VYPR
trendPublished Aug 27, 2026· 1 source

Industrial Automation Systems Face Shifting Threat Landscape in Q2 2026

Kaspersky's latest report reveals a global decrease in blocked malware on industrial control systems, though specific regions and the biometrics sector show rising threats.

Kaspersky's Q2 2026 report on the threat landscape for industrial automation systems (IAS) indicates a continued global decline in the percentage of Industrial Control System (ICS) computers encountering malicious objects, falling to 19.15%. This marks the lowest figure since 2022, suggesting a general improvement in security posture across the sector. However, this downward trend is not uniform, with notable increases observed in East Asia and Africa, highlighting regional disparities in cybersecurity resilience.

The report details significant regional variations, with Northern Europe experiencing the lowest attack percentage at 8.1%, while Africa recorded the highest at 27.9%. East Asia and Africa were among the five regions that saw an increase in attacked ICS computers over the quarter. East Asia, in particular, experienced a 2.0 percentage point rise, with threats increasing across most categories except for miners. The region also led in the growth of malicious scripts, phishing pages, spyware, and viruses, alongside an increase in threats originating from the internet and email-borne threats.

The biometrics sector emerged as a primary target, consistently ranking high in the percentage of ICS computers affected by malicious objects. This vulnerability is attributed to the sector's common reliance on internet access, extensive email usage for data exchange, and often insufficient cybersecurity controls. Biometric systems were particularly susceptible to malicious scripts, phishing pages, malicious documents, spyware, ransomware, and worms, with email threats posing a greater risk than internet threats in this sector.

Globally, several threat categories saw an increase in their prevalence on industrial automation systems. Denylisted internet resources climbed to second place in threat rankings, with a global average of 4.31% and a notable surge in Russia. Malicious documents also saw an uptick after a period of decline, particularly in South America and Southern Europe, with the biometrics industry being a common target in both regions. Spyware, while still a significant threat, saw its percentage decrease globally, though East Asia and Southeast Asia experienced increases.

Malicious scripts and phishing pages (JS and HTML) remained the most prevalent threat category, despite a global average decrease to 5.42%. East Asia was the only region to see an increase in this category, with biometrics and building automation systems being the most affected industries. The rise of denylisted internet resources, displacing spyware from the second position, indicates a growing reliance on malicious websites and infrastructure to deliver threats.

While the overall percentage of ICS computers affected by malware has decreased, the report underscores the persistent and evolving nature of threats targeting industrial environments. The concentration of attacks in specific sectors like biometrics and the regional increases in East Asia and Africa warrant focused attention. The continued prevalence of malicious scripts, phishing pages, and the rise of denylisted internet resources highlight the ongoing need for robust security measures and vigilance within industrial control systems.

The findings suggest that while broad security improvements are being made, attackers are adapting their tactics, focusing on specific vulnerabilities within certain industries and regions. The report serves as a critical reminder for organizations operating critical infrastructure to stay informed about emerging threats and to continuously assess and strengthen their defenses against a dynamic threat landscape.

Synthesized by Vypr AI