Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-03 and was added to the RWP archive on 2026-09-07.
Dragos Q1 2026 held the high baseline — 1,020 industrial ransomware claims, Qilin and Akira still on top
First quarter 2026 did not cool off after Q4's 1,211. Manufacturing 633, ICS-adjacent firms 139, North America nearly 500. The Gentlemen already in the top five.
Bottom line up front
CONFIRMED Dragos, 3 June 2026 — Q1 2026 leak-site/public census 1,020 industrial ransomware incidents, "consistent with the elevated baseline" of late 2025 (Q4 was 1,211). Manufacturing 633; ICS-related engineering/integrators/equipment makers 139; North America nearly 500. Volume leaders: Qilin and Akira; top five also The Gentlemen, LockBit 5.0, Play. Microsoft's May Gentlemen/Storm-2697 teardown is the technical sibling, not a merge. Stage 2 ICS: not the Q1 headline. Process impact via IT/OT dependency: ASSESSED, not counted as PLC malware.
Historical backfill of 3 June 2026 reporting; added 7 September 2026.
What happened
The 2025 hockey stick did not reset on 1 January. Gentlemen entering industrial volume is the new name on an old list.
Why it mattered
If you budgeted "Q4 was a spike," Q1 disagrees. ICS supply-chain firms (139) are how plants get hurt without their own leak-site listing.
Who / what was affected
Industrial orgs, NA-heavy. Gentlemen overlap with this archive's 28 May post.
Technical context
Same access story. Watch Gentlemen --spread if you see Go encryptors (already documented).
Exploitation / threat status at the time
CONFIRMED Dragos Q1 counts.
REPORTED group rank order.
What defenders should have done
- Do not relax after the holidays.
- Integrator/vendor access review.
- Gentlemen detections from the Microsoft post.
RWP assessment
Confidence: High on Dragos's census method being leak-site claims.
Defensive actions
- Continuity of the Q4 control set.
- Identity for engineering firms that touch many plants.
- Next number is Q2's 1,140.