In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15% — the lowest level recorded since 2022.
Global snapshot: decline to 19.15% and the continued diversity of threats
The broad headline from the quarter is one of decline: the global share of industrial control system (ICS) machines encountering blocked malicious objects slipped to 19.15%. Regionally, Kaspersky’s measurements ranged from 8.1% in Northern Europe to 27.9% in Africa. Across the dataset the vendor recorded activity from 10,904 different malware families targeting industrial automation systems.
Not all threat vectors moved in the same direction. Of the principal sources tracked, only email increased in Q2 2026: the percentage of ICS computers on which email threats were blocked rose to 2.84%. By contrast, threats attributed to the internet decreased to 7.61%, a low since 2021, while removable media (0.24%) and network folders (0.023%) continued their downward trajectories.
Region-level shifts: East Asia, Africa and Russia stood out
Five regions recorded quarter-on-quarter increases in overall percentages of affected ICS machines, most notably East Asia (up 2.0 percentage points) and Africa (up 0.5 pp). East Asia registered increases across almost every threat class except miners, and led growth for malicious scripts and phishing pages, spyware, viruses and internet-sourced threats. In East Asia the share of ICS computers on which malicious scripts and phishing pages were blocked rose by 0.93 pp to 4.86% — the region’s second-highest level in three years.
Africa remained the region with the highest overall percentage of attacked ICS computers (27.9%) and led quarterly growth for ransomware, reaching 0.29% (its highest since Q2 2025 except for that quarter). Russia showed a marked rise in denylisted internet resources — up 1.33 pp to 5.17% — making it the top region for that metric in Q2 2026.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIndustry focal points: biometrics, electric power, construction and building automation
The biometrics sector continues to top industry rankings, with 26.44% of ICS computers on which malicious objects were blocked. Kaspersky attributes the sector’s prominence to wide internet access, extensive email use for data exchange and approvals (for example, access granting), and, in many cases, minimal cybersecurity controls within the deploying organizations. Biometrics led industries for malicious scripts and phishing pages, malicious documents, spyware, ransomware and worms — and also for email threats; notably, email threats in biometrics exceeded internet-origin threats for that sector.
Electric power and construction also show concentrated risk in specific categories. In East Asia the electric power industry recorded the highest spyware figure among surveyed industries (11.75%), and in Africa electric power showed the largest ransomware figure among the region’s industries (0.72%). Construction sectors showed high virus and AutoCAD-malware exposure: viruses in Africa hit 5.47% for construction, while malware for AutoCAD in construction reached 6.38% in East Asia and 4.05% in Southeast Asia.
Shifting threat categories: denylisted internet resources, malicious scripts and AutoCAD malware
The category mix is changing. Malicious scripts and phishing pages remained the largest single category by reach, but the global average slipped to 5.42%. Denylisted internet resources climbed from third to second place among categories, rising to 4.31% globally and increasing in every region this quarter. Malicious documents ticked up to 1.77% after three quarters of decline, with Southern Europe (3.63%) and South America (3.56%) notable contributors.
Other movements of note: worms rose to 1.43% of ICS computers; ransomware recovered slightly to 0.16% after earlier declines; miners were at their lowest levels since 2021 (executable miners 0.48%; web miners 0.14%); and malware for AutoCAD increased to 0.31% globally, led by Africa at 1.02% and concentrated hotspots in construction in East and Southeast Asia.
What this means for technologists, procurement leaders, and regional operators
- Technologists and security teams: expect a mixed picture — internet-origin threats declined overall, but denylisted internet resources and email-origin threats rose. The diversity of active families (10,904) underscores continued need for layered detection and monitoring across web and email vectors.
- Procurement leaders and operators in biometrics and electric power: biometrics stands out with 26.44% of ICS machines affected and particularly high email-threat exposure (19.14% in Southern Europe for biometrics); electric power shows localized spikes in spyware and ransomware in some regions. Those purchasing or operating systems in these sectors should assume higher baseline exposure and plan control and monitoring investments accordingly.
- Regional operators and incident responders in East Asia and Africa: East Asia’s multi-category increases (malicious scripts, spyware, viruses and internet threats) and Africa’s overall highest regional rate (27.9%) and rising AutoCAD malware suggest region-specific prioritization of detection rules and sector-focused threat hunting.
The quarter’s record is mixed: fewer ICS machines were flagged overall, but certain regions, sectors and categories expanded their footholds. Kaspersky’s dataset — 10,904 malware families observed against industrial automation systems — is a numeric reminder that risk has not abated; it has shifted. For details and the full regional and industry breakdowns, see the original report.
Original report — Threat landscape for industrial automation systems. Q2 2026




