In Q2 2026, malicious objects were blocked on 19.15% of industrial control system (ICS) computers, the lowest proportion recorded since 2022. The global decline masked quarterly increases in five regions, with East Asia and Africa experiencing notable growth across several threat categories; the biometrics sector had the highest exposure rate, with 26.44% of ICS computers affected.
Malicious scripts and phishing pages remained the most prevalent threats against ICS environments, followed by denylisted internet resources and spyware. Ransomware, worms, malicious documents, and AutoCAD-targeting malware increased globally, while email was the only infection source to rise worldwide, reaching 2.84% of ICS computers; miners, viruses, and threats delivered through the internet, removable media, and network folders generally declined.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
During Q2 2026, Kaspersky security solutions blocked malicious objects on 19.15% of industrial control system computers globally, the lowest proportion reported since 2022. The quarter saw increases in several categories including denylisted resources, malicious documents, worms, ransomware, and AutoCAD-targeting malware, while email was the only delivery source to increase globally.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.