News

79% of ransomware attacks begin with stolen credentials, reports find

It’s revealed that 79% of ransomware attacks now begin with compromised identities instead of exploited software vulnerabilities. The finding comes from Sophos’ Global State of Ransomware 2026 report, which surveyed IT and cybersecurity leaders across 17 countries. The data shows a major shift in how attackers are gaining access to systems, which marks a turning point in global ransomware tactics.

For the first time in four years, exploited vulnerabilities are no longer the top entry point for ransomware. Instead, malicious emails (26%) and phishing campaigns (24%) have become the leading causes.

Sophos says this change shows how cybercriminals increasingly target human and machine identities to breach networks faster and more effectively.

The report also found that 59% of ransom demands linked to exploited firewall vulnerabilities exceeded $1 million, up from 48% last year.

While vulnerabilities remain high-value targets, identity-based attacks are now the dominant method. This signals a new era of ransomware delivery focused on credential theft and social engineering.

Also Read: Report: 71% of organizations faced identity breaches in the past year

Sophos warns that organizations must strengthen identity management and email security to stay protected. As attackers experiment with AI-driven tools, identity compromise could become even more common, making proactive defense essential for businesses worldwide.

Bryan Rilloraza has been a fixture in the local tech scene for over a decade, sharing his perspective as a tech enthusiast and industry veteran. Backed by an MBA from De La Salle University, a Bachelor’s Degree from the University of the Philippines, and 20 years of corporate experience in the telecommunications and banking sectors, Bryan provides a practical, real-world analysis of how technology serves the consumer.

Write A Comment