Ransomware Attacks Surge: 79% Now Initiated With Stolen Identities, Urging New Defense Strategies
79% of Ransomware Attacks Now Begin With Stolen Identities, Sophos Report Reveals
A new Sophos report released July 21, 2026 reveals that compromised credentials now fuel nearly four out of five ransomware attacks globally — reshaping how security professionals must think about defense.
The findings mark a decisive turning point in cybersecurity strategy. Identity theft has quietly overtaken every other attack vector as the preferred entry point for cybercriminals — and the numbers demand urgent attention from every organization handling sensitive data, managing remote workforces, or operating critical infrastructure.
The Identity Crisis Reshaping Cybersecurity
The Sophos report found that 79% of ransomware incidents exploited legitimate user logins to gain initial access. That figure dwarfs malicious email (26%) and phishing (24%) combined — making compromised identity the single most dominant ransomware entry point and attack vector by a significant margin.
Malicious actors are leveraging stolen identities across multiple attack surfaces:
- Systems and application intrusions accounted for 38% of identity-based incidents
- Remote device logins represented 30%
- Firewalls were exploited in 21% of cases
- VPNs accounted for 8%
- IoT devices for 3%
Chandra Gnanasambandam, Chief Technology Officer at SailPoint, said the data confirms what security professionals have long warned. "Attacks that once took a year to succeed now take about an hour," he said. "Cybercrime has industrialized, and with 95% of access still standing rather than granted just in time, identity is the obvious weak point."
The shift toward identity exploitation is part of a broader industrialization of cybercrime — one that mirrors, in an unsettling way, the efficiency-driven model of legitimate enterprise technology. Organizations that have not yet audited their identity and access posture are operating with a significant and measurable blind spot.
Why Stolen Credentials Are So Effective
When an attacker uses a legitimate username and password, they effectively inherit the trust that organization has extended to that user. There are no malware signatures to detect, no unusual file types to flag — just a seemingly authorized session moving through the environment. This is precisely why credential-based attacks are so difficult to identify using traditional perimeter defenses, and why detection strategies must evolve beyond signature-based tools toward behavioral analytics and continuous validation.
Phishing Surges While Vulnerability Exploits Decline
Not every threat vector is moving in the same direction. The exploitation of known security vulnerabilities dropped sharply — from 32% of incidents in 2025 to just 18% in 2026. That decline suggests organizations are improving their patch management practices.
However, phishing and malicious email attacks are trending in the opposite direction:
- Malicious emails served as the entry point in 26% of ransomware incidents this year — up from 19% in 2025
- Phishing attacks caused 24% of incidents in 2026 compared to 18% the previous year
- Brute force attacks remained relatively stable at 23% this year versus 22% in 2025
Mika Aalto, Co-Founder and CEO at Hoxhunt, offered a striking analogy to frame phishing's evolving role. "If ransomware is the explosion, phishing is often the spark," he said. Aalto pointed to research showing AI-generated phishing surged 14-fold almost overnight at the turn of 2025 to 2026 — not through entirely new tactics but through the rapid modernization of old ones. "Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale," he added.
The Automation Behind Brute Force Persistence
Brute force attacks held steady because automated credential-stuffing tools remain cheap and accessible — a reminder that even unsophisticated methods continue to yield results when organizations fail to enforce strong password policies. The persistence of this attack vector underscores a fundamental truth: attackers will always exploit the path of least resistance, and weak or reused credentials remain one of the most reliably exploitable weaknesses across industries.
The Organizational Gaps Enabling Attackers
The report exposed troubling internal vulnerabilities that help explain why so many attacks go undetected:
- 62% of cybersecurity leaders cited network security gaps as the primary reason cyberattacks evade detection
- 58% reported their organization was inhibited by a lack of resources or employee expertise
- 57% believed their organization had not implemented sufficient cybersecurity solutions
Shane Barney, Chief Information Security Officer at Keeper Security, said the implications are clear. "Once attackers obtain a legitimate identity, they can move through an environment undetected, escalating privileges and staging ransomware before most teams know something is wrong," he warned. Barney emphasized that strong password policies, Multi-Factor Authentication as a core security control, and continuous monitoring remain foundational — but are no longer sufficient on their own.
James Maude, Field CTO at BeyondTrust, argued the industry needs to invest more in prevention rather than post-breach response. "Ransomware and other threats are only as effective as the privileges and access they manage to acquire," he said. "If we can implement better hygiene and focus on least privilege, then threat actors are far less likely to ransomware us in the first place."
The Business Case for Identity-Centered Defense
The financial and operational consequences of a successful ransomware attack extend well beyond the ransom itself. Downtime, reputational damage, regulatory penalties, and recovery costs routinely dwarf the initial demand. Viewed through that lens, investment in identity governance and access management is not a cost center — it is risk mitigation with a measurable return. Organizations that align their security posture with identity and access management best practices are significantly better positioned to detect and contain intrusions before they escalate.
Trey Ford, Chief Strategy and Trust Officer at Bugcrowd, offered a sobering long-term outlook. "Criminals have established a scalable business model and we expect to see ransomware attack volume continue to grow," he said. Ford also cautioned that reported incidents likely underrepresent the true scale of the problem — larger targets with bigger payout potential have drawn the most aggressive investment in mitigation.
Translating the Data Into Action
Organizations looking to apply these findings can take immediate action in three meaningful ways.
- Audit and reduce standing administrative access — eliminating the privileges attackers depend on once credentials are stolen
- Implement continuous identity validation and least-privilege principles — shrinking the blast radius of any successful breach
- Evolve security training beyond awareness into behavioral conditioning — shaping real-time instincts rather than delivering static information, directly addressing the human factor that phishing continues to exploit at scale
The CISA Identity and Access Management Guidance provides a practical federal framework that organizations of all sizes can reference when building or stress-testing their identity security programs.
The data from this report is unambiguous: identity is now the primary battlefield in ransomware defense. Organizations that treat credential security, access governance, and behavioral monitoring as strategic priorities — rather than compliance checkboxes — will be materially better equipped to withstand the attacks that are already underway.