Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-10 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Dragos Q2 2026 — 1,140 industrial ransomware claims and still zero Stage 2 ICS kill-chain cases

Manufacturing 65 percent (747). Qilin, Akira, The Gentlemen the volume three. Dragos is explicit — disruption came from encrypting or shutting the IT/virtualization OT depends on, not from manipulating controllers.

RWP Ventures · 2026-09-07 · event 2026-06-30 · 1 min read · priority 8.0

Bottom line up front

CONFIRMED Dragos, 10 August 2026 — Q2 2026 1,140 industrial ransomware incidents (+12 percent vs Q1's 1,020). Manufacturing 747 (65 percent); ICS-adjacent 117; transportation 95. US 431 (38 percent); Germany 37→68 the notable country jump. Groups: Qilin 140 (down from 198), Akira 129 (up from 100), Gentlemen 83→125. Extortion still sliding toward data-theft-only. Dragos observed no Q2 case of a ransomware operator reaching Stage 2 of the ICS Cyber Kill Chain or directly manipulating a control system. Help Net Security quotes that line. That is the RWP-relevant sentence. Process impact: CONFIRMED as plant downtime from IT/virtualization in Dragos's framing; NOT CONFIRMED as PLC logic changes.

Historical backfill of 10 August 2026 reporting; added 7 September 2026.

What happened

More of the same, louder, with Gentlemen catching Qilin. IOActive's social recap also noted Teams IT-support impersonation as an access path — consistent with this archive's September Teams post, not proof every Q2 industrial hit used it.

Why it mattered

"Industrial ransomware" in a headline is not "ICS malware." Boards that fund PLC detection and skip ESXi backups have the arrow backwards.

Who / what was affected

Leak-site industrial claims; NA and Europe heaviest.

Technical context

Internet-facing, RMM, stolen creds. SimpleHelp called out in Cyber Daily's DragonForce aside. Stage 2 absence is a finding, not a promise for Q3.

Exploitation / threat status at the time

CONFIRMED Dragos census + Stage 2 negative finding.

REPORTED per-group tallies.

What defenders should have done

  1. Hypervisor and identity first.
  2. Do not brief the board that "no ICS malware means no OT risk."
  3. Germany jump — EU manufacturers in scope.

RWP assessment

Confidence: High. This quarter is the doctrine post for the whole Dragos ransomware series.

Defensive actions

  1. OT-aware IR when VMware hosting SCADA dies.
  2. Gentlemen/Qilin/Akira detections.
  3. Keep counting leak sites without inflating them into FrostyGoop.

Sources

  1. Dragos — Industrial ransomware analysis Q2 2026
  2. Help Net Security — Ransomware gangs don't need control system access
  3. Cyber Daily — Industrial ransomware continues to rise