Industrial cyber incidents climb 12% as cover gap widens

Surge is testing Australia's ability to manage industrial cyber risk - and most industrial businesses are uninsured when it hits

Industrial cyber incidents climb 12% as cover gap widens

Cyber

By Jonalyn Cueto

Ransomware attacks on industrial organisations climbed 12% globally in the second quarter of 2026, according to new data from operational technology security firm Dragos, adding pressure to a local cyber insurance market where uptake is already falling.

Dragos recorded 1,140 ransomware incidents affecting industrial organisations worldwide in Q2 2026, up from 1,020 in Q1, according to its Q2 2026 industrial ransomware analysis. Manufacturing remained the hardest-hit sector, with 747 incidents - 65% of the total. Firms supporting industrial control system environments, such as engineering companies and equipment manufacturers, recorded a further 117 incidents, while transportation and logistics operators accounted for 95.

Australia and New Zealand recorded 19 industrial ransomware incidents in the quarter, unchanged from the first three months of the year, with manufacturing and logistics businesses the most affected. In a country where manufacturing and logistics together employ more than one million people, 19 tracked incidents in a single quarter - in a sector that Dragos notes is likely undercounting unreported events - represents a significant exposure for businesses that are increasingly going without cover. North America recorded 514 incidents in Q2, Europe 316, and Asia 172.

IT systems, not control systems, drive disruption

Dragos said it observed no ransomware operator directly manipulating an industrial control system during the quarter. Disruption instead tended to follow the encryption of enterprise IT systems, or precautionary shutdowns of virtualisation infrastructure, when production depended on connected services such as ERP platforms, identity management and remote access tools.

That pattern is the critical insurance distinction. An industrial cyber claim that arises from encrypted IT systems causing OT shutdown does not clearly fall under all policy wordings in the same way as a direct OT compromise. Whether an insured's cyber policy covers IT-caused operational technology disruption - where the ICS itself was not directly breached but production halted nonetheless - varies across the market and is exactly the question most industrial clients have not asked their broker.

That pattern played out at Mackay Sugar, Australia's second-largest raw sugar producer, after a cyber incident on June 10, 2026 forced two of its three Queensland mills to halt milling and cane haulage days into the crushing season. The ransomware group known as The Gentlemen later listed the company on its data leak site. Mackay Sugar's public updates did not disclose whether the attackers reached its industrial control systems or whether those systems were affected indirectly through IT infrastructure disruption - a distinction that would be directly relevant to how any cyber insurance claim was assessed.

Dragos recorded 140 incidents attributed to Qilin, followed by 129 involving Akira and 125 involving The Gentlemen. The three groups accounted for a large share of tracked activity. Dragos also reported continued exploitation of internet-facing infrastructure and compromised credentials, alongside a rise in social engineering through Microsoft Teams, with attackers posing as internal IT support to persuade staff to install remote-monitoring tools.

Coverage gap widens as data-theft extortion grows

Dragos also pointed to a broader shift toward data-theft-only extortion, in which attackers threaten to publish stolen material rather than rely solely on encryption. For industrial firms, that extends exposure beyond downtime to engineering documents, technical specifications, and credentials that touch suppliers and contractors. Whether a policy responds to a data-theft threat that involves no encryption event is a wording question most industrial clients have not asked either.

The findings arrive as fewer Australian businesses carry cyber cover. The Australian Institute of Criminology's Cybercrime in Australia 2025 report recorded a second consecutive annual fall in cyber insurance take-up among individuals surveyed, down to 3.7% from 4.6% the year before - a metric that directionally tracks business uptake and points the wrong way in a year of rising industrial incident frequency. Separately, QBE Insurance Group data found the gap between initial network access and ransomware deployment has fallen roughly 70% since 2021, leaving less time for detection before damage occurs.

Three questions for brokers with industrial clients

Dragos said ransomware attacks on industrial organisations are likely to continue globally, and that incidents can cascade into operational technology environments even when attackers lack specialised ICS expertise. For brokers with manufacturing, engineering, logistics or utilities clients, three coverage questions follow directly from this data.

First, does the client's cyber policy cover IT-caused operational technology disruption? Not all wordings respond to shutdown of production systems when the ICS itself was not directly compromised. Second, does the policy trigger on data theft alone, without encryption? Purely exfiltration-based extortion is increasing and some policies define a trigger narrowly around encryption events. Third, does the business interruption limit reflect the extended recovery timeline typical of industrial incidents? A manufacturer restarting a milling operation or a logistics operator restoring an ERP platform may face a recovery period well beyond the indemnity period on a standard cyber policy. Each of these questions has a different answer depending on the specific wording, and each determines whether a client who suffers an industrial ransomware incident ends up with a claim or a gap.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!