ICS Threats in Q2 2026: What Defenders Should Know
Securelist’s Q2 2026 telemetry shows declining overall ICS detections but rising email, ransomware, worm, and malicious-document activity.
Industrial environments recorded a lower overall rate of blocked malicious activity in the second quarter of 2026, but the decline should not be mistaken for a uniform improvement in risk. Securelist, the research site operated by Kaspersky, reports that malicious objects were blocked on 19.15% of industrial control system (ICS) computers in its telemetry during Q2 2026. That was the lowest quarterly figure since 2022.
At the same time, several categories increased. Ransomware, worms, malicious documents, denylisted internet resources, and malware associated with AutoCAD all rose during the quarter. Email was the only reported threat source to increase, reaching 2.84% of ICS computers. The findings point to a familiar challenge for industrial operators: broad exposure may be falling, while selected attack paths remain active or are becoming more important in particular sectors and regions.
This analysis is based on Securelist’s statistical telemetry. The figures describe ICS computers on which Kaspersky security solutions blocked malicious objects; they do not, by themselves, establish successful compromise, operational disruption, or intrusion into a control process.
What Securelist observed
Kaspersky ICS CERT says its solutions blocked activity associated with 10,904 different malware families across multiple categories in Q2 2026. The source does not provide a list of those families in the supplied research, nor does it identify a specific threat actor, campaign, victim organization, exploit, or vulnerability. The most common category was malicious scripts and phishing pages using JavaScript or HTML, affecting 5.42% of ICS computers globally.
Denylisted internet resources moved into second place, reaching 4.31% and increasing for the second consecutive quarter. Spyware ranked third at 3.30%, its lowest level since 2022. Malicious documents, including Microsoft Office and PDF files, rose to 1.77% after declining over the previous three quarters. Worm detections increased to 1.43%, while viruses fell to 1.29%.
Ransomware affected 0.16% of ICS computers in the telemetry, an increase after three quarters of decline. Although that percentage is substantially lower than the leading categories, ransomware has a disproportionate potential effect in industrial settings because disruption to engineering workstations, operator systems, supporting servers, or production-adjacent infrastructure can create safety, availability, and recovery concerns.
Other categories declined. Windows executable miners fell to 0.48%, and browser-based web miners fell to 0.14%, both described as the lowest levels in the relevant reporting period. Malware for AutoCAD increased to 0.31%. The source gives no technical description of a particular AutoCAD malware family, so this category should be understood as a detection grouping rather than evidence of one named tool or campaign.
The reported exposure paths
Securelist divides observed sources into the internet, email, removable media, and network folders. Internet-originating threats remained the largest source category, although the percentage of ICS computers affected fell to 7.61%, the lowest level since 2021. Email moved in the opposite direction, increasing to 2.84%. Removable-media detections declined to 0.24%, while network-folder detections reached 0.023%, the lowest level in the period covered by the report.
These figures do not describe a single infection chain. Instead, they show several possible exposure channels visible in defensive telemetry. The prevalence of scripts, phishing pages, and malicious documents is consistent with the importance of web browsing and email controls around industrial networks. The report specifically notes that biometrics environments often have internet connectivity, extensive email use for approvals and data exchange, and limited cybersecurity controls. In that sector, email exposure exceeded internet exposure, making business communication systems an especially important defensive focus.
For defenders, the practical implication is not that removable media or network folders can be ignored. A lower aggregate percentage is not proof that a particular site is safe. Securelist identifies elevated examples, including electric-power systems in East Asia for removable-media threats and several East Asian industries for network-folder detections. Local architecture, maintenance practices, engineering workflows, and security coverage can make an individual facility materially different from a global average.
Regional and sector-specific signals
The overall percentage of affected ICS computers ranged from 8.1% in Northern Europe to 27.9% in Africa. East Asia recorded the most notable broad-based increases in several categories, including malicious scripts and phishing pages, spyware, viruses, and internet-originating threats. Africa led the regional ransomware ranking at 0.29% and also recorded the strongest growth in that metric. Securelist reports particularly high ransomware percentages in African electric-power and biometric environments.
The report highlights biometrics as the most affected selected industry overall, with 26.44% of ICS computers recording blocked malicious objects. The sector also ranked first for malicious scripts and phishing pages, malicious documents, spyware, ransomware, worms, and email threats. In Southern Europe, biometric systems had an email-threat figure of 19.14%, while building automation reached 12.49% for the same source.
