According to a new Kaspersky ICS CERT report, in Q1 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19,6% globally. Kaspersky security solutions blocked malware from 10 052 different malware families of various categories on industrial automation systems. Regionally, the share of ICS computers that were attacked ranged from 27,4% in Africa to 9,1% in northern Europe. Compared with the previous quarter, attacks on the manufacturing sector in Q1 increased across multiple regions, including Europe and Asia.
Across all industry sectors, five regions saw an increase in the share of attacked ICS computers in Q1 2026 compared to the previous quarter. These were southern Europe, Russia, northern Europe, Canada and Africa.
Under fire
In Q1, the biometrics industry, traditionally placed first in terms of the share of ICS computers on which malicious objects were blocked, measured an infection rate of 26,4%. These systems commonly have Internet access and, in many cases, have minimal cybersecurity controls within the organisations that use them. Regionally, southern Europe leads the ranking in biometric systems, with a percentage of 35,15%. Africa follows at 29,58%, and Central Asia comes in third at 28,53%.
In the manufacturing industry, Southeast Asia ranks first among regions in terms of the percentage of ICS computers attacked (23,21%), followed by Africa (21,36%) and South Asia (20,13%).
In 2025, Kaspersky and VDC Research estimated that, in just the first three quarters of 2025, ransomware attacks on manufacturing organisations could have generated over $18 billion in global losses. Actual business losses could have been even higher if supply-chain disruptions, reputational damage, and recovery expenses were factored in.
“Legacy operational technology systems remain deeply embedded in manufacturing environments, which makes them vulnerable. Supply chain complexity and branching of the trusted partner network expand the attack surface beyond the network perimeter. Attackers are realising that targeting OT assets of an industrial enterprise is not rocket science, which is why factory shutdowns bring massive financial losses,” commented Evgeny Goncharov, head of Kaspersky ICS CERT.
More information is available in the report.
© Technews Publishing (Pty) Ltd. | All Rights Reserved.