Malicious activity blocked on industrial control system (ICS) computers fell to 19.6% globally in Q1 2026, the lowest level reported in three years, according to Securelist. Exposure varied sharply by region, ranging from 9.1% in Northern Europe to 27.4% in Africa, while Southern Europe and Russia recorded quarter-over-quarter increases in several threat categories. Biometric systems remained the most exposed segment at 26.4%, and manufacturing was the only selected industry to post a global increase during the quarter.
Malicious scripts and phishing pages remained the leading threat category on ICS computers, while spyware ranked second despite an overall decline. The report also noted increases in denylisted internet resources and AutoCAD malware, underscoring continued targeting of industrial environments through engineering and web-based workflows. Among infection vectors, internet-delivered threats were the only major source to rise globally, while threats arriving through email, removable media, and network folders declined to multi-year or period lows.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky's analysis of Q1 2026 found that 19.6% of industrial control system computers had malicious objects blocked, the lowest global level observed in three years. The report also noted regional variation, increases in some categories in Southern Europe and Russia, and a rise in internet-delivered threats during the quarter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.