Other notable observations include elevated spyware activity in East Asian electric-power environments, where the sector-specific figure was 11.75%, and high worm activity in Middle Eastern building automation, at 2.90%. Construction in East Asia and Southeast Asia recorded the highest reported percentages for AutoCAD-related malware among the selected industries. These are telemetry observations, not evidence that every organization in those sectors was targeted by a coordinated campaign.
Securelist also reports a sharp increase in virus detections in Australia and New Zealand’s electric-power sector, from 0.29% to 1.24%. The source describes this as a notable increase relative to the region’s overall rate. Such changes warrant local investigation, but the supplied research does not identify the underlying samples, delivery mechanism, or operational consequence.
Why the numbers require careful interpretation
Blocked-object statistics are valuable for comparing trends, but they are not a complete measure of industrial cyber risk. They reflect the security products deployed, the systems covered, the detection categories used, and the events that reached those controls. A decrease may indicate fewer observed events, improved blocking earlier in the chain, changes in technology deployment, or other factors not resolved by the report.
Similarly, a blocked phishing page or malicious document is not equivalent to a successful intrusion. The supplied research does not confirm execution, persistence, lateral movement, command-and-control activity, data theft, encryption of operational assets, or process manipulation. It also does not provide indicators of compromise, named malware families, CVE identifiers, MITRE ATT&CK mappings, or actor attribution. Those absences matter when converting sector-level statistics into incident-response decisions.
Detection and hunting priorities
Organizations should first verify that monitoring covers both enterprise and operational technology boundaries. Security teams can review web-proxy and DNS telemetry for access to denylisted or newly categorized resources, while examining endpoint alerts for scripts, malicious documents, spyware, worms, and ransomware-related behavior. Email security logs should be correlated with attachment type, sender reputation, authentication results, user interaction, and subsequent endpoint events.
Because the report shows increases in email and malicious documents, defenders should prioritize visibility into business workstations that exchange engineering files, approve access, or communicate with vendors. Hunting can focus on unusual document-opening activity, unexpected child processes from office or PDF applications, script execution from user-writable locations, and new outbound connections following document or browser events. These are general defensive investigation themes, not indicators attributed to the activity in Securelist’s report.
Industrial environments should also maintain asset inventories that distinguish safety systems, controllers, engineering workstations, operator stations, historians, servers, and ordinary office endpoints. Where technically and operationally feasible, telemetry from these classes should be analyzed separately. A single aggregate ICS number can conceal concentration in one system type or workflow.
What organizations should do now
- Strengthen email controls around OT-adjacent users. Use attachment and URL inspection, sender authentication, malware scanning, and quarantine workflows. Apply additional scrutiny to accounts involved in engineering approvals, vendor coordination, and access management.
- Reduce unnecessary internet exposure. Review outbound access from engineering and operator workstations, limit browsing to an approved business need, and use monitored gateways for systems that cannot be fully isolated.
- Segment industrial assets. Separate enterprise, DMZ, supervisory, engineering, and control zones according to operational requirements. Restrict communications between zones and document approved administration paths.
- Control removable media and file movement. Use authorized media, malware scanning, device control, and documented transfer procedures. Treat engineering files and AutoCAD-related content as sensitive workflow artifacts requiring provenance and review.
- Prepare for ransomware without assuming it is rare. Maintain tested offline or otherwise protected backups, recovery procedures, spare-system plans, and clear criteria for safely isolating affected assets. Exercise these plans with operations, engineering, safety, and management teams.
- Investigate regional or sector-specific spikes. Compare local detections with the relevant baseline, validate sensor coverage, and determine whether a change reflects a real event pattern or a telemetry shift.
Conclusion
Securelist’s Q2 2026 data presents a mixed picture: the overall share of ICS computers with blocked malicious objects declined, yet email, malicious documents, worms, ransomware, denylisted resources, and AutoCAD-related detections increased. The most useful response is not to focus on one headline percentage, but to improve visibility across the enterprise-OT boundary and prioritize the exposure paths most relevant to each facility. The report supports stronger email security, segmentation, removable-media governance, endpoint monitoring, and recovery readiness. It does not, on its own, establish a named campaign, actor, exploit, or successful compromise.
Sources
Securelist: Industrial threat report for Q2 2026, by Kaspersky ICS CERT.