KITECH Webinar_~7.22
Physical AI HBM Smart Factory SDV AIoT Power Semicon 특수 가스 정정·반론보도 모음 e4ds plus

Surge in Ransomware Targeting English-speaking Countries… OT and IoT Security Threats Intensify

Google 우선 소스 기사입력2026.02.20 08:07


Nozomi Networks Releases OT/IoT Cybersecurity Trends Report for Second Half of 2025

It has been found that OT and IoT security threats are intensifying as ransomware targeting English-speaking countries surges.

According to the latest 'OT/IoT Cybersecurity Trends and Insights Report' released by Nozomi Networks Labs, 70% of global ransomware attacks were found to be concentrated in English-speaking countries such as the United States, Canada, and the United Kingdom.

In particular, 40% of all ransomware attacks in the second half of 2025 targeted U.S. companies, and attacks targeting Canada and the United Kingdom also reached 30%.

The report analyzed that as threat actors actively utilize generative AI for attack automation and social engineering techniques, the success rate of attacks is significantly increasing in English-speaking countries.

These three countries account for about 30% of the world's GDP, raising concerns that a successful cyber attack could cause serious disruption to the global economy.

The report pointed out that wireless network security remains a serious threat in industrial and critical infrastructure environments.

The survey results showed that 68% of the observed wireless networks used the latest encryption but did not apply MFP (Managed Frame Protection), and those using enterprise-grade authentication such as 802.1XThe job rate was only 2%.

In particular, it was found that 98% of all wireless networks rely on PSK (Pre-shared Key), which has structural limitations such as credential reuse and difficulty in tracing responsibility.

The transportation sector was the most attacked industry in 2025, and it was the top target in both the first and second halves of the year.

In the second half of the year, the manufacturing and public sectors followed, and attacks on the public sector increased sharply along with escalating geopolitical tensions.

In particular, exploratory attack techniques were detected most frequently in the public sector, indicating that attackers are focusing on preliminary reconnaissance for long-term infiltration.

In an analysis of attacker groups, 'Scattered Spider,' which was active in the summer of 2025, was identified as the most threatening group, accounting for 42.9% of all attacker-related alerts in the second half of the year.

In addition, North Korea's Kimsuky, Russia's APT29, and Iran's CURIUM were active.

Nozomi Networks predicted that cyber activities linked to North Korea, China, Iran, and Russia would continue to be a major threat in 2026.

Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, emphasized, “Critical infrastructure is exposed to more sophisticated and organized attacks than ever before,” adding that “securing asset visibility, AI-based threat detection, and risk-based vulnerability management are essential.”