Back 60% of cyberattacks on the industry begin with a phishing email

60% of cyberattacks on the industry begin with a phishing email
ZIUR, the Industrial Cybersecurity Center of the Gipuzkoa Provincial Council, identifies increased activity from cyberespionage and ransomware groups and warns of the rise in threats against industrial systems
Industrial systems are more exposed than ever to cyberattacks. This is reflected in the latest Industrial Cyber Intelligence Report prepared by ZIUR, which analyzes the evolution of threats against industrial environments between January 2025 and July 2026. The study concludes that 60% of attacks began with phishing campaigns, while the exploitation of vulnerabilities accounted for 21.3% of the initial access points detected. During this period, 2,864 vulnerabilities were also identified in industrial systems, demonstrating the increasing pressure on critical infrastructure.
The report confirms an evolution in the international threat landscape. Alongside advanced cyber espionage groups (APTs), which continue to refine their infiltration techniques, criminal organizations specializing in ransomware are playing an increasingly prominent role, capable of compromising industrial infrastructure through stolen credentials, remote access, or targeted phishing campaigns.
The document identifies increasing activity by groups linked to state interests that use cybersecurity as a tool for geopolitical influence over critical infrastructure. Among them are Kamacite, associated with the Russian ecosystem and specializing in operations against the energy, water, and manufacturing sectors in Europe and the United States; Sylvanite, with Chinese ties, focused on exploiting vulnerabilities to facilitate access to strategic infrastructure; and Bauxite, linked to Iran and the CyberAv3ngers group, which has directed its attacks against industrial control systems by exploiting vulnerabilities in connected devices. These actors reflect how international geopolitical competition is also extending into cyberspace, where industrial infrastructure has become a strategic target for espionage and destabilization.
Regarding ransomware groups, which operate for financial gain with the aim of encrypting victims' data and demanding a ransom for its release, Qilin stands out as one of the most active in the world, along with Akira and Play, which have launched campaigns against companies and critical infrastructure in Europe, North America, and other regions. Alongside these, the report analyzes the activity of APT groups specializing in cyber espionage that target strategic infrastructure and whose activity is often linked to international geopolitical interests.
A scenario of “more sophisticated and professional” attacks
According to ZIUR's CEO, María Penilla, “the industry faces a scenario in which attacks are becoming increasingly sophisticated and professional. We are no longer just talking about protecting information, but about guaranteeing the continuity of production processes essential to the economy and the operation of critical services.”
The analysis identifies targeted phishing, exploitation of vulnerabilities, use of compromised credentials, and the compromise of technology providers as the main access points—a particularly worrying trend due to the growing interconnection between manufacturers, integrators, and industrial companies.
For María Penilla, “cybersecurity has become a factor of competitiveness. Companies that integrate security from the design stage of their products and processes will be better prepared to respond to a more demanding regulatory environment and increasingly complex threats.”
ZIUR Acceleration Program
In this context, ZIUR highlights that the Gipuzkoa Provincial Council is promoting a pioneering strategy to strengthen industrial cybersecurity as a driver of competitiveness. Among the initiatives, the ZIUR Acceleration Program stands out, with a budget of three million euros, which supports companies in adapting to the European Cyber Resilience Regulation (CRA). In its first six months of operation, the program has already begun 25% of the planned assessments, attracted the interest of 68 companies, and plans to evaluate between 60 and 80 connected industrial products and services per year.
"The best response to this scenario is to anticipate it. Our goal is to help companies incorporate cybersecurity from the earliest stages of product development and turn regulatory compliance into an opportunity to innovate and gain a competitive edge," concludes Penilla.
Download the report here: https://www.ziur.eus/en/-/initial-access-vector-threat-landscape-report