Industrial Technology

Ransomware Rarely Reaches the Control System. It Still Stops the Line

Dragos found no ransomware case in the second quarter that touched a control system directly, yet manufacturers absorbed 65% of all industrial incidents. Production stops because the IT systems the plant floor depends on go dark first.

October 7, 2026·Industrial Technology
An empty process control room with operator chairs facing a bank of SCADA and alarm monitoring screens

Key Takeaways

  • Dragos counted 1,140 ransomware incidents against industrial organisations in the second quarter of 2026, and manufacturing absorbed 747 of them, or 65%.
  • Dragos observed no second-quarter case in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system.
  • In Fortinet's 2026 survey, 71% of OT organisations reported between one and nine intrusions, up from 47% a year earlier.
  • Verizon's 2026 breach report found the median time to fully remediate a vulnerability has stretched to 43 days, from 32 the year before.

October is Cybersecurity Awareness Month, and most plant security programmes are still built around a single nightmare: an attacker inside the PLCs, changing setpoints and driving equipment into an unsafe state. The latest industrial incident data points somewhere less dramatic and far more common. Ransomware is stopping production lines in record numbers, and in almost every case it never touches the control system at all. It takes down the ERP, the virtual servers and the scheduling tools the plant floor quietly depends on, and the line stops anyway.

Manufacturing Is Taking Most of the Hits

In its industrial ransomware analysis for the second quarter of 2026, Dragos identified 1,140 ransomware incidents affecting industrial organisations worldwide, a 12% increase over the 1,020 recorded in the first quarter. Manufacturing accounted for 747 of them, or 65%. Construction, equipment makers and food and beverage producers led the manufacturing subsectors, and the United States alone accounted for 431 incidents, 38% of the global total.

The surveys tell the same story from the inside. Fortinet's 2026 State of Operational Technology and Cybersecurity Report, summarised by Fortinet on itWire, found that 71% of respondents reported between one and nine intrusions, up from 47% the previous year. Phishing was still the most reported intrusion at 76%, and ransomware remained a major concern at 50%, only slightly below 54% in 2025. Perhaps more telling, the share of organisations placing themselves at maturity Level 4 fell from 49% to 17%, a sign that OT teams are measuring themselves more honestly than they did a year ago.

The consequences are not abstract. In July, Coca-Cola's dairy business Fairlife suspended its U.S. production after a ransomware attack, while its Canadian operations stayed open. The company said the attack had no effect on the quality and safety of its products. Its plants stopped regardless.

The Line Stops Because Its Dependencies Stop

The most important finding in the Dragos analysis is what did not happen. Dragos observed no case in the quarter in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Instead, ransomware continued to affect operational environments through the loss of enterprise IT systems, ERP platforms and virtualisation infrastructure. Where production was disrupted, it followed encryption or a precautionary shutdown of the enterprise and virtualisation systems on which OT depends.

That distinction matters for how plants plan. A line can be mechanically healthy, with every controller and HMI intact, and still be unable to run because work orders, recipes, batch records or shipping labels live on servers that have been encrypted or switched off as a precaution. If nobody has mapped which plant functions rely on which IT services, nobody knows how long the floor can keep producing once those services go dark.

The way in is equally ordinary. Dragos reports that affiliates mainly gained access through internet-facing infrastructure, including the exploitation of a remote access VPN authentication bypass, and through compromised credentials. Several groups contacted employees on Microsoft Teams posing as internal IT support, then talked them through a screen-sharing session to install a remote monitoring and management tool. Dragos names SimpleHelp, AnyDesk and QuickAssist among the remote tools being abused.

Patching and Partners Are Widening the Gap

Verizon's 2026 Data Breach Investigations Report, reported by Help Net Security, shows why that exposed edge is so hard to close. For the first time in the report's 19 years, exploitation of vulnerabilities overtook stolen credentials as the main way attackers gain initial access. Ransomware grew to 48% of all breaches, up from 44%. The median time to fully remediate a vulnerability rose to 43 days from 32, and only 26% of the flaws on CISA's known exploited list had been fully fixed, down from 38%.

Third parties add to the problem. Verizon found that breaches involving a third party jumped 60% year on year and now account for nearly half of all breaches. In a plant, that third party is often an integrator, a machine builder or a maintenance contractor holding remote access to equipment it supports, frequently through the same kind of remote tools Dragos saw being abused.

Visibility remains thin. Fortinet found that about 23% of respondents can see only around half of their OT environment, and 89% expect more OT security regulation within five years, up from 66% in 2025. When an incident lands, plants will increasingly be expected to show what happened, when, and what they did about it, from records that survive the outage.

What Operations Leaders Should Do Now

None of this argues against protecting control systems. It argues for protecting the ability to keep producing when the business network falls.

The control system is still worth defending. But the data says the next ransomware stoppage is far more likely to start in an inbox, a VPN or a contractor's laptop, and to reach the plant floor through the systems production quietly depends on. Plants that know those dependencies, and can run without them for a while, will lose hours rather than weeks.

More in Industrial Technology

All Resources →