Quick Takeaways
- Malicious scripts, phishing pages, and denylisted internet resources remain the top attack vectors, with increases notably in East Asia and Russia, targeting ICS environments.
- Ransomware activity surged, especially in Africa and the biometric industry, with a 0.16% overall increase and some regions experiencing a sharp rise in infection rates.
- Threat actors increasingly use email-based attacks and malware-laden documents, while attacks via removable media and network folders continue declining but still pose residual risks.
Threats, Attack Techniques, and Targets
In Q2 2026, the percentage of ICS computers blocked with malicious objects fell to 19.15%, the lowest since 2022. Although the overall threat level decreased globally, East Asia and Africa saw increases of 2.0 and 0.5 percentage points respectively. The main threats include malicious scripts, phishing pages, denylisted internet resources, malicious documents, worms, ransomware, malware for AutoCAD, spyware, viruses, miners, and worms. Malicious scripts and phishing pages remain the top threat categories worldwide, especially in East Asia’s biometric and building automation sectors. The report shows an increase in threats via email, with biometric systems and building automation being most affected. Notably, denylisted internet resources became increasingly prevalent, particularly in Russia’s electric power and engineering industries. Threat actors employ diverse attack techniques, primarily relying on internet-based methods, malicious documents, and email campaigns targeting industries with extensive internet use and minimal cybersecurity defenses.
Impact, Security Implications, and Remediation Guidance
The rise in threat activity indicates ongoing risks to industrial control systems, which could lead to operational disruptions or data breaches. The variety of malware—including ransomware, worms, and spyware—poses significant security concerns, especially for sectors like biometrics, building automation, and electric power. These threats can compromise safety, disrupt processes, and result in financial losses. Security teams should prioritize protecting internet interfaces, email traffic, and removable media. To reduce risks, organizations must strengthen cybersecurity measures, update defenses, and monitor network activity actively. Because specific remediation guidance is not provided in the report, organizations should consult their cybersecurity vendors or relevant authorities for tailored security strategies.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
