Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Dragos observed 312 ransomware incidents affecting industrial organizations and infrastructure in April–June 2024, compared with 169 in the first quarter—an increase of about 85%. The figures come from Dragos’s tracking of public reporting and dark-web data, not a complete census of every attack. Manufacturing made up the largest share. Dragos reported no ransomware attacks directly targeting industrial control system (ICS) or operational technology (OT) processes during the quarter, although IT incidents can still disrupt industrial operations through IT/OT dependencies.
What changed in Q2 2024?
Dragos’s Industrial Ransomware Analysis: Q2 2024, published August 14, 2024, recorded 312 observed incidents, versus 169 in its Q1 analysis. That is about 1.85 times the earlier count; Dragos described the number as having “almost doubled.” The comparison describes a change in Dragos’s observed dataset, not a measured increase in every industrial company’s individual risk.
Dragos compiled information from public reporting and data on dark websites, including victim listings and entities reported to have paid or cooperated. The company cautions that these records do not correspond one-to-one with all incidents that occurred. The totals, sector and regional breakdowns, and group attributions should therefore be read as reported observations rather than a comprehensive industry-wide count. Dragos, Industrial Ransomware Analysis: Q2 2024; Dragos, Industrial Ransomware Analysis: Q1 2024.
Free tools Windows power users keep installed
One-click scans. No signup required.
Which industries and regions accounted for the observations?
Sector breakdown
Manufacturing accounted for 210 of the 312 Q2 observations, or about 67%. The next-largest grouping was industrial control systems equipment and engineering, with 47 incidents (15%). Transportation had 23 (7%); government, 8 (3%); oil and natural gas, 7 (2%); and communications, 5 (2%). Dragos also reported three incidents each in mining, electric, renewables, and water. Percentages are rounded as reported.
#1 Best Overall
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
Within manufacturing, Dragos broke the data into 23 subsectors. Construction led with 33 observations; consumer and food and beverage each had 27. These are counts in the same public-source dataset, not independently verified totals for each sector.
Regional breakdown
North America accounted for 187 observations (about 60%) and Europe for 82 (about 26%). Dragos counted 29 in Asia (about 10%) and 6 in South America (about 2%); eight more were grouped across the Middle East, Australia, and Africa. Percentages are rounded. Because the collection depends on public reporting and dark-web listings, these figures describe where observed victims were attributed, not necessarily the true geographic distribution of all attacks. Dragos’s Q2 2024 report.
Which ransomware groups appeared most often?
Dragos recorded 29 groups active in Q2, up from 22 in Q1, among 86 groups it said were known to target industrial organizations. LockBit was associated with 66 Q2 observations, about 21% of the total; Play was associated with 31, about 10%. “Associated” is important: public victim claims and reporting can be incomplete, and the report’s collection method does not make these figures a verified count of attacks conducted by each group.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Did ransomware directly target industrial control systems?
Dragos said it identified no ransomware attacks directly targeting ICS or OT processes in Q2 2024. That does not mean industrial operations were unaffected. The report describes OT-network disruption arising primarily from IT/OT interdependencies: for example, an incident in corporate IT can interrupt systems, services, or supply chains that industrial operations rely on without encrypting or controlling an industrial process itself.
The report’s examples illustrate why those outcomes should not be conflated. Frontier Communications shut down some systems, with material operational disruption. Allied Telesis experienced encrypted corporate files and data theft that disrupted telecommunications equipment supply operations. A bio-energy plant incident involved SCADA access and data exfiltration. For Clevo, Dragos said the exact operational impact was not fully known. These cases differ in what was affected; none should be generalized into proof that ransomware directly compromised an ICS process across the quarter.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What does the later 2024 trend add?
Dragos’s 2025 retrospective says an average of 34 industrial organizations were attacked per week during the first half of 2024, and that the weekly rate more than doubled in the second half. That retrospective uses a broader annual view and a weekly-rate framing; it is not the same metric or dataset as the 312 Q2 observations. Dragos, 2024 Year in Review.
Quick Recap
Rank #4
How to interpret the headline
- The observed count rose sharply: Dragos recorded 312 incidents in Q2 versus 169 in Q1 using its public-source tracking.
- Manufacturing dominated the recorded sectors: it accounted for about two-thirds of Q2 observations.
- More incidents do not automatically mean more direct OT compromise: Dragos reported no direct ransomware targeting of ICS/OT processes, while describing operational effects mediated through IT/OT dependencies.
- The counts are not a complete incident census: reporting gaps and the source methodology limit what can be inferred about the true total or relative risk to a particular firm.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

