Industrial hacks aimed at physical damage are rising

On 5 April, four high speed trains in Taiwan braked to a halt and stayed there for 48 minutes. No malware was involved. A student had bought software defined radio gear online, decoded the parameters of the railway's radio network, programmed them into handheld radios and transmitted a high priority "General Alarm" that tripped emergency braking.

Kaspersky's ICS CERT puts that incident inside a wider pattern. In its quarterly overview of industrial cybersecurity, published on 20 August, the team counted 163 incidents that victims themselves publicly confirmed during the second quarter of 2026, and reported a significant increase in accounts of attacks on control systems intended to cause physical damage. The number of such incidents confirmed by the attacked parties rose alongside them.

A radio system that ran 19 years without new keys

The Taiwan High Speed Rail Corporation case shows how little it can take. The operator's TETRA radio system had been in service for 19 years and its parameters were apparently not rotated in that time, which let the attacker bypass seven layers of verification. An accomplice supplied some of the critical parameters. When the operator checked its logs it found the alarm had come from a radio beacon not assigned for duty, and because the device itself was not missing, unauthorized cloning was the plausible explanation. The student was arrested.

Water utilities keep paying for thin budgets

In March, staff at the water treatment plant serving Minot, North Dakota, found ransomware on the plant's SCADA server. Operators reverted to manual processes for about 16 hours while a replacement server was installed. City officials said the water system stayed operational and safe throughout, that the message left behind carried no direct demand for money, and that the city paid nothing. In May, Poland's internal security agency ABW disclosed that attackers had breached water treatment facilities in five Polish towns during 2025, in some cases reaching the control systems and altering equipment parameters in ways that put supply at direct risk.

Kaspersky's reading is economic rather than technical. Public utilities, water in particular, are typically small private enterprises with modest IT and OT budgets, and the researchers point back to the 2023 US appeals court decision that blocked mandatory Environmental Protection Agency cybersecurity audits for those utilities. We covered a related case this month, when attackers reached a Polish power plant through its private mobile network.

Fuel gauges nobody bothered to password

US officials suspect Iranian linked hackers were behind a run of breaches involving automatic tank gauge systems at American fuel storage sites. The gauges were reachable online without password protection, letting attackers manipulate the readings operators saw. Officials said the incidents did not result in physical damage, and cautioned that thin forensic evidence may prevent a definitive answer on responsibility. In June, CISA, the FBI, the NSA, the Department of Energy and other US government partners published a joint notice warning that internet exposed tank gauges across critical infrastructure sectors were being targeted. CISA has been busy on this front: it also warned this month that attackers are using AI written scripts to probe Siemens plant controllers. A separate attempt against a Swedish thermal power plant failed against built in protection, and Sweden's security service identified suspects believed to have links to Russia.

Rotate the parameters nobody has touched

The quarter's sharpest cases turn on the same neglect: keys and radio parameters set once and left alone. Inventory the ICS, radio and telemetry systems whose credentials have not changed in years, and rotate them. Get tank gauges and SCADA interfaces off the public internet or behind authentication. Rehearse the manual fallback, because Minot's plant ran on it for 16 hours and that is what kept the water flowing. Kaspersky lists all 163 incidents, including ransomware outages at Foxconn's North American factories and at Australian sugar producer Mackay Sugar, in a table closing the original report.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions