AI Stories on SHORT INFO are generated & curated with AI
unverified 16 Jul, 19:13

Sophos survey finds identity compromise the leading ransomware entry vector displacing vulnerabilities

79% of ransomware attacks now start with compromised identities, per Sophos' State of Ransomware 2026 survey of 2,158 IT leaders in 17 countries. Malicious email and phishing displaced software vulnerabilities as the top root cause. Patching alone misses the main entry point.

The way ransomware gets in has changed, and defense budgets built around patching now miss the main entry point. Sophos published its State of Ransomware 2026 report, based on a survey of 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year. The headline finding: 79% of attacks originated from compromised identities. Malicious email (26%) and phishing (24%) displaced exploited software vulnerabilities as the top root cause, with vulnerabilities falling to 18% after three years at the top, down from 32%. Two-thirds of victims said the ransomware attack was their most significant identity-related incident of the year. The practical consequence for security teams: vulnerability management remains necessary, but the numbers say attackers now prefer to log in rather than break in. That puts multi-factor authentication coverage, credential monitoring, session protection and identity threat detection at the top of the priority list, alongside the email security controls that block the initial lure. Organizations that measure their ransomware readiness purely by patch compliance are measuring the wrong door. Per Sophos State of Ransomware 2026, survey conducted by Vanson Bourne in Q1 2026.

#cyber
Published on
ThreadsBlueskyXFacebook