CVE Tools

Ransomware gangs don’t need control system access to disrupt industrial production

Help Net SecurityBy Sinisa Markovic

Reported exploitedAnyDeskQilinQuick Assist

Our summary

Dragos reports that ransomware actors disrupted industrial production in Q2 2026 primarily by compromising enterprise IT infrastructure rather than accessing industrial control systems directly. With 1,140 recorded incidents, up 12% from the previous quarter, manufacturing was the hardest-hit sector, accounting for two-thirds of all cases. Threat groups such as Qilin, Akira, The Gentlemen, and Silent Ransom Group leveraged social engineering tactics, including impersonating IT support on Microsoft Teams to deploy remote access tools like AnyDesk and Quick Assist.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store