Sophos Report: Identity-based attacks overtake software flaws as leading ransomware entry point
By Bob Reyes
Cybercriminals are increasingly targeting user identities rather than software vulnerabilities to launch ransomware attacks, according to Sophos' latest State of Ransomware 2026 report, which found that compromised credentials have become the dominant entry point for attacks worldwide.
The seventh annual vendor-agnostic study, conducted by Vanson Bourne in the first quarter of 2026, surveyed 2,158 IT and cybersecurity decision-makers across 17 countries. It revealed that 79% of ransomware incidents now begin with compromised identities, marking the first time in four years that exploited software vulnerabilities have been displaced as the leading initial access vector.
Among identity-related attacks, malicious email accounted for 2% of ransomware incidents, while phishing represented 24%. Sophos noted that 67% of organizations affected by ransomware also identified the incident as their most significant identity-related attack. Even with multi-factor authentication (MFA) deployed in some form in 97% of credential-based breaches, attackers were still able to gain access, highlighting the need for broader identity protection beyond MFA alone.
The report also showed ransomware operators becoming more successful in encrypting victims' data. Successful encryption occurred in 56% of attacks, up from 50% in 2025 and reversing a two-year decline. In 16% of cases, attackers both encrypted and stole data. Smaller organizations with 100 to 250 employees were found to be more vulnerable, stopping attacks before encryption only 34% of the time, compared with a 46% success rate among enterprises employing between 3,001 and 5,000 workers.
Ross McKerchar, Chief Information Security Officer at Sophos, warned that artificial intelligence is enabling cybercriminals to operate more efficiently and at greater scale. He said AI could accelerate attackers' ability to identify valuable assets, compromise identities, and launch ransomware campaigns faster than ever before.
Despite attackers' growing effectiveness, organizations have improved their recovery capabilities. More than half, or 55%, of ransomware victims were able to recover within one week, while 16% restored operations in less than a day, largely due to stronger backup infrastructure. Among organizations that paid a ransom, 51% successfully negotiated lower settlements than the attackers initially demanded. Median ransom demands have fallen by 65% over the past two years, while only 48% of victims ultimately paid — a figure that represents the second-lowest payment rate recorded by Sophos.
However, the overall financial impact of ransomware continues to rise. The average recovery cost reached $1.7 million per incident, even as ransom payments declined. The report also noted that ransomware attacks exploiting firewall vulnerabilities remained particularly costly, with 59% of such incidents involving ransom demands exceeding $1 million. The United Kingdom recorded the highest median ransom demand at $2.5 million.
Alongside the report, Sophos introduced Sophos Fusion, an AI-native cybersecurity platform designed to help organizations respond to increasingly sophisticated AI-driven threats. Built on analytics technology from Secureworks Taegis, which Sophos acquired in 2025, the platform integrates with more than 500 third-party security products and provides a unified environment for threat detection and response.
Sophos said the platform consolidates security data into a shared context, coordinates automated responses across connected security tools, enables AI-assisted investigations under human oversight, and continuously improves defenses using global threat intelligence. The company reported that within its own Security Operations Center, which protects more than 40,000 customers, artificial intelligence already resolves 52% of security cases, with an average automated response time of 89 seconds.
The company also outlined several product enhancements scheduled for release between August and October 2026. These include a next-generation Security Information and Event Management (SIEM) platform, expanded Extended Detection and Response (XDR) and Managed Detection and Response (MDR) capabilities, AI governance tools for managing enterprise AI usage, and a virtual Chief Information Security Officer service aimed at mid-sized businesses.
To strengthen ransomware defenses, Sophos urged organizations to prioritize identity threat detection and response, deploy phishing-resistant authentication, minimize firewall exposure, maintain rigorous vulnerability management programs, and implement resilient backup strategies that include offline or immutable storage and regularly tested incident response plans.