Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-10 and was added to the RWP archive on 2026-09-07.
Dragos Q2 2026 — 1,140 industrial ransomware claims and still zero Stage 2 ICS kill-chain cases
Manufacturing 65 percent (747). Qilin, Akira, The Gentlemen the volume three. Dragos is explicit — disruption came from encrypting or shutting the IT/virtualization OT depends on, not from manipulating controllers.
Bottom line up front
CONFIRMED Dragos, 10 August 2026 — Q2 2026 1,140 industrial ransomware incidents (+12 percent vs Q1's 1,020). Manufacturing 747 (65 percent); ICS-adjacent 117; transportation 95. US 431 (38 percent); Germany 37→68 the notable country jump. Groups: Qilin 140 (down from 198), Akira 129 (up from 100), Gentlemen 83→125. Extortion still sliding toward data-theft-only. Dragos observed no Q2 case of a ransomware operator reaching Stage 2 of the ICS Cyber Kill Chain or directly manipulating a control system. Help Net Security quotes that line. That is the RWP-relevant sentence. Process impact: CONFIRMED as plant downtime from IT/virtualization in Dragos's framing; NOT CONFIRMED as PLC logic changes.
Historical backfill of 10 August 2026 reporting; added 7 September 2026.
What happened
More of the same, louder, with Gentlemen catching Qilin. IOActive's social recap also noted Teams IT-support impersonation as an access path — consistent with this archive's September Teams post, not proof every Q2 industrial hit used it.
Why it mattered
"Industrial ransomware" in a headline is not "ICS malware." Boards that fund PLC detection and skip ESXi backups have the arrow backwards.
Who / what was affected
Leak-site industrial claims; NA and Europe heaviest.
Technical context
Internet-facing, RMM, stolen creds. SimpleHelp called out in Cyber Daily's DragonForce aside. Stage 2 absence is a finding, not a promise for Q3.
Exploitation / threat status at the time
CONFIRMED Dragos census + Stage 2 negative finding.
REPORTED per-group tallies.
What defenders should have done
- Hypervisor and identity first.
- Do not brief the board that "no ICS malware means no OT risk."
- Germany jump — EU manufacturers in scope.
RWP assessment
Confidence: High. This quarter is the doctrine post for the whole Dragos ransomware series.
Defensive actions
- OT-aware IR when VMware hosting SCADA dies.
- Gentlemen/Qilin/Akira detections.
- Keep counting leak sites without inflating them into FrostyGoop.
Sources
- Dragos — Industrial ransomware analysis Q2 2026
- Help Net Security — Ransomware gangs don't need control system access
- Cyber Daily — Industrial ransomware continues to rise