Skip to main content
Return to Investigación Profunda de TrendAI™
Cyber crimeIoT & endpointsRansomware

Mapping the Criminal Economy Targeting Critical Infrastructure

TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth of data revealed an underground where financially motivated brokers and ransomware crews now operate alongside state-aligned hacktivists, sharing the same entry vectors, the same pirated training, and in some cases, the same personnel.

Research featuresIndustrial & energyHacktivismRansomware & extortionOT & critical infrastructure

By the numbers

3,178   Leak-site listings involving IE&M organizations

The industrial, energy, and manufacturing (IE&M) underground is not a future risk but an economy actively operating today. Access brokers sell footholds into factories, utilities, and energy companies on the same forums, with the same escrow and reputation mechanics used to trade stolen credentials and banking data. A Thai manufacturer's production system lists for US$25 on BreachForums; a German renewable-energy firm's internal database lists for 12 BTC, roughly US$748,000.

Four things security leaders need to know

Access as a service (AaaS) is an active market for industrial targets 

Manufacturing is the center of gravity in the access broker market. Sellers on Russian- and English-language forums offer virtual private network (VPN) and Remote Desktop Protocol (RDP) access with operational technology and supervisory control and data acquisition (OT/SCADA) reachability marketed as a premium feature.

Why this matters

Industrial access is a commodity product. Brokers advertise factory-floor reachability, SCADA connectivity, and domain-admin control as selling points, lowering the barrier for any buyer willing to pay.

Risk implications

  • OT exposure is traded openly on criminal forums as added value
  • Entry prices are low enough to attract less-skilled malicious actors
  • VPN gateways and RDP are the dominant entry vectors
  • Access to high-value energy and utility industries allows the demand for premium prices

Ransomware pressure on IE&M is growing, not stabilizing

Between January 2024 and June 2026, IE&M organizations appeared in 3,178 leak-site listings. Manufacturing makes up 78% of cases. Victim volume rose 48% from 2024 to 2025, with 767 victims in the first half of 2026 already putting the year on pace to match or exceed 2025. 

Why this matters

The ransomware threat to IE&M is growing, not stabilizing. Manufacturing's low payment rate pushes actors toward volume and data-sale monetization, increasing the total number of organizations hit.

Risk implications

  • Ransomware activity is likely to increase because of pressure to resume production
  • Manufacturing has a disproportionately low ransom-payment rate
  • Three ransomware-as-a-service (RaaS) groups account for roughly 30% of all IE&M victims
  • Attacks are most heavily concentrated in the U.S. and Western Europe

Professional ICS training is being weaponized through piracy

Underground forums host and resell professional industrial control system (ICS) security training materials. The same materials that used to train defenders are repurposed to onboard attackers at near-zero cost.

Why this matters

Pirated training lowers the skill barrier for OT-focused attacks. Curricula covering the Purdue model, programmable logic controller (PLC), and industrial protocols give attackers a structured path from novice to capable without formal enrollment.

Risk implications

  • Defenders’ own training materials are repurposed as attacker onboarding tools
  • Cost of ICS knowledge acquisition is near zero on criminal forums
  • Persian and Arabic-language channels build region-specific curricula
  • Piracy volume signals sustained underground demand for OT skills

Geopolitically motivated hacktivists are targeting ICS at scale

Between 2024 and 2026, hacktivist groups aligned with Russia and Iran claimed a growing number of intrusions against energy grids, water utilities, oil-and-gas operations, and manufacturing plants. Z-Pentest became the most prolific OT-focused actor. Based on our underground findings, the Iran-Israel-U.S. confrontation in 2026 drove the sharpest spike in infrastructure-directed activity. 

Why this matters

Low-skill actors are achieving real-world impact against exposed industrial control systems. A far larger share of IE&M activity is hacktivist and geopolitically driven than in the banking fraud or healthcare undergrounds.

Risk implications

  • Pro-Russia and pro-Iran actors target energy, water, and manufacturing simultaneously, including covert prepositioning of malicious code for future disruption
  • A Cybersecurity and Infrastructure Security Agency (CISA) joint advisory confirms low-skill actors causing physical damage, with state-sponsored actors quietly embedding footholds inside civilian critical infrastructure
  • Geopolitical escalation in 2026 drives the sharpest spike in targeting and long-term prepositioning risk

How brokers get in, and what it costs

Access-as-a-service price range distribution
Figure 1. Access-as-a-service price range distribution

Access brokers rely on abuse of legitimate remote-access infrastructure and identity, not exotic zero-days. The dominant footholds are internet-facing VPN and RDP (Remote Desktop Protocol) secured with weak, reused, or stolen credentials, frequently via a vulnerable edge appliance.

Access vector/entry point % of Records
VPN, remote-access gateways 20.9%
RDP, Remote Desktop 13.1%
Stolen credentials/logins 12.5%
Domain Admin privilege 11.0%
Local Admin privilege 8.0%
Fortinet/FortiGate 7.6%
SCADA/ICS/HMI/PLC 6.6%
Stealer logs, including RedLine and Lumma 6.2%
Table 1. Top access vectors by share of records

Energy, oil and gas, and utilities appear less often but command higher prices and more discreet handling, reflecting both regulatory sensitivity and the strategic value certain buyers place on them.

Brokers advertise "OT/SCADA access to factory" as a premium feature, not unlike a car listing highlighting leather seats.

