
Critical Infrastructure Under Siege: Ransomware Groups Target North America's Vital Sectors
Ransomware groups are increasingly targeting critical infrastructure in North America, including power grids, water systems, and healthcare, posing a critical threat to national security.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
Ransomware groups have escalated their attacks on critical infrastructure across North America, focusing on sectors such as power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These operations have resulted in significant operational disruptions, financial losses, and heightened national security concerns.
Current Threat Landscape
In March 2026, ransomware activity remained heavily concentrated in sectors combining operational dependency with high-value data exposure. The Professional Goods & Services sector emerged as the most targeted, reflecting attackers’ focus on organizations holding sensitive client and business-critical data. Manufacturing and Consumer Goods & Services also recorded substantial activity, highlighting continued pressure on production-driven and customer-facing industries where disruption directly impacts revenue streams. Significant targeting was further observed in Healthcare and Information Technology, underscoring risks to critical services and the strategic role of IT providers within broader supply chains. (cyfirma.com)
Notable Threat Actors and Tactics
Several ransomware groups have been identified as primary actors in these attacks:
-
Qilin: An established ransomware-as-a-service (RaaS) operation active since 2022, Qilin has significantly expanded its affiliate recruitment and victim disclosures since early 2025. (blog.checkpoint.com)
-
Akira: First observed in 2023, Akira targets Windows, Linux, and ESXi systems, focusing on business services and industrial manufacturing. (blog.checkpoint.com)
-
DragonForce: Operating a white-label “cartel” model, DragonForce has accelerated its activity, absorbing displaced RansomHub affiliates and conducting high-profile social engineering campaigns. (blog.checkpoint.com)
These groups employ a variety of tactics, including phishing, exploiting vulnerabilities in internet-facing systems, and leveraging RaaS models to expand their reach.
Sector-Specific Impacts
-
Power Grids and Water Systems: Attacks on industrial control systems (ICS) have led to operational disruptions and financial losses. For instance, Iranian-affiliated actors have targeted programmable logic controllers (PLCs) in U.S. water and energy facilities, causing significant disruptions. (picussecurity.com)
-
Healthcare Sector: The healthcare industry remains a prime target, with ransomware attacks leading to data breaches and operational halts. The emergence of new ransomware variants, such as "BlackShadow," has intensified the threat landscape. (defendthegame.intrusion.com)
-
Financial Sector: Financial institutions continue to face challenges from ransomware attacks, with threat actors seeking to steal customer credentials and conduct extortion. The adoption of AI by attackers has increased the sophistication of these attacks. (pwc.com)
Recommendations for Mitigation
Organizations are advised to implement the following measures to enhance resilience against ransomware attacks:
-
Regular System Audits: Conduct comprehensive audits of all systems, especially those connected to critical infrastructure, to identify and mitigate vulnerabilities.
-
Employee Training: Provide ongoing cybersecurity training to employees to recognize phishing attempts and other social engineering tactics.
-
Incident Response Planning: Develop and regularly update incident response plans to ensure a swift and coordinated reaction to potential breaches.
-
Collaboration with Authorities: Maintain open communication channels with federal and state cybersecurity agencies to stay informed about emerging threats and best practices.
Conclusion
The targeting of critical infrastructure by ransomware groups poses a significant threat to national security and public safety. Proactive measures, including system audits, employee training, and robust incident response planning, are essential to mitigate these risks and ensure the continued resilience of critical sectors.
Highlights:
- US cybersecurity agency issues an urgent alert as Iranian hackers attack critical infrastructure - CISA guidance warns organizations to immediately shield certain programmable logic controllers from the internet to thwart future attacks, Published on Friday, April 10
- US agencies warn Iranian hackers are targeting American critical infrastructure - causing 'disruptive effects within the United States', Published on Wednesday, April 08
- Why cyber attacks on critical national infrastructure are such a huge threat, Published on Wednesday, March 18
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

Gunra and Medusa Ransomware Groups Intensify Double-Extortion Campaigns Against Critical Infrastructure

