WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships ICS/OT Ransomware – Dragos’s Most Recent Industrial Ransomware Analysis: Q2 2024
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT Ransomware – Dragos’s Most Recent Industrial Ransomware Analysis: Q2 2024

Author: Chase Snow

Created: Thursday, August 15, 2024 - 17:47

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

There was a notable rise in ransomware attacks targeting industrial organizations in the second quarter of 2024 compared to the prior quarter according to the “Dragos Industrial Ransomware Analysis: Q2 2024” report. The report highlights a significant resurgence in threat actor activity, with large ransomware groups such as Royal ransomware and the Knight groups, rebranding as BlackSuit and RansomHub, respectively. Despite a drop in both the volume and impact of attacks in Q1 – following law enforcement crackdowns on BlackCat and LockBit – Q2 saw the number of attacks nearly double from 169 incidents to 312.

Dragos indicates that 29 out of the 86 ransomware groups known to target industrial organizations remained active in the second quarter, reflecting an increase from the 22 groups that conducted attacks in the first quarter. Most of the reported ransomware attacks focused on industrial organizations in the United States and Europe, with the manufacturing sector remaining the primary target.

Dragos “assesses with moderate confidence that the ransomware threat landscape will continue to evolve, characterized by the introduction of new ransomware variants and increasingly coordinated campaigns targeting industrial sectors. Despite significant law enforcement actions, the observed resilience and adaptability of ransomware groups indicate a likely continuation of this trend.” Access the full report at Dragos, and for more analysis, visit SecurityWeek.

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar