Kaspersky has reported an increase in cyberattacks targeting industrial organisations during the first quarter of 2026, with manufacturing environments experiencing growing levels of malicious activity across multiple regions.
According to a new report from Kaspersky ICS CERT, malicious objects were blocked on 19.6% of industrial control systems (ICS) globally during the quarter. Kaspersky security solutions detected malware from 10,052 different malware families targeting industrial automation systems.
Regionally, the share of attacked ICS computers ranged from 27.4% in Africa to 9.1% in Northern Europe. Compared with the previous quarter, Kaspersky recorded increases in attacks against manufacturing organisations in several regions, including Europe and Asia.
The report found that Southeast Asia experienced the highest proportion of attacks on manufacturing ICS computers at 23.21%, followed by Africa at 21.36% and South Asia at 20.13%.
Kaspersky also highlighted the financial impact of cyberattacks on manufacturers. Research conducted by Kaspersky and VDC Research estimated that ransomware attacks against manufacturing organisations generated more than US$18 billion in losses globally during the first three quarters of 2025, excluding wider costs such as supply chain disruption, reputational damage and recovery expenses.
“Legacy operational technology systems remain deeply embedded in manufacturing environments, which makes them vulnerable,” said Evgeny Goncharov.
“Supply chain complexity and branching of the trusted partner network expands the attack surface beyond the network perimeter.”


