{"id":7612,"date":"2026-03-14T09:15:00","date_gmt":"2026-03-14T09:15:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5362\/"},"modified":"2026-07-09T17:16:38","modified_gmt":"2026-07-09T17:16:38","slug":"ot-security-2026-119-ransomware-groups-target-industrial-facilities","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/14\/ot-security-2026-119-ransomware-groups-target-industrial-facilities\/","title":{"rendered":"OT Security: 119 Ransomware Groups Target Industrial Facilities"},"content":{"rendered":"<p><span style=\"background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;font-weight:600;\">8 Min Read<\/span><\/p>\n<p><strong>119 active ransomware groups are now specifically targeting industrial facilities \u2013 49 percent more than last year. Dragos has identified three new threat actor groups specializing in operational technology: Sylvanite, Azurite, and Pyroxen. At the same time, Forescout reported a record high of 508 ICS advisories disclosing 2,155 vulnerabilities in 2025. For operators of critical infrastructure, OT security is no longer optional \u2013 it&#8217;s a matter of survival.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\">\ud83c\udfed 119 ransomware groups focused on industry, up 49% from last year (Dragos, 2025).<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\">\u26a0\ufe0f 508 ICS advisories with 2,155 vulnerabilities in 2025 \u2013 the highest number ever recorded (Forescout).<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\">\ud83d\udd0d 3 new OT threat actor groups identified: Sylvanite, Azurite, and Pyroxen (Dragos).<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\">\ud83d\udca5 Over 60 hacktivist groups become active within hours of geopolitical escalations.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\">\ud83d\udee1\ufe0f IT-to-OT pivoting is the growing primary attack vector \u2013 network convergence without protection.<\/li>\n<\/ul>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The Threat Landscape: More Groups, More Vulnerabilities, More Attacks<\/h2>\n<p>The latest OT\/ICS report from <a href=\"https:\/\/www.dragos.com\/year-in-review\/\" target=\"_blank\" rel=\"noopener\">Dragos<\/a> paints an alarming picture. The number of ransomware groups specifically targeting industrial organizations has risen to 119 \u2013 49 percent more than the previous year. These are no amateurs: the three newly identified groups, Sylvanite, Azurite, and Pyroxen, demonstrate a level of sophistication that even seasoned OT security experts find concerning. Related reading: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/28\/ot-security-2026-why-industry-must-act-now\/\">OT Security 2026<\/a>.<\/p>\n<p>Sylvanite focuses on energy providers in Western Europe. Azurite targets manufacturing companies with connected SCADA systems. Pyroxen specializes in logistics and transportation infrastructure. All three use IT networks as entry points and then move laterally into OT environments. The pattern is consistent: compromised VPN access or phishing in IT, followed by pivoting through unsecured gateways into production control systems.<\/p>\n<blockquote style=\"margin:32px 0;padding:24px 28px;background:linear-gradient(135deg,#f0f7ff 0%,#e4f1fd 100%);border-left:4px solid #69d8ed;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.5;color:#69d8ed;\">\n<p>\u201cThe convergence of IT and OT creates efficiency \u2013 but also an attack surface that many industrial organizations still don\u2019t fully understand. The boundary between these two worlds is often the weakest link.\u201d<\/p>\n<p><cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">Dragos OT\/ICS Year in Review, 2025<\/cite>\n<\/p><\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">IT-to-OT pivoting: Why classic segmentation isn\u2019t enough<\/h2>\n<p>Most industrial companies installed a firewall between IT and OT at some point and considered the job done. Reality tells a different story: remote maintenance access for machine manufacturers, historian servers streaming production data to the cloud, ERP connections to the manufacturing control system. Each of these links is a potential attack vector.<\/p>\n<p>The Purdue Model (the classic reference architecture for <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/13\/zero-trust-network-segmentation-why-flat-networks-are-the-biggest-security-risk\/\" target=\"_blank\" rel=\"noopener\">OT segmentation<\/a>) calls for strict layer separation: Enterprise (Level 4\u20135), DMZ (Level 3.5), Manufacturing Operations (Level 3), Control (Level 2), Field (Level 0\u20131). In practice, most organisations never implemented this separation cleanly or have eroded it over the years.<\/p>\n<p>Forescout reports that 38 % of OT vulnerabilities lie in Levels 3 and 4 \u2013 exactly the zone that should act as the DMZ. In other words, even companies with OT segmentation often fail to protect the very layer that is supposed to buffer IT from OT.