ADVERTISEMENT

Sophos Report: Identity-based attacks overtake software flaws as leading ransomware entry point

Published Jul 20, 2026 09:25 am
Cybercriminals are increasingly targeting user identities rather than software vulnerabilities to launch ransomware attacks, according to Sophos' latest State of Ransomware 2026 report, which found that compromised credentials have become the dominant entry point for attacks worldwide.
The seventh annual vendor-agnostic study, conducted by Vanson Bourne in the first quarter of 2026, surveyed 2,158 IT and cybersecurity decision-makers across 17 countries. It revealed that 79% of ransomware incidents now begin with compromised identities, marking the first time in four years that exploited software vulnerabilities have been displaced as the leading initial access vector.
Among identity-related attacks, malicious email accounted for 2% of ransomware incidents, while phishing represented 24%. Sophos noted that 67% of organizations affected by ransomware also identified the incident as their most significant identity-related attack. Even with multi-factor authentication (MFA) deployed in some form in 97% of credential-based breaches, attackers were still able to gain access, highlighting the need for broader identity protection beyond MFA alone.
The report also showed ransomware operators becoming more successful in encrypting victims' data. Successful encryption occurred in 56% of attacks, up from 50% in 2025 and reversing a two-year decline. In 16% of cases, attackers both encrypted and stole data. Smaller organizations with 100 to 250 employees were found to be more vulnerable, stopping attacks before encryption only 34% of the time, compared with a 46% success rate among enterprises employing between 3,001 and 5,000 workers.
Ross McKerchar, Chief Information Security Officer at Sophos, warned that artificial intelligence is enabling cybercriminals to operate more efficiently and at greater scale. He said AI could accelerate attackers' ability to identify valuable assets, compromise identities, and launch ransomware campaigns faster than ever before.
Despite attackers' growing effectiveness, organizations have improved their recovery capabilities. More than half, or 55%, of ransomware victims were able to recover within one week, while 16% restored operations in less than a day, largely due to stronger backup infrastructure. Among organizations that paid a ransom, 51% successfully negotiated lower settlements than the attackers initially demanded. Median ransom demands have fallen by 65% over the past two years, while only 48% of victims ultimately paid — a figure that represents the second-lowest payment rate recorded by Sophos.
However, the overall financial impact of ransomware continues to rise. The average recovery cost reached $1.7 million per incident, even as ransom payments declined. The report also noted that ransomware attacks exploiting firewall vulnerabilities remained particularly costly, with 59% of such incidents involving ransom demands exceeding $1 million. The United Kingdom recorded the highest median ransom demand at $2.5 million.
Alongside the report, Sophos introduced Sophos Fusion, an AI-native cybersecurity platform designed to help organizations respond to increasingly sophisticated AI-driven threats. Built on analytics technology from Secureworks Taegis, which Sophos acquired in 2025, the platform integrates with more than 500 third-party security products and provides a unified environment for threat detection and response.
Sophos said the platform consolidates security data into a shared context, coordinates automated responses across connected security tools, enables AI-assisted investigations under human oversight, and continuously improves defenses using global threat intelligence. The company reported that within its own Security Operations Center, which protects more than 40,000 customers, artificial intelligence already resolves 52% of security cases, with an average automated response time of 89 seconds.
The company also outlined several product enhancements scheduled for release between August and October 2026. These include a next-generation Security Information and Event Management (SIEM) platform, expanded Extended Detection and Response (XDR) and Managed Detection and Response (MDR) capabilities, AI governance tools for managing enterprise AI usage, and a virtual Chief Information Security Officer service aimed at mid-sized businesses.
To strengthen ransomware defenses, Sophos urged organizations to prioritize identity threat detection and response, deploy phishing-resistant authentication, minimize firewall exposure, maintain rigorous vulnerability management programs, and implement resilient backup strategies that include offline or immutable storage and regularly tested incident response plans.

Related Tags

Sophos cybersecurity ransomware
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ static_articles_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.