Ransomware attacks have been a thorn in the side of organizations worldwide, and a new report from Sophos sheds light on a disturbing trend: identity compromise has become the primary root cause of ransomware attacks. Gone are the days when vulnerability exploitation was the top culprit; malicious email and phishing have taken center stage.
According to Sophos’ State of Ransomware 2026 report, which surveyed 2,158 IT and cybersecurity leaders across 17 countries who had experienced a ransomware attack in the past year, identity compromise is now the leading cause of ransomware attacks. Malicious email (26%) and phishing (24%) accounted for half of all ransomware root causes, dethroning vulnerabilities (18%, down from 32%) as the top threat.
The report also found that two-thirds of victims identified their ransomware attack as their most significant identity attack over the past year. This shift towards email-based attacks suggests that technical vulnerability patching alone is insufficient to prevent ransomware attacks. Organizations should deploy advanced email filtering, implement DMARC/DKIM/SPF protocols, and invest in regular phishing awareness training.
But what’s particularly striking is that even when multifactor authentication (MFA) was deployed, it failed to prevent compromise in 97% of cases where compromised credentials were the root cause of ransomware attacks. One-time passwords, push-based applications, and passkeys were the most common secondary authentication mechanisms used, but FIDO2 tokens, a gold standard for phishing-resistant authentication, was only the fourth most common method.
Sophos offered two possible explanations for why MFA failed: either it wasn’t fully deployed across all relevant systems, creating gaps for attackers to exploit, or it simply isn’t sufficient on its own to prevent credential-based attacks as bypass techniques continue to evolve. The report suggests that organizations should prioritize identity threat detection and response (ITDR), enforce MFA across all access points, and regularly audit both human and non-human identity credentials.
In an interview with Dark Reading, Chet Wisniewski, director and global field chief information security officer at Sophos, emphasized the importance of aggressive defense-in-depth. “Every layer of defense, even if it can be bypassed, is a speed bump, an alert, or a potential clue to trigger a threat hunt,” he said. This approach involves using segmentation to slow down attackers, deploying zero-trust network access (ZTNA) to contain app exploits, and maintaining 24/7 threat detection and response capabilities.
In light of this report, organizations would do well to take a step back and reassess their security posture. While patch management remains essential, the fight against ransomware is increasingly about identity protection. By prioritizing MFA, enforcing it across all access points, and regularly auditing identity credentials, organizations can significantly reduce their risk of falling victim to a ransomware attack.
Source: Dark Reading — 2026-07-15