A handful of RaaS operations drive the majority

Leak-site data from Ransomware.live shows industrial and energy victims rising from 974 in 2024 to 1,437 in 2025, and 767 disclosed in the first half of 2026 alone, already tracking above the half-year pace of prior years.

Top 12 groups in-scope victim count
Figure 2. Top 12 groups in-scope victim count

Akira, Qilin, and Play, the three most prolific groups against these sectors, account for roughly 30% of all in-scope victims. Victim organizations are heavily concentrated in the U.S. (1,397 disclosures), followed by Germany, Canada, and Italy.

Manufacturing appears disproportionately on leak sites relative to its share of paid resolutions. Many mid-market manufacturers restore from backups and absorb downtime; stolen data is often operational rather than regulated personal data, lowering extortion leverage. The net effect is a sector heavily attacked and heavily leaked, but comparatively resistant to paying, pushing actors toward volume and data-sale monetization.

The defensive curriculum doubles as an attacker's field manual

Underground forums host and resell professional ICS security training. SANS Institute's ICS410: ICS/SCADA Security Essentials appears more than 200 times as pirated course packs, alongside hobbyist Q&A on SCADA, PLCs, and industrial protocols.

200+  Pirated ICS410 course packs found

The same content that helps engineers secure a plant also maps how industrial networks are laid out, which protocols to target, where IT/OT weak points sit, and how safety and control systems behave under manipulation. On the messaging layer, Persian and Arabic channels build SCADA-hacking curricula referencing real-world attacks like Stuxnet.

Ideology on the same target set as profit

What distinguishes the IE&M underground is the overlay of geopolitical motivations. These actors rely on persistence and opportunism rather than technical skill, yet their public claims of impact routinely outpace their verified capabilities. Claims below are drawn from monitored Telegram channels and are not necessarily verified.

It is worth noting that these low-skill actors achieved real-world impact. These groups have less technical depth than advanced persistent threats (APTs), yet their attacks resulted in varying degrees of impact, including physical damage, across water, energy, and food-and-agriculture systems.

Alignment Actor Targeting and activity
Pro-Russia Z-Pentest The most prolific OT-focused actor during the period. The group targeted organizations across the energy, water, oil and gas, and manufacturing sectors, with activity spanning Europe, NATO member states, the U.S., and Taiwan.
NoName057(16) A foundational collective active since 2022. Through its DDoSia platform, the group has conducted crowdsourced DDoS attacks targeting critical infrastructure sectors, including energy, water, and transport.
Sector 16 A spin-off of Z-Pentest that focuses primarily on the energy, power, and manufacturing sectors in the U.S. and Europe.
Dark Engine, TwoNet, and CyberTroops These groups have targeted a range of industrial and critical infrastructure sectors, including manufacturing, chemical facilities, water treatment, and renewable energy generation.
Pro-Iran/Anti-Israel Handala An Iranian Ministry of Intelligence (MOIS)-linked front reportedly behind the June 2026 breach of California Water Service. The group framed the attack as retaliation for strikes on Sirik, Iran.
CyberAv3ngers An Islamic Revolutionary Guard Corps (IRGC)-linked, state-sponsored actor that has exploited programmable logic controllers (PLCs) across U.S. utilities. The group has also disrupted water and wastewater operations in more than 30 Minnesota communities.
Hunt3r Kill3rs A group that blends ideological and criminal characteristics. It has claimed attacks against energy assets, including nuclear-adjacent facilities and PLC devices.
Pro-Ukraine Blackjack Represents the upper limit of what hacktivist OT operations have achieved. The group has been associated with the Fuxnet wiper attack against municipal OT systems in Moscow, one of the few reported cases in which hacktivist activity resulted in demonstrable operational disruption rather than merely claims of access.
Table 2. An overview of the hacktivist groups active from 2024 to 2026 that targeted IE&M sectors and were observed for this research.

The defensive implications are straightforward, but not simple

Brokers get in through VPN gateways and RDP secured with weak or stolen credentials, not exotic zero-days. Removing that access removes most of what makes industrial footholds worth selling.

  1. Require phishing-resistant multi-factor authentication (MFA) on every VPN, RDP, Citrix, and remote-access portal. VPN, the single largest observed vector, is largely neutralized when stolen credentials no longer yield access.
  2. Treat edge appliances as tier-zero. Patch Fortinet, Citrix, Cisco, Palo Alto, and SonicWall on an emergency cadence; inventory and retire end-of-life devices.
  3. Harden identity and Active Directory with tiered administration, Local Administrator Password Solution (LAPS), and aggressive monitoring of privileged authentication, since domain admin and user access are what brokers actually sell.
  4. Segment IT from OT and remove flat paths to SCADA/PLC/HMI networks. Route remote access through a hardened, monitored demilitarized zone (DMZ) jump server and baseline normal admin activity across the boundary.
  5. Centralize logs in an immutable security information and event management (SIEM) held outside local control, retained for more than 12 months, and monitor the credential supply chain via stealer-log and exposure feeds.
  6. Prioritize by consequence, not volume. Utilities, power generation, oil and gas, and water warrant greater protection even where observed access volume is comparatively low. Exercise an OT-specific incident-response plan annually.
Mapping the Criminal Economy Targeting Critical Infrastructure

Read the full report, "Mapping the Criminal Economy Targeting Critical Infrastructure," by downloading the PDF here.