2026 OT Cyber Threat Report
Ransomware is down, nation state / hacktivists are up
Unlike other industry reports, we focus exclusively on verified incidents with physical consequences. Each data point is meticulously documented and can be independently verified, making this the most credible and actionable OT security report available today.
Cyber breaches with physical consequences in the public record for heavy industry and critical industrial infrastructures decreased 25% to 57 in 2025 from 76 in 2024. Most of this reduction is because of temporary factors affecting ransomware attacks. Nation-state and hacktivist attacks doubled, with most attacks targeting critical infrastructures. The report is unique in its focus, and in that the entire 2025 data set is included in the Appendix.
Key Takeaways
- Jaguar / LandRover – the most costly production shutdown in a decade,
- Colins Aerospace – a crippled software system caused flight cancellations and delays for weeks – highlighting the need for rapid recovery or manual fall-backs for critical systems operated and managed by third parties,
- Grounded and mis-directed ships – again highlighted the need for multiple independent checks on important external inputs, such as GPS signals, and
- Polish distributed generation – a near miss because the lights stayed on, an example of the Russian nation state targeting European critical infrastructures, and a cautionary tale about “bricking” control equipment
About the author
Waterfall team
FAQs About the 2025 OT Cyber Threat Report
What is in the 2026 OT Cyber Threat Report?
The Waterfall Threat Report 2025 brings you comprehensive, verifiable data on cyber attacks that caused physical consequences in OT environments to help you understand today’s threat landscape and what’s required to face it.
Why should I download it?
Unlike other industry reports, the Waterfall Threat Report 2026 focuses exclusively on verified incidents with physical consequences. Reading the report will help you understand today’s threat landscape and what’s required to face it.