WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 ICS/OT Ransomware Impacts to Utilities – Highlights from Dragos ICS/OT Ransomware Analysis: Q1 2022
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT Ransomware Impacts to Utilities – Highlights from Dragos ICS/OT Ransomware Analysis: Q1 2022

Author: Jennifer Walker

Created: Thursday, May 5, 2022 - 18:45

Categories: OT-ICS Security

While Coveware’s recent quarterly report, Ransomware Threat Actors Pivot from Big Game to Big Shame Hunting analyzes the broader ransomware threat picture, Dragos’ quarterly report, ICS/OT Ransomware Analysis: Q1 2022 looks at ICS/OT impacting ransomware. The report supports Dragos’ Q4 2021 assessment that ransomware would continue to disrupt OT operations into 2022 and combined with several globally significant events, indicates that ransomware may even pose a greater risk for operational disruption and impacts than it did last year. While the manufacturing sector took the large brunt of the targeting at 75 percent, food and beverage were a distant second at 6 percent. All other sectors ranged from 4 to 1 percent, including utilities at 2 percent. Likewise, out of the 37 ransomware groups targeting industrial organizations that Dragos monitors, Avos Locker and Blackbyte have been the 2 groups that primarily impact utilities. This year federal partners have posted indicators of compromise and behaviors for both groups. Members are highly encouraged to review those reports (referenced below) for details on detecting and protecting against activity their behaviors. Visit Dragos for more.

References:

  • FBI-USSS: Indicators of Compromise Associated with BlackByte Ransomware
  • Indicators of Compromise Associated with AvosLocker Ransomware

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 21, 2026)

May 21, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Poland Warns of Escalating Cyber Threats to Water Utilities and ICS Operations

May 21, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – May 21, 2026

May 21, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar