
Identity-based attacks and abuse of compromised credentials have become the most common method cybercriminals use to hit networks with ransomware, according to analysis of real-world incidents. A new report from Sophos shows that 79 percent of ransomware attacks can be traced back to an initial intrusion which exploited compromised identities and legitimate user logins. It also found that:
- Malicious emails accounted for the initial entry point for ransomware in 26 percent of analyzed incidents, up from 19 percent in 2025.
- Phishing attacks, often used to steal legitimate login credentials, were the root cause of ransomware attacks in 24 percent of incidents, which is up from 18 percent during the previous year.
- The third most common entry point for ransomware incidents was brute force attacks, a method which sees cybercriminals use automation and trial and error to breach commonly used or weak passwords. This accounted for 23 percent of ransomware attacks, a slight drop from 22 percent during the previous year.
Identity-based attacks have risen at the expense of vulnerabilities being exploited. Previously, the most common root cause of ransomware incidents, the percentage of attacks which started with attackers exploiting known security vulnerabilities dropped from 32 percent in 2025 to 18 percent in 2026. Attackers are leveraging the exploited identities in several different ways, using them to access:
- Exposed applications or systems (38 percent).
- Remote device logins (30 percent).
- Firewalls (21 percent).
- Exposed VPNs (eight percent).
- IoT devices as the initial point of entry (three percent).
According to the more than 2,000 cybersecurity leaders surveyed, 62 percent cited security gaps in the network, both known and unknown as a potential reason for cyber-attacks going undetected. More than half (58 percent) said their organization was held back by a lack of people or appropriate expertise. Meanwhile, 57 percent said that they felt that their organization had not implemented the correct level of cybersecurity solutions or protections to keep the network or users safe.
Industry stakeholders shared the following thoughts.
Chandra Gnanasambandam, CTO, SailPoint
"This data confirms what we've been saying: 79 percent of ransomware attacks start with identity — nearly double malicious email and phishing combined. That's exactly why those like us in the industry have been ringing the identity bell for years. This is the new normal.
"Attacks that once took a year to succeed now take about an hour, cybercrime has industrialized, and with 95 percent of access still standing rather than granted just in time, identity is the obvious weak point. It's why security is undergoing one of its biggest shifts, moving from 25 years of human-centered defense to a human-plus-AI world that demands adaptive identity and zero standing privilege as baseline."
Shane Barney, CISO, Keeper Security
"Stolen credentials are now the dominant ransomware entry point, and the trend is accelerating. Once attackers obtain a legitimate identity, they can move through an environment undetected, escalating privileges and staging ransomware before most teams know something is wrong.
"Organizations need to recognize that identity is now the primary security perimeter. Strong password policies, Multi-Factor Authentication (MFA) and continuous monitoring remain foundational, but they're no longer sufficient on their own.
"Security teams need visibility into who is accessing critical systems, whether that access is appropriate and how privileged accounts are being used. Applying least-privilege principles, eliminating standing administrative access and continuously validating identities significantly reduces the opportunities attackers have to abuse stolen credentials. The goal isn't just stopping the initial breach. It’s limiting the blast radius when credentials are compromised."
Trey Ford, Chief Strategy and Trust Officer at Bugcrowd
"Criminals have established a scalable business model, and we expect to see ransomware attack volume continue to grow. We also need to bear in mind that there will be a gap in reported incidents versus overall ransomware incidents. Larger targets, with bigger payout potential, will have seen the most aggressive corporate investment (process and technology) mitigating exposure to this attack pattern - it is still an unsolved space."
Mika Aalto, Co-Founder and CEO, Hoxhunt
"Phishing is rarely the end goal. It’s typically the front door to something much bigger, including data theft, cloud compromise, or ransomware. Here’s an analogy: If ransomware is the explosion, phishing is often the spark.
"Recent research found a step change at the turn of 2025 to 2026, when AI-generated phishing surged 14-fold almost overnight. The big shift isn’t brand-new tactics and zero-day messaging, it’s the modernization of old attacks. Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale.
"Phishing never really went away, it simply got an upgrade. With that being said, people are trained to obey authority, and phishing attacks are designed to push people into bypassing normal checks. Organizations need to normalize ‘see something, say something’ behavior and make verification frictionless.
"Phishing has evolved beyond static text and awareness must do the same. The entire concept of ‘security awareness training’ is outdated if it stops at awareness. The next generation of defense is behavioral, not informational. We’re moving from telling people what to do to shaping what they actually do, in real time. We are building an essential set of security reflexes and instincts."




















