<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Ransomware Groups Targeting Industrial Systems Surge 49% in 2025

Ransomware attacks on industrial firms surge in 2025, exploiting VPNs and stolen credentials, warns Dragos. Manufacturing hit hardest.
Content Team

Cybercriminals are increasingly targeting industrial organizations, with 119 ransomware groups tracked in 2025 compared to 80 in 2024, according to Dragos researchers. Over 3,300 industrial organizations worldwide were hit by ransomware attacks, nearly double the 1,693 affected in 2024.

Manufacturing led as the most targeted sector, followed by transportation, oil and gas, electricity, and communications. Attackers primarily exploited remote-access portals like VPNs using stolen credentials obtained through phishing, malware, or dark web purchases.

The average "dwell time" before ransomware deployment was 42 days, allowing criminals to move quietly between IT and operational technology systems. One group used compromised VPN access to target SCADA virtual machines, causing operational delays despite not directly touching industrial equipment.

Dragos CEO Robert M. Lee warns that without comprehensive monitoring, future technologies like AI and distributed energy will create even greater security blind spots.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo