• Home  
  • Sophos report finds compromised identities behind 79% of ransomware attacks
- Enterprise Technology - News

Sophos report finds compromised identities behind 79% of ransomware attacks

Sophos has released its seventh annual State of Ransomware report, revealing that compromised identities have become the leading entry point for ransomware attacks, accounting for 79% of incidents analyzed across organizations worldwide. The vendor-agnostic survey, conducted among 2,158 IT and cybersecurity decision-makers across 17 countries, shows a major shift in ransomware tactics as attackers increasingly […]

Sophos has released its seventh annual State of Ransomware report, revealing that compromised identities have become the leading entry point for ransomware attacks, accounting for 79% of incidents analyzed across organizations worldwide.

The vendor-agnostic survey, conducted among 2,158 IT and cybersecurity decision-makers across 17 countries, shows a major shift in ransomware tactics as attackers increasingly target user accounts and credentials instead of relying primarily on software vulnerabilities.

For the first time in four years, exploited vulnerabilities were no longer the most common initial access vector. Instead, malicious email (26%) and phishing (24%) emerged as the leading causes of ransomware attacks. However, vulnerabilities remain a high-value target, with 59% of ransom demands originating from exploited firewall vulnerabilities reaching $1 million or more.

Ross McKerchar, Chief Information Security Officer at Sophos, said ransomware attackers are increasingly using identity-based techniques and may leverage artificial intelligence (AI) to accelerate attacks, identify weaknesses, and scale their operations. He emphasized that organizations must move beyond patching alone and strengthen identity protection, exposure management, and endpoint security.

The report found that ransomware attacks are becoming more successful at encrypting data. Among organizations affected by ransomware, 56% experienced data encryption, reversing a two-year decline. Of those incidents, 16% involved both data encryption and theft.

Other key findings include:

  • 67% of ransomware victims said their ransomware incident was also their most significant identity attack, reinforcing identity compromise as a major attack pathway.
  • 48% of organizations whose data was encrypted paid ransom, bringing the four-year average payment rate to 50%.
  • Only 34% of small organizations with 100–250 employees successfully stopped ransomware attacks before encryption or extortion.
  • 97% of attacks involving compromised credentials had some form of multi-factor authentication (MFA) in place, showing that MFA alone is not enough without proper implementation and coverage.
  • The United Kingdom recorded the highest median ransom demand at $2.5 million.

Despite continued threats, organizations have improved their ransomware recovery capabilities. More than half (55%) of affected organizations recovered within one week, while 16% recovered in less than a day, driven partly by increased investment in backup and recovery infrastructure.

Sophos also reported that ransomware recovery costs continue to rise, reaching an average of $1.7 million per incident, even as ransom payments decline and more organizations successfully negotiate lower settlements.

To improve ransomware resilience, Sophos recommends that organizations prioritize identity threat detection and response (ITDR), deploy phishing-resistant MFA, regularly audit user and non-human accounts, strengthen backup strategies, maintain vulnerability management programs, and integrate firewall monitoring with extended detection and response (XDR) and managed detection and response (MDR) solutions.

As ransomware groups increasingly adopt AI-driven techniques, Sophos said organizations must combine technology, people, and processes into a unified cybersecurity strategy focused on prevention, detection, and rapid response.

Email Us

For inquiries, press releases, and partnership request, get in touch with us at: info.aitimes.ph@gmail.com.

Contact: 0956-344-3286

AI Times  @2026. All Rights Reserved.