<\/p>\n<div class=\"evm-stat evm-stat-row\" style=\"display:flex;gap:16px;margin:32px 0;\">\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">119<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Ransomware groups (industrial)<\/div>\n<\/p><\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">2.155<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">ICS vulnerabilities (2025)<\/div>\n<\/p><\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">+49 %<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Increase in attacker groups YoY<\/div>\n<\/p><\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Hacktivism: When geopolitics becomes an operational disruption<\/h2>\n<p>A new threat vector is intensifying the risk: hacktivism targeting industrial facilities. Dragos documents that within hours of geopolitical escalations more than 60 hacktivist groups swing into action. Their targets: SCADA systems, waterworks, power utilities. The attacks are technically simple \u2013 default credentials, exposed HMIs \u2013 but the impact is real: operational downtime, data exfiltration, public embarrassment.<\/p>\n<p>For German industrial companies this is relevant because hacktivism does not discriminate by company size or sector. A mid-sized supplier with an unprotected PLC on the public internet can be hit just as easily as a DAX-listed conglomerate. The KRITIS umbrella act and NIS2 sharpen liability: operators of critical infrastructure must prove they have implemented adequate protective measures.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What industrial companies need to do now<\/h2>\n<p><strong>Step 1: Asset inventory of the OT environment (immediately).<\/strong> You cannot protect what you do not know. Catalog every device in the OT environment: PLCs, HMIs, historian servers, network switches, remote-maintenance links. Passive scanning tools such as Claroty, Nozomi Networks or Dragos Platform map OT networks without disrupting operations.<\/p>\n<p><strong>Step 2: Secure every IT\/OT transition (this week).<\/strong> Every data path between IT and OT must be guarded by a dedicated firewall with whitelist rules \u2013 no \u201cany-to-any\u201d policies. Remote-maintenance access only via jump hosts with MFA. Audit vendor VPNs and set strict time limits.<\/p>\n<p><strong>Step 3: Deploy OT-specific monitoring (1\u20133 months).<\/strong> Standard IT SIEMs do not understand OT protocols (Modbus, S7, DNP3). Install OT monitoring with anomaly detection. Claroty, Nozomi and Dragos offer solutions that parse industrial protocols and flag anomalous communication patterns.<\/p>\n<p><strong>Step 4: OT incident-response plan (1\u20133 months).<\/strong> An IT incident-response plan is useless when the production line is down. OT IR prioritises safety over data confidentiality. Define who can trigger an emergency stop, how manual production continues, and how control systems are restored from clean backups.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The Counterargument: OT Security Is Expensive and Slows Production<\/h2>\n<p>Many industrial companies resist OT security projects. The objections: passive scans can still disrupt controls, firewalls between IT and OT slow data flows, and the cost of OT monitoring platforms (\u20ac50,000 to \u20ac200,000 per year) is significant for mid-sized firms.<\/p>\n<p>The response to these concerns is straightforward: what\u2019s the cost of a production outage? ThyssenKrupp estimated its 2022 cyber incident at a double-digit million-euro sum. Norsk Hydro lost more than \u20ac70 million to ransomware in manufacturing in 2019. Investing in OT security is a fraction of the potential damage. And passive monitoring solutions demonstrably do not affect production operations.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Conclusion: OT Security Is the Next Mandatory Discipline<\/h2>\n<p>119 ransomware groups, 2,155 ICS vulnerabilities, three new attacker groups specialising in industrial targets. The threat landscape for operational technology has never been more serious. NIS2 and the KRITIS umbrella law make OT security a <a href=\"https:\/\/www.digital-chiefs.de\/cybersecurity-budget-2026-was-der-cfo-vom-ciso-hoeren-muss\/\" target=\"_blank\" rel=\"noopener\">CEO-level obligation<\/a>. If you lack an asset inventory today, no IT\/OT segmentation, and no OT monitoring, you\u2019re walking straight into the next incident. The first step costs nothing: compile a list of every device and connection in the OT environment. Step two: audit remote-access pathways. Both are achievable within a week.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>We\u2019re not a KRITIS operator. Does OT security still apply to us?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. Ransomware groups don\u2019t distinguish between KRITIS and non-KRITIS targets. If you run a connected production line, you\u2019re in their sights. Moreover, NIS2 broadens the circle of affected companies substantially: many suppliers and service providers now fall under the obligations even if they don\u2019t operate critical infrastructure themselves.<\/p>\n<\/details>\n<details>\n<summary><strong>Can passive OT monitoring really avoid disrupting production?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Exactly. Passive monitoring solutions (Claroty, Nozomi, Dragos) analyse network traffic via mirror ports (SPAN) or network TAPs. They send no packets into the OT network and therefore cannot influence controllers. Active scans (such as Nmap or Nessus), by contrast, should never be used in OT environments because they can crash PLC controllers.<\/p>\n<\/details>\n<details>\n<summary><strong>What\u2019s the entry-level cost of OT security for a company with three production sites?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Asset inventory can be done with built-in tools (network scans, documentation). Dedicated OT monitoring platforms start at \u20ac15,000 per site per year for the base licence. For three sites, budget \u20ac50,000 to \u20ac80,000 annually. Add one-off implementation costs of \u20ac20,000 to \u20ac40,000. Against that stand average incident costs of \u20ac1.8 million (Sophos) to \u20ac70 million (Norsk Hydro).<\/p>\n<\/details>\n<details>\n<summary><strong>Our machine builders demand remote access. How do we secure that?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Remote access is the most common attack vector in OT environments. Three immediate actions: first, route all remote access through a central jump host (no direct SPS access). Second, enforce MFA for every remote session. Third, impose time limits: enable remote sessions only on request (no always-on VPN). Log every session with timestamp and actions performed.<\/p>\n<\/details>\n<details>\n<summary><strong>How do the KRITIS umbrella law and NIS2 relate to OT security?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The KRITIS umbrella law governs physical security and resilience of critical infrastructures. NIS2 governs cyber security. Together they mean: operators must manage both physical and digital risks, senior management is personally liable, and the BSI can conduct audits. For OT environments this translates into concrete obligations: network segmentation, monitoring, incident response and regular testing are no longer recommendations \u2013 they\u2019re mandatory.<\/p>\n<\/details>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Further Reading in the Network<\/h2>\n<ul style=\"list-style:none;padding:0;margin:0;\">\n<li style=\"margin-bottom:12px;\">\u2192 <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/13\/zero-trust-network-segmentation-why-flat-networks-are-the-biggest-security-risk\/\" target=\"_blank\" rel=\"noopener\"><strong>Zero-Trust Network Segmentation: Why Flat Networks Pose the Greatest Risk<\/strong><\/a> (SecurityToday)<\/li>\n<li style=\"margin-bottom:12px;\">\u2192 <strong>Mastering DORA and NIS2 in Parallel: Tackling the Compliance Double Challenge<\/strong> (SecurityToday)<\/li>\n<li style=\"margin-bottom:12px;\">\u2192 <strong>KRITIS Umbrella Act in Force: Mandatory Steps for Operators by July<\/strong> (SecurityToday)<\/li>\n<\/ul>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/03\/13\/tls-certificates-2026-why-200-day-validity-means-the-end-of-manual-management\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-tls-zertifikate-2026-warum-200-tage-lauf-6313409.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">TLS Certs 2026: 200-Day Validity Ends Manual Management<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/bitkom-ai-study-2026-41-of-companies-use-ai-smes-catch-up\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bitkom-ki-studie-2026-41-prozent-unterne-84045783-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Bitkom AI Study 2026: 41% of Companies Use AI, SMEs Catch Up<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"8 Min Read 119 active ransomware groups are now specifically targeting industrial facilities \u2013 49 percent more than last year. Dragos has identified three new threat actor groups specializing in operational technology: Sylvanite, Azurite, and Pyroxen. At the same time, Forescout reported a record high of 508 ICS advisories disclosing 2,155 vulnerabilities in 2025. For [&hellip;]","protected":false},"author":50,"featured_media":5361,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"ransomware groups","_yoast_wpseo_title":"OT Security 2026: 119 Ransomware Groups Target Industrial Facilities","_yoast_wpseo_metadesc":"OT Security 2026: 119 ransomware groups now target industrial facilities\u201449% surge. Protect your critical infrastructure. Learn more and stay ahead.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5362"],"footnotes":""},"categories":[255,259],"tags":[],"class_list":["post-7612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":5362,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7612"}],"version-history":[{"count":9,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7612\/revisions"}],"predecessor-version":[{"id":21719,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7612\/revisions\/21719"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5361"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}