Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-10 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Dragos Q4 2025 industrial ransomware — 1,211 claimed hits, Qilin still the volume leader

October–December 2025 leak-site census jumped from 742 in Q3 to 1,211. Qilin 284. Manufacturing and ICS engineering remain the body count, not a new ICS encryptor.

RWP Ventures · 2026-09-07 · event 2025-12-31 · 1 min read · priority 7.8

Bottom line up front

CONFIRMED Dragos, 10 March 2026 — Q4 2025 (Oct–Dec) 1,211 ransomware incidents against industrial entities from leak sites and public claims, up from 742 in Q3 and 657 in Q2 2025. Third straight quarter Qilin led (284 in Q4, up from 138 in Q3). Ecosystem consolidating around operators who can repeat intrusion/extortion. ICS engineering called out as a slice (Dragos figure: 50 incidents / 44 percent in one breakout — treat as Dragos's category math, not a global PLC-compromise rate). Sequel to this archive's Q3 post. Stage 2 ICS manipulation: not claimed as the Q4 pattern. Process impact: ASSESSED where plants shut IT/virtualization; UNKNOWN as PLC malware.

Historical backfill of 10 March 2026 reporting; added 7 September 2026.

What happened

Leak-site counting. IAB + RaaS against low-downtime industries. Data theft for extortion stayed central.

Why it mattered

Q4 is when industrial orgs freeze change windows. Volume into that freeze is the story.

Who / what was affected

Industrial entities worldwide in Dragos's census. Manufacturing dominant as in prior quarters.

Technical context

Same as Q3: internet-facing remote access, stolen creds, ESXi. Hunt Qilin affiliate tooling. Do not invent an ICS-specific Qilin payload.

Exploitation / threat status at the time

CONFIRMED Dragos counts as leak-site analysis.

REPORTED group rankings.

What defenders should have done

  1. Assume Qilin volume continues into 2026 (it did — see Q1/Q2 posts).
  2. Backup and identity, not a new YARA.
  3. Classify downtime as OT-relevant when SCADA VMs die.

RWP assessment

Confidence: High on the QoQ numbers as Dragos-observed claims.

Defensive actions

  1. External attack surface for industrial remote access.
  2. Extortion tabletop that includes data-theft-only.
  3. Keep Q3/Q4/Q1/Q2 as a series, not one mashed post.

Sources

  1. Dragos — Industrial ransomware analysis Q4 2025
  2. Dragos — Industrial ransomware analysis Q3 2025
  3. Dragos — ICS malware and ransomware resource index