4 SEP 2026 — Industrial cyber attacks that cause physical damage are the ones operators fear most, because they cross from an IT outage into a safety event. Waterfall's threat report counted fifty-seven of them in heavy industry worldwide in 2025, down 25 per cent on the previous year. The fall is a composition change rather than an improvement. Ransomware flat-lined, and nation-state and hacktivist attacks roughly doubled without quite filling the gap.

What the report counts

The dataset is deliberately narrow. It covers only verified incidents where a cyber attack produced a physical consequence in industrial operations, which excludes the far larger population of breaches that stole data or encrypted office systems without touching a process.

Within that population, ransomware appears to have flat-lined or fallen slightly. Nation-state and hacktivist attacks nearly doubled. The top victim geographies were the United States, Germany and Russia, with Russia's exposure driven largely by Ukrainian hacktivist and state activity.

57Attacks with physical consequences in 2025
-25%Against the previous year
~2xIncrease in nation-state and hacktivist attacks
US, Germany, RussiaTop three victim geographies

A smaller number of worse events

The headline count hides a substitution, and this year it is a clear one. A criminal encrypting a plant wants payment, which means the operator is a counterparty rather than a target, and the damage stops when the transaction completes or the backups restore.

A state actor causing a physical consequence is doing it deliberately, has usually been resident on the network for a long time first, and is not going to negotiate. The same is true of a hacktivist attacking on political grounds, with the difference that the hacktivist is often less careful.

So a 25 per cent fall in the total, achieved by trading criminal incidents for state and hacktivist ones, is not a safer year. An operator planning against last year's threat mix is planning against the wrong one.

The consequences differ too. A ransomware outage is measured in days of lost production and a recovery cost. A state actor with process access is a safety question, because the systems involved are the ones that keep pressures, temperatures and flows inside limits that exist for physical reasons.

Why ransomware slowed, and why that may not last

The report attributes most of the reduction to temporary factors affecting ransomware. That phrase is doing a lot of work and it is the honest way to put it, because the drivers of ransomware volume are not stable.

Law enforcement disruption removes one operator, and the affiliates move. Payment rates fall while insurers tighten terms, then recover as new entrants undercut. When a group fragments there is a lull, followed by more groups. None of that is a structural reduction in the willingness to attack industrial targets.

Which means the composition shift is the finding with a longer shelf life. If ransomware returns to trend while the state and hacktivist component holds, the total climbs from a base with a worse mix in it.

The measurement is getting harder

The report's most uncomfortable observation is about itself. Incident reports are becoming far less detailed, so it is increasingly difficult to determine how a cyber attack led to a physical consequence.

That degrades the dataset in a specific way. A count of verified incidents with physical consequences depends on somebody publishing enough detail to verify the consequence, and if disclosure thins, incidents drop out of the count without dropping out of reality.

Some of the 25 per cent fall could therefore be reporting rather than events, and the report cannot separate the two. That is not a criticism of the methodology, which is stricter than most. It is a reason to treat any year-on-year movement in this series as a floor.

What an operator should do differently

The practical consequence of a shift toward state actors is that the problem becomes dwell time, not ransomware defences. Criminal intrusions are noisy and fast; speed is the business model. State intrusions are quiet and long, because access is the objective and the effect comes later.

Detection tuned for the first misses the second. A control set built around rapid encryption, backup integrity and rebuild speed does very little against an actor who has been reading the historian for eight months and has no intention of encrypting anything.

The corresponding investment is unglamorous. It means network visibility inside the operational technology segment, baselines for what normal process traffic looks like, and the ability to reconstruct what happened months after it started. None of that is bought as a product.

Log retention decides whether that reconstruction is possible at all. An intrusion discovered at eight months cannot be investigated with ninety days of logs, and the retention window is usually set by storage cost, not by how long an adversary is expected to stay.

Why the geography understates this region

The United States, Germany and Russia topping the victim list is partly a statement about disclosure, not targeting. Those three have the strongest reporting obligations and the most active security press. Russia also has a conflict that produces publicity for attacks on it.

Southeast Asian industrial operators are not absent from the threat landscape. They are absent from datasets built on verified public reporting, because the region's disclosure requirements for operational incidents are lighter and a plant outage rarely produces a document anyone outside can verify.

Hold that when the report gets quoted regionally. A country not appearing in the top three has not demonstrated that its plants are safer, and on a measure that depends on published detail, quiet is not evidence.