HomeLatest NewsCyber SecurityIndustrial ransomware attacks see 46% quarterly spike

Industrial ransomware attacks see 46% quarterly spike

Ransomware attacks on energy, manufacturing and critical sectors rise sharply in early 2025, necessitating urgent need for stronger cybersecurity measures across industrial operations.

Preferred Source of Google

attacks targeting industrial operators increased by 46% in the first quarter of 2025 compared to the previous quarter, according to a new cybersecurity threat report.

The findings highlight growing risks to critical infrastructure sectors such as energy, manufacturing and utilities, which are becoming frequent targets due to their dependence on uninterrupted operations.

The analysis, based on billions of cybersecurity logs and thousands of threat events, documents a marked rise in both ransomware and malware activity during the period under review.

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

A significant contributor to this trend was the proliferation of credential-stealing trojans, with one variant, W32.Worm.Ramnit, accounting for over one-third of all malicious files blocked. This marks a 3,000% increase in activity for the trojan compared to the previous quarter.

“Industrial operations across critical sectors like energy and manufacturing must avoid unplanned downtime as much as possible – which is precisely why they are such attractive ransomware targets,” said Paul Smith, director of operational technology cybersecurity engineering and author of the report.

“These attackers are evolving fast, leveraging ransomware-as-a-service kits to compromise the industrial operations that keep our economy moving,” Smith said.

Advertisement

The report also identified 2,472 potential ransomware attacks in the first quarter of 2025 alone, representing 40% of the total volume recorded for the entire previous year. This surge indicates a steady escalation in the frequency and ambition of cybercriminal campaigns.

USB-based threats continue to be a persistent risk for operational systems, with 1,826 unique threats detected in the same quarter. Of these, 124 were previously unidentified, underlining the evolving nature of malware delivered through removable media.

This trend builds on a 33% increase in USB malware detections in 2023, following a 700% rise in 2022.

Advertisement

The report further noted that threats are also being introduced via commonly used plug-in hardware such as charging cables, external mice and laptops—devices often connected during maintenance or software updates in industrial environments.

The US Cybersecurity and Infrastructure Security Agency (CISA) classifies incidents as substantial when they enable unauthorised access that causes operational disruption or impairment. Industry suggests that such disruptions cost large companies an estimated $1.5 trillion annually, equating to approximately 11% of their revenue.

“With increasingly significant threats and updated SEC reporting regulations requiring the disclosure of material cybersecurity incidents, industrial operators must act decisively to mitigate costly unplanned downtime and risks, including those linked to safety,” Smith said.

“Leveraging Zero Trust architecture and for security analysis can speed detection and enable smarter decision making and proactive in an increasingly complex digital landscape,” he said.

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

India to Lead Global IT Security Standards Body for Two Years

India will chair the Common Criteria Development Board from April 2026, gaining influence over international IT security certification standards recognised by 38 countries.

RELATED ARTICLES