Ransomware at SMBtech

Industrial Ransomware Threats Are Escalating: Dragos Analysis

Surprisingly Useful AI Article Enhancements

Industrial organisations around the globe are facing a growing wave of ransomware attacks, with cyber extortion now one of the most consequential threats to operational resilience and global supply chains. According to Dragos’s Industrial Ransomware Analysis: Q3 2025, ransomware activity affecting industrial entities continued to rise both in volume and operational impact during the third quarter of 2025.

Ransomware Incidents Continue Upward Trend

Between July and September 2025, Dragos identified 742 ransomware incidents targeting industrial organisations worldwide – up from 657 in Q2 and 708 in Q1. This quarterly increase underscores how ransomware remains a persistent, evolving threat across sectors where downtime can have severe economic and safety consequences. North America remained the most affected region by volume, followed by Europe and Asia, with notable increases reported in Thailand’s industrial cyber incidents.

Manufacturing And Critical Sectors Most Heavily Targeted

Manufacturing organisations continued to bear the brunt of ransomware activity, absorbing approximately 72 per cent of all reported incidents (about 532 cases) during the quarter. Within manufacturing, the construction subsector emerged as one of the most frequently hit, illustrating that ransomware actors are increasingly targeting firms integral to industrial supply chains and infrastructure projects.

The analysis also shows notable shifts in other sectors. For example:

• The electric and renewables sector saw ransomware incidents rise sharply – from just 3 in Q2 to 16 in Q3 – indicating that attackers are broadening their focus into critical energy infrastructure.

• Government organisations experienced a striking rise in activity, climbing from 4 incidents in Q2 to 35 in Q3, highlighting that public entities are increasingly in ransomware threat actors’ crosshairs.

These patterns point to adversaries’ growing emphasis on sectors where disruption can translate into high operational and political impact.

Evolving Ransomware Ecosystem & Group Dynamics

A defining characteristic of the Q3 2025 landscape is the ongoing fragmentation of ransomware operations. While mature Ransomware-as-a-Service (RaaS) platforms continue to drive much of the activity, a proliferation of smaller, short-lived groups is reshaping the ecosystem.

Dragos’s report highlights that ransomware activity is less about the brand names seen on leak sites and more about the behaviour of affiliates, Initial Access Brokers (IABs), and how they exploit organisational weaknesses. This fragmentation – aided in part by inexpensive tooling and automated payload builders – has allowed low-discipline groups to quickly surface and target industrial firms’ business systems.

Among established players, Qilin remained the most prolific ransomware group for the second consecutive quarter, responsible for roughly 138 confirmed incidents, making it one of the dominant forces in the industrial ransomware landscape. Other groups such as Akira, Play, and INC Ransom collectively accounted for a substantial share of Q3 activity.

Interestingly, the once-prominent RaaS brand LockBit attempted to re-enter the ecosystem with a rebranded affiliate program (“LockBit 5.0”), removing some traditional sector targeting restrictions. However, most former LockBit affiliates had already migrated to other platforms, and the brand’s influence in industrial attacks remained comparatively limited in Q3.

How Ransomware Is Disrupting Industrial Operations

Beyond raw incident counts, the report illustrates how ransomware is disrupting real industrial operations:

• Jaguar Land Rover (JLR) – A ransomware intrusion in early September forced parts of its global IT environment offline, resulting in nearly five weeks of manufacturing disruption and significant supply chain knock-on effects.

• Asahi Group Holdings (Japan) confirmed extended production downtime at some of its facilities following a ransomware attack that also involved data exfiltration.

• Collins Aerospace (RTX subsidiary) experienced internal system outages that affected airport passenger operations like check-in and baggage processing, demonstrating that ransomware can extend well beyond the factory floor to impact service continuity.

• Data I/O Corporation, which supplies programmable integrated circuit support systems, disclosed disruptions to communications and shipping operations triggered by a ransomware intrusion.

While not all of these incidents involved direct compromise of industrial control systems (ICS), they show how attacks on enterprise IT environments that support OT workflows can cascade into tangible operational impact.

According to Dragos’s analysis, several broader patterns emerged in Q3:

• Identity-centric extortion collectives – Groups focused on credential theft and cloud/identity abuse continued to expand their reach into environments that undergird industrial operations, even without deploying traditional ransomware payloads.

• Use of common access vectors – Compromised credentials, insecure remote access services (e.g., RDP/VPN), and initial access purchased through IABs remain frequent footholds for ransomware operators.

• Operational diversity – Some actors increasingly pair ransomware encryption with data theft and extortion, underscoring the trend toward multi-pronged extortion tactics that maximise leverage against victims.

What This Means For Industrial Cybersecurity

The Q3 2025 ransomware landscape underscores that industrial organisations must treat ransomware not as a peripheral IT threat but as a core operational risk.

With attackers exploiting the convergence of IT and OT environments and targeting organisations with low tolerance for downtime, defenders need to prioritise holistic resilience – bridging IT security, OT safety, identity protections, and supply-chain risk management. Proactive measures, including robust segmentation, identity hygiene, secure remote access configurations, and incident response planning, are increasingly essential as ransomware operators continue to evolve both their tactics and ecosystem structure.

Abdulrahman H. Alamri is a Senior Intel Analyst & Lexie Mooney is Senior Threat Analyst at Dragos.

Last Updated on February 13, 2026 by Abdulrahman H. Alamri

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.