Skip to content

Ransomware on support systems halts OT production – without directly targeting OT

Bottom line: Modern industrial facilities are threatened by extended OT environments (xOT) in which virtualization, SCADA support, and cloud systems are attacked – paralyzing production without the machines themselves being compromised.

Dragos documents in its latest report that ransomware attackers are increasingly targeting industrial operations via IT-adjacent and virtualized systems – not the control technology itself. The result: production standstills despite fully functional plants.

Dragos observed a characteristic attack: After attackers gained entry via a compromised VPN access point, they obtained access to an OT-adjacent virtualization system and deployed ransomware across multiple virtual machines. The production facilities remained operational, but the failure of the virtualization layer destroyed critical monitoring and control functions – operations came to a halt until recovery.

The threat landscape is considerable: Dragos identified 119 ransomware groups deliberately targeting industrial enterprises (previous year: 80 groups). Approximately 3,300 industrial enterprises were affected. In the first quarter of 2026, Dragos registered 1,020 ransomware incidents globally in industrial enterprises, with a focus on the manufacturing industry. Notably: there was no evidence of OT-specific ransomware – attackers instead exploit standard vulnerabilities in IT systems.

The typical attack sequence begins with stolen credentials (via infostealer malware or initial-access brokers), followed by logon via VPN, firewall interfaces, or other remote access mechanisms. From there, attackers move into virtualized infrastructure where SCADA systems, HMIs, historian systems, and engineering workloads run. These platforms are attractive because their failure immediately destroys critical functions (monitoring, operation, maintenance).

For CISOs and OT managers, it is critical to understand: classifying an incident as an “IT security incident” misses the point when an attack on OT-adjacent systems leads to production shutdown. The so-called Extended Operational Technology (xOT) encompasses all systems that exert influence over physical processes – regardless of system classification or network assignment. Those who define protection scope only by classification, not by actual operational impact, obtain an incomplete situational picture.


Source: www.it-daily.net · Published 21 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: