Dragos has published the 2025 OT/ICS Cybersecurity Report, a comprehensive report of cyber threats facing industrial organizations. The report says that ransomware activity surged at an increase of more than 87% over the last year and describes the emergence of new malware families designed specifically for OT environments.
“This year’s report demonstrates two important trends; that operational technology (OT) has become a mainstream target, and that even advanced cyber operations are employing unsophisticated tactics to compromise and disrupt critical infrastructure,” said Robert M. Lee, Co-founder and CEO of Dragos. “Skilled adversaries from state-sponsored groups are hiding in critical infrastructure and hacktivists and criminal groups are increasingly using ransomware and exploiting known vulnerabilities, weak remote access configurations, and exposed OT assets to penetrate industrial environments. Meanwhile lack of visibility into OT conceals the full scope of these attacks.”
“However, it’s important to recognize the progress made by OT defenders,” Lee added. “We’ve seen organizations implement stronger network segmentation, improve visibility into their OT environments, and develop more robust incident response capabilities. These proactive measures are making it harder for adversaries to operate undetected and are key to the long-term resilience of industrial cybersecurity.”
Other key findings include:
Geopolitical conflicts fuel OT-centric cyber operations: adversaries aligned with state-backed initiatives continue to launch cyber operations targeting critical infrastructure in Ukraine, Russia, and the Middle East, often as a direct extension of military conflicts.
Hacktivist groups escalate attacks on critical infrastructure: in 2024 hacktivists leveraged new attack vectors to target OT environments, disrupting energy and water utilities while aligning their actions with geopolitical motivations. In 2023 and into early 2024, Dragos observed a trend of hacktivist groups, or self-proclaimed hacktivist groups, actively targeting and achieving Stage 2 of the ICS Cyber Kill Chain against industrial organizations and critical infrastructure and services worldwide.
State-sponsored threat actors and hacktivism converge: increasing collaboration between hacktivist groups and state-backed cyber actors has led to a hybrid threat model where hacktivists amplify state objectives, either directly or through shared infrastructure and intelligence. State actors increasingly look to exploit hacktivist groups as proxies to conduct deniable cyber operations, allowing for more aggressive attacks with reduced attribution risks.
Hacktivists start using ransomware: hacktivist and self-proclaimed hacktivist groups are now employing ransomware as part of an evolution of their operations against a variety of industrial targets.
Ransomware activity surges: the number of ransomware groups targeting industrial organizations jumped to 80, a 60% increase from the 50 groups observed in 2023. Collectively, these groups attacked an average of 34 industrial organizations per week during the first half of 2024. That number more than doubled during the second half of the year. Manufacturing remains the most affected sector, accounting for more than 50% of observed ransomware victims. 25% of the ransomware cases that Dragos observed involved full shutdown of an OT site, and 75% involved disruption to operations to some degree.
Vulnerabilities carry risk of deep impact on industrial processes: in 2024, Dragos found that 70% of the vulnerabilities researched were deep within the ICS network, 39% could cause both a loss of view and a loss of control, and 22% of advisories were network-exploitable and perimeter-facing, rising from 16% in 2023.
It’s time to hunt: enhancing industrial cybersecurity resilience
Adversaries have evolved, leveraging increasingly sophisticated attack methods to infiltrate industrial environments. The data from the report is clear: organizations that take proactive security measures experience shorter recovery times, reduced financial losses, and minimized operational disruptions. Threat hunting is no longer an option—it is a necessity.
Industrial organizations must move beyond reactive security measures and embrace threat hunting as a fundamental defense strategy. Attackers are exploiting known vulnerabilities, remote access weaknesses, and supply chain gaps at an accelerating rate. Organizations that proactively search for threats and adversarial activity within their environments gain a crucial advantage in preventing attacks before they escalate.
ICS defenders must be relentless. Attackers are already inside networks, and the ability to hunt them down before they cause damage is the next evolution of industrial cybersecurity. Now, more than ever, it’s time to hunt, says the report.






