WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts ICS Ransomware Trends – Dragos Analyzes ICS Ransomware Attacks for Q2 2023
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS Ransomware Trends – Dragos Analyzes ICS Ransomware Attacks for Q2 2023

Author: Jennifer Walker

Created: Tuesday, August 1, 2023 - 17:19

Categories: Cybersecurity, OT-ICS Security

Dragos continues tracking ransomware incidents impacting industrial organizations and has published its latest findings for Q2 2023. Overall, ransomware activity targeting industrial organizations and infrastructure is sustaining its trend upward resulting in more incidents and new or rebranded threat groups compared to last quarter. Dragos called it “an exceptionally active period” and assesses with moderate confidence that the current trend will continue.

According to its latest report, Dragos tallied 253 incidents compared to the 214 last quarter. This activity included five new ransomware groups this quarter (66) than last (61), with thirteen more causing impact, 33 over 20, respectively. The groups most concerning for ICS organizations are LockBit, AlphaV, and Black Basta. Dragos noted that these groups continued to employ previously effective tactics, including exploiting zero-day vulnerabilities, leveraging social engineering, targeting public-facing services, and compromising IT service providers. Also notable is that Dragos observed an overlap in victim profiles between some ransomware-as-a-service (RaaS) groups, initial access brokers (IABs), and phishing-as-a-service (PhaaS) groups.

While the observed attacks against water and wastewater (2) and electric (1) utilities were low during Q2, members are highly encouraged to maintain awareness of and validate protections against the behaviors and the active groups demonstrating interest and capability to impact industrial organizations and infrastructure. For more analysis and to access the report, visit Dragos.

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar