Ransomware attacks expanded to the industrial sector last year to such an extent that this type of incident became the number one threat in the industrial sector. Two ransomware groups, LockBit and Conti, were the most active.

The threat of ransomware is common in the construction sector
A report today from industrial cybersecurity firm Dragos highlights that the industrial sector has become a more attractive target for both financially motivated adversaries and actors linked to state groups.
While monitoring threat activity in the industrial sector last year, the company discovered a spike in ransomware incidents targeting ICS/OT networks.
See also: Asustor network storage devices hit by ransomware attack
According to Dragos' findings, the most common targets for ransomware groups were in the construction sector, with 211 attacks accounting for 65%, followed by 35 successful breaches of companies in the food and beverage industry and 27 attacks against entities in the transportation sector.

The researchers note that the manufacturing industry is the most exposed to attacks because this "sector is often the least mature in terms of OT security defenses.".
An overview of these companies' security reveals a worrying trend, researchers say, based on data collected during customer engagement.
Many organizations have very limited visibility into the infrastructure, fail to properly segment network perimeters, have many externally connected devices , and a high percentage of shared credentials between the corporate network (IT) and the OT environment.

The above problems create the ground for successful attacks, allowing threat actors to pivot from the IT network to the OT department, even if breaching the latter is not the primary goal.
See also: Ransomware: Victims pay but hackers come back for more
This has allowed the ransomware threat to become the number one cause of breaches in the industrial sector, the researchers note in the report.

LockBit and Conti attacks in the ICS domain
Of the ransomware groups attacking industrial infrastructure, LockBit and Conti are by far the most active, accounting for 51% of incidents.
According to Dragos, the two ransomware groups are responsible for 166 attacks on companies in the ICS sector, LockBit for 103 incidents and Conti for 63.
In 70% of all ransomware incidents analyzed by Dragos, targets were in the manufacturing sector, with the most affected subsectors being metal products, automotive, plastics, technology, and packaging.
See also: FBI: BlackByte ransomware has targeted critical US infrastructure
Ransomware threats are showing no signs of abating, despite governments prioritizing law enforcement efforts to bring ransomware-as-a-service (RaaS) operators and their associates to justice.
Information source: bleepingcomputer.com
