Industrial Ransomware Incidents Rise 12% in the Second Quarter
1,140 incidents involving industrial organisations were recorded in Q2 2026, with manufacturing accounting for 65% of them and Germany's count nearly doubling.

Analysis reported on 11 August 2026 counted 1,140 ransomware incidents involving industrial organisations in the second quarter of 2026, up 12% from 1,020 in the first quarter.
The sector breakdown is heavily weighted. Manufacturing accounted for 747 incidents, 65% of the total. Construction followed at 176, organisations supporting industrial control systems at 117, equipment manufacturing at 114, transportation and logistics at 95, and food and beverage at 70.
Regionally, North America recorded 514 incidents, up from 480, with the United States alone at 431 — 38% of the worldwide total. Europe rose more sharply, from 252 to 316, and Germany's count nearly doubled from 37 to 68, with 76% of those in manufacturing. Asia recorded 172, South America 64, the Middle East 44, Australia and New Zealand 19, and Africa 11.
Among the groups, Qilin claimed the most industrial victims at 140, though down from 198 in the first quarter. Akira rose from 100 to 129 and The Gentlemen from 83 to 125 — a pattern of one large operator contracting while several others expand, which is the usual shape after law-enforcement pressure or a rebrand.
The reading that matters for anyone building or maintaining plant systems is where the damage comes from. Two thirds of these incidents land on manufacturing, and the disruption to production typically arrives through IT-side encryption cascading into operations rather than through direct control-system access. That argues for hardening the boundary services production actually depends on — historians, MES connectors, remote-access jump hosts, licence servers — and for keeping offline, tested backups of PLC and HMI project files. Those project files are frequently the slowest asset to restore, because they are often held on an engineering workstation that nobody classified as critical until the day it mattered.
Source: Help Net Security