Ransomware becomes an identity crisis: 79% of attacks now start with stolen credentials
Nearly four in five ransomware attacks over the past year began not with a software exploit but with an identity, either credentials secured for abuse or credentials already stolen and put to work. That single figure, 79%, sits at the centre of the seventh annual Sophos State of Ransomware report, and it marks the clearest evidence yet that ransomware has become an identity problem wearing a malware disguise. Drawn from 2,158 IT and cybersecurity leaders across 17 countries whose organisations were hit in the past year, the report describes a threat landscape where falling ransom figures mask a quiet and consequential shift in how attackers get in, and where the defences most organisations already own are proving unequal to the change.
The movement at the point of entry is the story, and it is a reordering of the entire threat hierarchy. After three consecutive years at the top of the rankings, exploited vulnerabilities are no longer the leading root cause of ransomware, dropping 14 percentage points in a single year to 18% from 32% in the 2025 report. Email-based methods have moved into the vacuum, with malicious emails accounting for 26% of incidents and phishing a further 24%, together making up half of all attacks. Compromised credentials held steady at 23%, consistent with prior years. What ties the new leaders together is that each turns on a person rather than a patch, and the report states its conclusion plainly, noting that 79% of attacks started with an identity-based approach and that this “highlights why identity security is a critical piece in a holistic security posture.” Two-thirds of victims, 67%, confirmed that their ransomware incident was the same event as their most significant identity attack, a finding the report describes as establishing identity compromise as a dominant ransomware delivery mechanism.
For the wider sector, the shift redraws where defensive budgets should sit. A decade of ransomware guidance has trained security teams to patch fast and patch first, on the reasonable basis that exploited vulnerabilities were the most travelled route in. That route is narrowing, though not through any collapse in attacker capability. The report cautions that the decline may prove temporary, warning that “given the speed and scale of frontier AI's vulnerability discovery capabilities, organisations should remain alert to the possibility of an increase in ransomware attacks where the root cause is an exploited vulnerability in the year ahead.” The immediate lesson is that patching alone can no longer carry a defensive strategy when half of all intrusions now walk through the inbox and the login page.
The launch of Sophos Fusion, the company's new defence system unveiled on 15 July, was built around this same diagnosis. “As AI increases the speed, scale and complexity of attacks, organisations need a modern connected, intelligent and adaptive defence,” said Joe Levy, Chief Executive Officer, Sophos. The report gives that argument its statistical backbone, and nowhere more sharply than in its findings on the safeguards organisations most rely on to keep identities from being turned against them.
Multi-factor authentication is deployed almost everywhere, and failing anyway
If identity is the battleground, the survey delivers an uncomfortable verdict on the tool meant to hold it. Among incidents where compromised credentials were the root cause, 97% of victims had multi-factor authentication enabled in some capacity at the time of the attack, with respondents using an average of 2.5 methods. One-time passwords, deployed by 52% of victims, push-based applications at 51%, and passkeys, also at 51%, were the most widely used, with FIDO2 tokens present in 32% of cases and security questions in 28%. MFA, in other words, was present in almost every breached environment and stopped none of them.
The number demands interpretation rather than despair. Enabled in some capacity is doing quiet work in that sentence, and the report reaches the same conclusion, observing that the high deployment rate among victims “indicates that it may not have been fully deployed across all relevant systems, creating gaps for attackers to exploit,” and that while MFA “remains an essential element of effective cyber defence strategies, it is not sufficient on its own to prevent credential-based attacks as bypass techniques continue to evolve.” Those techniques now range from adversary-in-the-middle phishing kits to session-token theft, each treating a single MFA prompt as an obstacle rather than a wall. For a market that has spent years selling MFA as the baseline of good hygiene, that is an awkward and necessary recalibration, and it explains why the report pairs its MFA guidance with a push toward identity threat detection and response.
Where attacks take hold within an environment is data the report surfaces for the first time, and it sharpens the identity picture considerably. Exposed applications and systems were the most common entry point at 38%, followed by user devices at 30% and firewalls at 21%. Compromised credential attacks concentrated on exposed applications and systems, where they reached 59%, a pattern the report links to the broader shift toward cloud and SaaS environments “where internet-facing systems present a large and growing attack surface.” Brute-force attempts, by contrast, targeted firewalls at a notably high rate of 44%, underlining the value of rate-limiting and account lockout policies on perimeter devices that too often escape that discipline.
Firewalls earn their keep in the defensive chain even so, and the report puts hard numbers on the value of early detection. Some 61% of victims said their firewall detected the attack before the payload detonated, and organisations in that position saw data encrypted 50% of the time. Where the firewall identified the attack only after deployment, the encryption rate rose to 65%, and where it failed to spot the attack at all, a scenario reported by 7% of victims, encryption reached 71%. The 21-point spread between the best and worst outcomes makes the case for firewall telemetry feeding broader detection systems, and it carries a financial edge, since 59% of ransom demands from attacks that began with an exploited vulnerability on the firewall were for $1 Million or more, against 48% of demands overall. Firewalls, as the report puts it, “hold a very privileged position in the organisational infrastructure,” and attackers price that access accordingly.
