For MSSPs
Scale threat-led services across your customers
For Internal SOCs
Run threat-led operations in your own environment
Integrations
Connect Sol to your security stack
Blog
Latest articles and insights
About Us
Meet the people and purpose behind Elezar
Account
Login
Create Account
Support
Help Centre
Legal
Terms & Conditions
Privacy Policy
The Americas, led by the United States, carried the highest ransomware burden in every June reporting week. The United States accounted for 32.10 to 45.59 percent of global ransomware victims, while Canada reached 7.35 percent in the week of 2 to 8 June. Energy and utilities also faced a distinct nation-state threat through VOLTZITE pre-positioning against electric and water infrastructure, plus FortiBleed, a Russian-speaking initial-access campaign that compromised more than 430,000 FortiGate devices and captured over 110 million credentials. No source report named a specific Americas energy victim, so the brief separates region-wide exposure from confirmed sector targeting.
Recommendations are calibrated for distributed utility operations, OT and ICS estates, remote-access infrastructure, MSP dependencies and high-impact service continuity requirements.
EMEA energy and utilities faced a criminally dominated threat environment in June 2026. No source report named a specific EMEA energy victim, but Europe was heavily represented in global ransomware activity, with Germany accounting for 5.15 percent of victims during the week of 2 to 8 June. The most important sector risks were LockBit-derived ransomware families, the Amadey and StealC credential ecosystem, a broad AsyncRAT family infrastructure footprint and the emergence of AiLock with post-quantum key encapsulation and GDPR-focused extortion pressure.
APAC energy, gas, oil and utilities faced two parallel threat streams during June 2026. Chinese state-sponsored groups focused on long-term access to utility and OT-adjacent environments, while criminal operators maintained pressure through ransomware, credential theft and edge-device exploitation. VOLTZITE was the most strategically significant actor because its confirmed targeting scope includes Australia, New Zealand, Singapore, Taiwan and India. Earth Lusca also expanded its capability by deploying a Windows version of SprySOCKS with rootkit functionality. No source report named a specific APAC energy victim during the month, so this brief distinguishes confirmed actor targeting from inferred sector exposure.