

A new report from Sophos found the most common method malicious actors use to enact ransomware is the abuse of compromised credentials. 79% of incidents exploited legitimate user logins and identities in order to gain initial access.
The research also found that malicious actors are leveraging identities in several ways, such as intruding on systems or applications (38%), remote device logins (30%), firewalls (21%), VPNs (8%) and IoT devices (3%) for initial access.
Key findings from the report include:
- Malicious emails were the entry point for ransomware in 26% of incidents, showing an increase from 19% of incidents in 2025.
- Phishing attacks caused 24% of incidents, often to steal login credentials. This is an increase from the last year, in which phishing attacks represented 18% of incidents.
- Brute force attacks remained relatively even from the previous year (22% of incidents in 2025), accounting for 23% of incidents this year.
- The exploitation of known security vulnerabilities decreased from from 32% last year to 18% in 2026.
- 62% of cybersecurity leaders cite network security gaps as the reason cyberattacks go undetected. 58% reported their organization was inhibited by lack of resources or employee expertise, and 57% believe the organization had not implemented sufficient cybersecurity solutions.
Below, security leaders weigh in on these findings.
Security Leaders Weigh In
Chandra Gnanasambandam, Chief Technology Officer at SailPoint:
This data confirms what we’ve been saying: 79% of ransomware attacks start with identity — nearly double malicious email and phishing combined. That’s exactly why those like us in the industry have been ringing the identity bell for years. This is the new normal. Attacks that once took a year to succeed now take about an hour, cybercrime has industrialized, and with 95% of access still standing rather than granted just in time, identity is the obvious weak point. It’s why security is undergoing one of its biggest shifts, moving from 25 years of human-centered defense to a human-plus-AI world that demands adaptive identity and zero standing privilege as baseline.
Shane Barney, Chief Information Security Officer at Keeper Security:
Stolen credentials are now the dominant ransomware entry point, and the trend is accelerating. Once attackers obtain a legitimate identity, they can move through an environment undetected, escalating privileges and staging ransomware before most teams know something is wrong.
Organizations need to recognize that identity is now the primary security perimeter. Strong password policies, Multi-Factor Authentication (MFA) and continuous monitoring remain foundational, but they’re no longer sufficient on their own. Security teams need visibility into who is accessing critical systems, whether that access is appropriate and how privileged accounts are being used. Applying least-privilege principles, eliminating standing administrative access and continuously validating identities significantly reduces the opportunities attackers have to abuse stolen credentials.
The goal isn’t just stopping the initial breach. It’s limiting the blast radius when credentials are compromised. Organizations that can’t see who has access to what, and can’t revoke it fast, will keep finding out after the fact. That’s what zero trust and strong identity governance are designed to prevent.
James Maude, Field CTO at BeyondTrust:
In order to effectively deal with ransomware and other threats, we need to invest more in shifting left. We must think more about securing identities and access to reduce our attack surface and blast radius in the event of compromise, rather than just thinking post breach. Ransomware and other threats are only as effective as the privileges and access they manage to acquire. Therefore, if we can implement better hygiene, and focus on least privilege, then threat actors are far less likely to ransomware us in the first place.
Trey Ford, Chief Strategy and Trust Officer at Bugcrowd:
Criminals have established a scalable business model, and we expect to see ransomware attack volume continue to grow. We also need to bear in mind that there will be a gap in reported incidents versus overall ransomware incidents. Larger targets, with bigger payout potential, will have seen the most aggressive corporate investment (process and technology) mitigating exposure to this attack pattern – it is still an unsolved space.
Mika Aalto, Co-Founder and CEO at Hoxhunt:
Phishing is rarely the end goal. It’s typically the front door to something much bigger, including data theft, cloud compromise, or ransomware. Here’s an analogy: If ransomware is the explosion, phishing is often the spark.
Recent research found a step change at the turn of 2025 to 2026, when AI-generated phishing surged 14-fold almost overnight. The big shift isn’t brand-new tactics and zero-day messaging, it’s the modernization of old attacks. Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale. Phishing never really went away, it simply got an upgrade. With that being said, people are trained to obey authority, and phishing attacks are designed to push people into bypassing normal checks. Organizations need to normalize ‘see something, say something’ behavior and make verification frictionless.
Phishing has evolved beyond static text and awareness must do the same. The entire concept of ‘security awareness training’ is outdated if it stops at awareness. The next generation of defense is behavioral, not informational. We’re moving from telling people what to do to shaping what they actually do, in real time. We are building an essential set of security reflexes and instincts.
https://www.securitymagazine.com/articles/102440-79-of-ransomware-attacks-start-with-compromised-identities


