Identity Attacks Overtake Exploits as Top Ransomware Cause

Ransomware has long been a major concern for businesses and individuals alike, but recent data suggests that identity attacks have become the dominant root cause of these devastating cyber incidents.

According to Sophos’ State of Ransomware 2026 report, malicious email and phishing attacks have surpassed vulnerability exploitation as the top reasons behind ransomware attacks. A staggering 67% of victims reported that their ransomware attack was also their most significant identity attack over the past year. This shift in tactics highlights the growing importance of protecting identities in the fight against cybercrime.

The data is clear: email-based attacks are now driving the majority of ransomware incidents. With malicious email accounting for 26% and phishing responsible for 24% of cases, it’s no longer a question of whether an organization will be targeted by attackers, but rather when. This trend suggests that relying solely on technical vulnerability patching is insufficient to prevent these attacks.

One of the most striking findings in the report is that even when multifactor authentication (MFA) was deployed in 97% of cases where compromised credentials were the root cause of ransomware attacks, it failed to prevent compromise. Sophos offers two possible explanations for this failure: either MFA may not have been fully deployed across all relevant systems, creating gaps for attackers to exploit, or bypass techniques used by attackers may be evolving faster than traditional MFA can keep up.

This development underscores the need for a more comprehensive approach to identity protection. Organizations should prioritize identity threat detection and response (ITDR), enforce multifactor authentication across all access points, and regularly audit both human and non-human identity credentials. Rather than relying solely on MFA, organizations should adopt an aggressive defense-in-depth strategy that includes segmentation, zero-trust network access, and 24/7 threat detection and response capabilities.

As Chet Wisniewski, director and global field chief information security officer at Sophos, notes, “Every layer of defense, even if it can be bypassed, is a speed bump, an alert, or a potential clue to trigger a threat hunt.” This approach may seem daunting, but it’s essential in today’s rapidly evolving cyber landscape.

Ultimately, the shift towards email-based attacks and compromised credentials as the primary root causes of ransomware incidents means that organizations must adapt their security strategies accordingly. By prioritizing identity protection and adopting a more comprehensive defense-in-depth approach, businesses can better protect themselves against these devastating cyber incidents and stay ahead of the attackers.


Source: Dark Reading — 2026-07-15