Historical intelligence backfill. This assessment covers reporting originally published on 2025-12-09 and was added to the RWP archive on 2026-09-07.

Daily Top · OT / ICS

Dragos Q3 2025 counted industrial ransomware victims — not confirmed OT malware

Dragos logged 742 ransomware incidents against industrial entities in Q3 2025, led by manufacturing, while the JLR and PPL cases show IT disruption of operations rather than proven controller compromise.

RWP Ventures · 2026-09-07 · event 2025-09-30 · 3 min read · priority 7.7

Bottom line up front

CONFIRMED Dragos's Q3 2025 industrial ransomware analysis (published 9 December 2025) counted 742 incidents against industrial entities in July–September, up from 708 in Q1 and 657 in Q2. Manufacturing was 72% (532). North America led, then Europe (162 in one secondary tally), then Asia with Thailand driving much of the Asian increase. Qilin was the most active brand in Dragos's telling (138). Construction was the largest manufacturing subsector (142).

CONFIRMED operational disruption is not the same as CONFIRMED OT/ICS compromise. Jaguar Land Rover's September 2025 incident shut IT and stopped plants for weeks; that is production impact via enterprise systems. Pakistan Petroleum Limited reported ransomware on IT segments and said it had no indication of operational-data compromise. RWP will not relabel those as "OT breaches."

Historical backfill of 9 December 2025 reporting; added 7 September 2026.

What happened

Dragos's quarterly is a victimology product: industrial organizations hit by ransomware, usually on IT, ERP, virtualization, and identity. ISSSource and Industrial Cyber repeat the 742 / 72% / Qilin figures. Dragos also described three parallel dynamics: mature RaaS, noisy short-lived affiliates, and identity-centric extortion against the enterprise layer that manufacturing runs on.

Electric/renewables incidents rose (3 in Q2 to 16 in Q3) and government industrial-adjacent counts rose (4 to 35). Those are still ransomware-on-the-enterprise-of-an-industrial-org unless a specific case shows a PLC.

Why it mattered

Boards hear "industrial ransomware" and picture Stuxnet. The Q3 data is mostly "the factory's SAP/VMware/Okta got encrypted and the line stopped because no one would run without MES." That is bad enough. Treating it as FrostyGoop wastes the OT team's week.

JLR is the teaching case: multi-week manufacturing halt, supply-chain shock, still an IT-core incident unless later evidence shows controllers. PPL's public line is the correct evidence discipline.

Who / what was affected

Industrial entities globally; manufacturing first; construction subset; North America volume lead. Named examples in Dragos: PPL (IT, 6 August), JLR (IT shutdown, 1 September). Do not invent additional victims.

OT/ICS malware in this dataset: UNKNOWN as a class. Individual CONFIRMED OT cases would need their own sources.

Technical context

Initial access Dragos and secondaries flag for this quarter: MFA abuse, cloud identity, virtualization — i.e., the same enterprise path as everyone else. Compensating OT controls still matter because a stopped MES is an availability event: segmentation so encryption of IT cannot become a safety or setpoint event; manual-run playbooks; immutable backups of both IT and engineering stores.

Exploitation / threat status at the time

CONFIRMED incident counts as Dragos-observed; manufacturing dominance; Qilin volume.

REPORTED JLR and Asahi-class multi-week production delays via ERP/virtualization/logistics.

ASSESSED (high): most of the 742 never touched a controller.

UNKNOWN how many of the 742 had any dual-homed historian or jump host taken.

What defenders should have done

  1. Split metrics: "ransomware at an industrial company" vs "ransomware in OT." Report both.
  2. Identity and hypervisor hardening on the manufacturing IT that actually stops the line.
  3. Test running critical processes without MES for the length of a real outage, not a tabletop hour.
  4. Vendor/supply-chain notification templates — JLR showed downstream plants eat the same incident.
  5. Do not hunt ICS malware first if EDR shows Encryptor.exe on the domain controllers.

What we know now

Later Dragos quarterlies (Q4 2025, Q1–Q2 2026) continue this series; they are separate posts. The evidence rule does not change.

RWP assessment

Confidence: High on Dragos's counts as vendor telemetry, not as a global census. High that OT-compromise claims need extra evidence. Moderate that Qilin's 138 is ranking, not a unique TTP dump.

Defensive actions

  1. CISO dashboard: two numbers, not one.
  2. Privileged-access and backup tests on ERP/VMware this quarter.
  3. OT: confirm no domain-joined jump hosts with mapped process-network drives.
  4. After any manufacturing ransomware, ask "did a controller change?" and accept "no" as a success.

Sources

  1. Dragos — Industrial Ransomware Analysis: Q3 2025
  2. ISSSource — OT Ransomware Continues to Rise
  3. Industrial Cyber — Ransomware surge, manufacturing 72% of Q3 cases
  4. SecurityBrief Asia — Industrial ransomware attacks surge