Ransom figures are falling, but encryption success is creeping back up
The financial headlines point in a reassuring direction, and organisations are negotiating harder than they once did. Median ransom demands fell to $698,000, a decline of 65% over two years from $2 million in the 2024 report, while the mean demand came in at $3.13 million, itself down 28% since 2024. Median payments dropped to $769,000 from $1 Million a year earlier, and just under half, 48%, of payments were for $1 Million or more, down from 52% the previous year. Just over half of organisations that paid, 51%, handed over less than the sum originally demanded, with the median payment settling at 90% of the initial ask. The typical recovery bill moved the other way, rising 11% to $1.7 Million once ransom payments are excluded, though that figure remains 38% below the $2.73 Million peak recorded in 2024.
Demands also scale sharply with a target's means. Organisations with revenue under $50 million faced median demands of roughly $140,000, while those above $5 billion faced medians of $5.7 million, a spread the report reads as evidence that “attackers conduct reconnaissance to calibrate demands based on perceived ability to pay.” Propensity to pay, meanwhile, varied widely by sector: local and state government paid in 72% of cases and media, leisure and entertainment in 64%, more than double retail's 32%, the lowest of any sector, which the report attributes to public bodies facing acute pressure to restore citizen-facing services while retail organisations prove more willing to “weather the storm.”
Beneath the falling numbers runs a countervailing trend that deserves as much attention as the reassuring ones. Over half of attacks, 56%, succeeded in encrypting data this year, up six points from the 50% low recorded in 2025 and a reversal after two years of steady decline. The figure remains below the 76% peak of 2023, but the report warns that the turn “warrants attention: after two years of declining encryption success, attackers appear to be regaining some ground.” Within that total, 16% of attacks involved both encryption and data theft, which the report singles out as “particularly concerning, as these dual-impact attacks give attackers multiple leverage points for extortion.”
That resilience is precisely where the good news concentrates. Backup-based recovery surged to 66% of encrypted-data cases, up from 54% a year earlier, in what the report describes as renewed investment in backup infrastructure after a dip in 2025. The proportion paying a ransom to retrieve data fell to 48%, the lowest in three years, and only 2% reported getting no data back at all, meaning recovery through some means is now nearly universal once data is encrypted. More than half, 55%, were operational again within a week. The human cost, though, stayed close to universal and immune to the operational gains: among organisations that had data encrypted, 99% reported lasting repercussions for their IT and cybersecurity teams, with heightened anxiety about future attacks the most cited impact at 41%, and for more than one in five, 21%, the leadership team was replaced as a direct result. Increased recognition from senior leaders, rising to 36% from 31%, was the only measured repercussion to climb year over year.
The vendor answers bet on connection over accumulation
Sophos' response to the picture its own research paints is a system rather than another product, and the wager is a pointed one for an industry that has long grown by addition. Fusion unites security operations, endpoint, network, identity, email and cloud into a single architecture, and its pitch rests on a diagnosis the report supports at every turn: the typical enterprise runs more than 45 separate security products, leaving teams with more dashboards, more spending and more manual work while attackers move at machine speed. The system is the evolution of Sophos Central, used by 625,000 organisations, now rebuilt to incorporate Secureworks Taegis analytics following the company's 2025 acquisition of the firm, and it is designed to be open as well as native, with more than 500 third-party integrations feeding the same shared data layer so existing tools operate as part of the system rather than beside it.
The company points to its own agentic security operations centre, serving over 40,000 customers, where 52% of cases are resolved entirely by AI and the average time from alert to automated response is 89 seconds. “Sophos Fusion is built as a defence system optimised for Human-AI workflows,” Levy said. He added that the company brings “the most complete solution to a new category, a timely advancement demanded by the AI era.” The claim to a new category is a commercial one, and rival vendors are converging on similar language around unified platforms and agentic operations, which makes the report's independent data the more useful measure of whether the underlying thesis holds.
On that measure, the direction of the evidence is consistent. Better outcomes clustered around organisations whose defences shared context, from early firewall detection to renewed backup discipline, while the persistent weaknesses, cited by 62% who pointed to a security gap, known or unknown, and 58% to a shortage of people or skills, grow more dangerous as adversaries turn AI to finding weaknesses faster and orchestrating attacks across multiple control points at once. The report's closing argument is that closing that gap “will depend less on adding more tools and more on connecting the ones already in place.” On its own numbers, the organisations best placed for what comes next are those that treat identity as a foundational security layer rather than an afterthought, and sustain the executive attention that the rising recognition figure suggests is finally arriving, on a problem changing shape faster than the ransom figures alone reveal.