A new report shows that cyberattacks targeting **industrial control systems** increased globally during the first quarter of 2026.

According to the Kaspersky ICS CERT report, security solutions blocked malicious objects on 19.6% of these systems worldwide. Consequently, the data highlights a growing threat to automated infrastructure across multiple regions.

Security solutions blocked malware from 10,052 different families on industrial automation systems during this period. Meanwhile, the percentage of attacked computers varied significantly by region, ranging from 27.4% in Africa to 9.1% in Northern Europe. In addition, Europe and Asia experienced a notable rise in attacks on the manufacturing sector, highlighting the need for stronger cybersecurity measures.

Global Rise in Industrial Control Systems Attacks

The report identified specific regions where the share of attacked **industrial control systems** computers increased. Specifically, Southern Europe, Russia, Northern Europe, Canada, and Africa saw quarterly rises. Furthermore, these findings indicate that threat actors are actively expanding their operations across diverse geographic locations.

Regional and Sector Vulnerabilities

Biometric systems experienced the highest percentage of blocked malicious objects at 26.4% globally. Notably, these smart devices often have direct internet access and minimal security controls. Geographically, Southern Europe led this category at 35.15%, followed by Africa at 29.58% and Central Asia at 28.53%.

Within the manufacturing sector, Southeast Asia recorded the highest percentage of attacked **industrial control systems** at 23.21%. Meanwhile, Africa followed at 21.36%, and South Asia reached 20.13%. These figures demonstrate that manufacturing remains a primary target for digital threats.

Financial Impact of Ransomware

In 2025, ransomware attacks on manufacturing organizations caused substantial financial damage, affecting the global economy. Specifically, Kaspersky and VDC Research estimated that these attacks generated over $18 billion in global losses during the first nine months of 2025. Moreover, actual business losses were likely higher due to supply-chain disruptions and recovery expenses.

“Legacy operational technology systems remain deeply embedded in manufacturing environments, which makes them vulnerable. Supply chain complexity and branching of the trusted partner network expands the attack surface beyond the network perimeter. Attackers are realizing that targeting OT assets of an industrial enterprise is not rocket science, which is why factory shutdowns bring massive financial losses,”

Evgeny Goncharov, Head of Kaspersky ICS CERT

Recommended Security Measures

To protect **industrial control systems** from emerging threats, experts recommend conducting regular security assessments. Additionally, organizations should establish continuous vulnerability assessment and triage processes. Implementing timely updates and security patches for key components is also crucial to prevent costly production interruptions.

Furthermore, deploying endpoint detection and response solutions can help identify sophisticated threats. Finally, improving incident response skills through dedicated training for IT and operational technology staff is highly recommended. These proactive steps help secure critical infrastructure against evolving digital risks.