Site icon techcoffeehouse.com

Ransomware Attacks on SEA Industrial Systems Rise 50%

Advertisements

Ransomware attacks targeting industrial control systems (ICS) in Southeast Asia rose 50 per cent quarter-on-quarter in the second quarter of 2026, according to a new report from Kaspersky.

The findings, published by Kaspersky ICS CERT, show the percentage of ICS computers attacked by ransomware climbed across nearly every region worldwide between Q1 and Q2 2026, even as overall malicious activity blocked on ICS systems fell to its lowest level since 2022.

Southeast Asia among the sharpest regional increases

Southeast Asia recorded one of the steepest rises in ransomware activity against ICS systems, trailing only Australia and New Zealand (67 per cent) and outpacing Africa (31 per cent), Central Asia (31 per cent) and South America (38 per cent). The Middle East saw an 11 per cent increase, while Western Europe, Southern Europe and Canada were the only regions to buck the trend.

The top regions by absolute number of ICS computers hit by ransomware were Africa, the Middle East, Central Asia and South Caucasus, East Asia, Southern Europe and South Asia.

“Ransomware remains a challenge for industrial enterprises, with its operational dynamics increasingly shifting toward highly evasion-prone tactics while exploiting legitimate administrative tools to blend in with normal network traffic,” said Evgeny Goncharov, Head of Kaspersky ICS CERT.

Goncharov added that with legacy operational systems deeply embedded in critical infrastructure, a single localised failure can paralyse entire supply chains, and urged targeted organisations to refuse ransom payments and instead reinvest in proactive security measures.

Biometrics sector remains most targeted globally

Across all recorded threats, not just ransomware, the biometrics sector remained the most targeted industry globally in Q2, with malicious objects blocked on 26 per cent of its ICS computers — slightly higher than the previous quarter. Kaspersky attributed this to the sector’s heavy reliance on internet access and email, combined with minimal cybersecurity controls. Regionally, Southern Europe led biometrics-related detections at 33 per cent, followed by Africa and Central Asia.

Kaspersky recommends that operational technology (OT) operators conduct regular security assessments, adopt continuous vulnerability management, apply timely patches, deploy endpoint detection and response (EDR) tools, and invest in dedicated OT security training to stay ahead of evolving threats.

Author

Exit mobile version