Virtual Round Table · Jul 22

View the event
Sophos: Compromised Identities Now Drive 79 Percent of Ransomware Attacks
Cybersecurity

Sophos: Compromised Identities Now Drive 79 Percent of Ransomware Attacks

Sophos's seventh annual ransomware study finds stolen and abused credentials have overtaken software exploits as the dominant way attackers get in, and MFA alone is not closing the gap.

PublishedJuly 19, 2026
Read time6 min read
Share

The headline shift

Sophos published its seventh annual State of Ransomware report this week, and the top-line finding rewires how enterprises should think about their exposure. Identity has become the dominant initial access vector, with 79 percent of ransomware attacks starting from compromised identities. For three years running, software vulnerabilities held the top spot as the most common root cause. In the latest data they fell to 18 percent, down sharply from 32 percent the year before. Malicious email at 26 percent and phishing at 24 percent now lead, with compromised credentials contributing another 23 percent. The center of gravity in ransomware has moved decisively from the exploit to the login.

The report rests on a substantial evidence base. Sophos commissioned Vanson Bourne to survey 2,158 IT and cybersecurity decision-makers across 17 countries in the first quarter of 2026, spanning organizations of 100 to 5,000 employees across 15 industry sectors. That breadth gives the findings weight beyond a single vendor's incident telemetry. When a survey of this size shows identity-based access more than four times as common as vulnerability exploitation, the message for security leaders is that the threat model many programs are still optimized around has aged out, and defensive spending needs to follow the attackers to where they actually operate.

Why identity became the path of least resistance

The economics explain the shift. Exploiting a software vulnerability requires research, reliable tooling, and a race against patching. Acquiring a working credential is cheaper, faster, and endlessly repeatable, and it drops the attacker into the environment wearing a legitimate identity. Roman Sannikov of iCounter framed the calculus directly, noting that buying or phishing a working credential is faster and repeatable, and once you are in, you look like a legitimate user. That last point is the crux. Credential-based access generates far less of the noise that exploit chains produce, so it evades many of the detections tuned to catch technical intrusions and buys the attacker quiet dwell time.

Kevin Surace of TokenCore captured the strategic reality in blunt terms, saying attackers have realized they no longer need to hack through firewalls when they can simply log in with stolen credentials. The infostealer economy has industrialized the supply of those credentials, harvesting session tokens and passwords from infected endpoints and feeding them into marketplaces that resell access at scale. Shane Barney of Keeper Security observed that once attackers obtain a legitimate identity, they can move through an environment undetected, escalating privileges and staging ransomware. The intrusion no longer looks like an attack in progress. It looks like an employee doing their job, which is exactly why it works.

The uncomfortable truth about MFA

The most sobering data point concerns multi-factor authentication. Among incidents where compromised credentials were the root cause, MFA was deployed in 97 percent of cases. Read plainly, that means the presence of MFA did little to stop these attacks. The explanation lies in the gap between deploying a control and deploying it everywhere in a form that resists modern attack techniques. Chester Wisniewski, Sophos Global Field CISO, pointed to the practical failure modes, observing that MFA is not on every entry point, or it supports a mix of strong passkeys or U2F and weak, time-based one-time passwords that attackers can phish or intercept.

The lesson is not that MFA is worthless. It remains essential, and removing it would make matters dramatically worse. The lesson is that partial or weak MFA creates a false sense of security that maps poorly to the actual threat. A single legacy application without MFA, a service account exempted for convenience, or reliance on one-time passcodes that a real-time phishing proxy can relay all leave the door open. Enterprises should audit MFA coverage as a first-class exercise, close the exemptions, and migrate high-value access toward phishing-resistant methods such as passkeys and hardware security keys that defeat the credential-relay attacks now in common use.

What it costs when identity fails

The financial picture reinforces why the initial access vector deserves board attention. Sophos reported an average recovery cost of $1.7 million per incident, and in the UK the median ransom demand reached $2.5 million, the highest of any country surveyed. Fifty-six percent of victims had data encrypted, and of those, 48 percent paid a ransom. Recovery was not quick for many, though 55 percent of affected organizations managed to restore operations within a week. Notably, 67 percent of victims said the ransomware event was also the most significant identity-related attack they suffered over the past year, tying the operational disaster directly back to the credential compromise that enabled it.

For PE-backed SaaS and retail technology operators, these figures translate into concrete portfolio risk. A recovery cost measured in millions per incident, multiplied across operating companies that often share identity providers, administrative patterns, and thinly staffed security teams, is a material exposure that shows up in valuation and diligence. The through-line from a phished credential to a seven-figure recovery bill is short and well documented. Treating identity security as a cost-of-doing-business investment rather than a discretionary line item is the rational response to data showing that the cheapest attack path now produces the most expensive outcomes.

Reorienting the program

The practical implication is a rebalancing of where defensive effort goes. Ross McKerchar, Sophos CISO, cautioned that defenders cannot rely on patching alone to keep pace, so reducing external exposure and maintaining strong endpoint protection is essential. Patching still matters, and the 18 percent of attacks that begin with exploited vulnerabilities are real. The point is that a program weighted almost entirely toward vulnerability management is defending yesterday's primary vector while the majority of attacks now walk in through identity. Jacob Krell of Suzu Labs put the priority plainly, arguing that stopping credential acquisition matters more now than catching ransomware payloads at the endpoint.

In concrete terms, that means investing in phishing-resistant authentication across every entry point, aggressive least-privilege enforcement so a single stolen credential cannot roam, and detection tuned to identity anomalies such as impossible travel, unusual privilege use, and access from unfamiliar infrastructure. It also means treating the infostealer supply chain as a direct threat, monitoring for exposed corporate credentials and revoking sessions quickly when they surface. The Sophos data is a clear signal that ransomware defense has become, in large part, an identity and access management discipline, and the programs that internalize that shift will absorb the next wave of attacks better than those still fighting the last one.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#sophos#identity-security#mfa#phishing#credential-theft#state-of-ransomware-2026