There was an increase in ransomware incidents across the globe driven by more advanced tactics from attack groups which are using multi-factor authentication (MFA) abuse, cloud identity takeover, and virtualization compromise to disrupt manufacturing and aviation operations, a new report found.

In the third quarter of 2025 (July-September), security provider, Dragos, identified 742 ransomware incidents affecting industrial entities worldwide, an increase from the 708 incidents documented in Q1 and the 657 incidents documented in Q2 2025, according to the Dragos Q3 ransomware report.

North America was the most targeted region in Q3, followed by Europe, which experienced a slight decrease in incidents overall. Asia was the third most impacted region, with an increase in incidents in Q3, with Thailand accounting for the majority.

Manufacturing remained the most impacted sector, accounting for 72 percent of incidents recorded in Q3. The top manufacturing subsector impacted by ransomware was construction, accounting for 142 of the 532 manufacturing incidents in Q3. The global electric/renewables sector saw an increase from 3 incidents in Q2 to 16 in Q3. Similarly, government organizations saw an increase from 4 incidents in Q2 to 35 in Q3.

Key Highlights

Other components to the report include:

Schneider Bold
  • Attackers no longer need to breach ICS networks to impact OT
  • Researchers tracked more than 20 emerging groups, including Gentlemen and Sinobi, many of which end up enabled by leaked builders and AI tools
  • Major companies, including Jaguar Land Rover and Asahi Group, experienced multi-week production delays after attackers compromised ERP, virtualization, and logistics systems

The industrial ransomware landscape in Q3 2025 revolved around three parallel dynamics:

  1. Mature Ransomware-as-a-Service (RaaS) operations continued to drive the majority of activity affecting industrial entities.
  2. Fragmentation across the ecosystem created a growing number of low-discipline, short-lived operators.
  3. Identity-centric extortion collectives also expanded their reach into enterprise environments that support manufacturing, logistics and transportation workflows.

Ransomware activity targeting industrial organizations should intensify as adversaries increasingly focus on the IT systems that underpin OT operations, according to the report.

ERP platforms, MES servers, virtualization environments, and remote access infrastructure will continue to serve as high-value targets because disruption at this layer can rapidly translate into delays, shutdowns, and supply-chain impact without requiring access to ICS networks.

Fragmentation across the ransomware ecosystem is likely to accelerate, Dragos researchers said.

The continued appearance of short-lived, low-discipline groups reflects an environment where leaked builders, recycled infrastructure, and affiliate migration make it easier than ever for new operators to emerge, according to the report.

Ransomware Density Increases

As small groups expand, the density of ransomware activity increases, placing additional pressure on industrial organizations already facing resource constraints and legacy IT-OT interdependencies.

Artificial Intelligence (AI) is also expected to play a growing role in the evolution of ransomware operations, the Dragos report said.

AI-assisted phishing, automated reconnaissance, and evasion techniques will reduce dwell times and enable even low-skilled operators to achieve intrusion outcomes previously associated with more sophisticated adversaries.

As these capabilities become more accessible, the operational tempo and impact of ransomware campaigns will continue to rise.

Click here for more on the report.

ISSSource

Pin It on Pinterest

Share This