initial access patterns Dragos observed are unglamorous and repeatable, which is exactly why they keep working: exploitation of internet-facing edge devices (Fortinet FortiGate and Cisco appliances came up repeatedly) and remote management tooling, abuse of valid accounts, credential theft, Active Directory reconnaissance, certificate abuse, and — increasingly routine — EDR-killer tooling and Bring Your Own Vulnerable Driver (BYOVD) techniques used to blind endpoint defenses immediately ahead of impact (Infosecurity Magazine).

None of this requires zero-days. It requires an unpatched edge device, a reused credential, or a remote-access tool nobody's been auditing — the same gaps that show up in nearly every incident response engagement in this sector, quarter after quarter.

What this means for manufacturers right now

A few takeaways that follow directly from the data, not from general advice:

  1. Treat enterprise IT as part of your OT risk surface, not a separate program. If ERP or virtualization downtime stops the line as effectively as a control-system compromise, your business continuity plan for "the plant goes down" needs to cover both paths — because attackers clearly aren't distinguishing between them.
  2. Audit internet-facing edge devices and remote management tools first. These are the documented, repeated entry point. Patch cadence and exposure on FortiGate, Cisco, and VPN/remote-access appliances deserve the same priority as any ICS-specific control.
  3. Plan for data-theft extortion, not just encryption. Backup and restore procedures don't address a breach where the leverage is publication, not availability. Know what sensitive engineering and operational data you hold and where, so you can scope exposure quickly if it's stolen.
  4. Watch for EDR-killer and BYOVD activity as a late-stage warning sign. By the time defenses are being blinded, attackers are near impact — detection needs to catch the access and lateral-movement stages well before that point.
  5. If you're a systems integrator, engineering firm, or equipment maker, you're not a bystander. The 117 incidents against ICS-supply-chain organizations this quarter say attackers see you as a route into your customers, not just a target in your own right.

Where MBCTG fits

The core finding here — that IT-side disruption alone can stop a production line — is exactly why we don't treat OT security and IT security as separate conversations. Our OT security services are built around the actual dependency chain between enterprise IT and the plant floor, not just the control network in isolation, and our 24/7 SOC is positioned to catch the credential abuse, edge-device exploitation, and EDR-evasion patterns Dragos is describing before they reach the impact stage.

If you're a manufacturer and haven't mapped what would actually happen to production if your ERP or virtualization layer went down tomorrow — not your control network, your IT — that's a conversation worth having before a ransomware crew answers the question for you. Talk to an MBCTG expert.