The cyber threat landscape has officially shifted. According to the newly released seventh annual State of Ransomware report by major cybersecurity firm Sophos, identity is now the leading ransomware entry point. The era of relying solely on perimeter defenses is over.
The vendor-agnostic survey, which polled IT and cybersecurity leaders across 17 countries, reveals a startling reality: four in five (79%) of all ransomware attacks now start with compromised identities. For the first time in four years, exploited vulnerabilities are no longer the most common root cause, having been overtaken by malicious emails (26%) and phishing (24%).
The UK Faces the Highest Global Ransom Demands
The financial implications detailed in the report are severe. The United Kingdom faced the highest median ransom demand globally, reaching a crippling $2.5 million over the last 12 months. Globally, the average recovery cost following a ransomware attack has surged to $1.7 million per incident, despite the median ransom demands dropping by 65% over the past two years.
- Encryption Rates Rebound: 56% of targeted organizations had their data encryptedโreversing a two-year downward trend. Among these, 16% suffered both encryption and data theft (double extortion).
- The Exploit Premium: While identity is the most common entry point, vulnerabilities remain high-value targets. 59% of ransom demands that started with an exploited firewall vulnerability exceeded $1 million.
- Payment Rates: 48% of organizations whose data was encrypted chose to pay the ransom, though 51% of payers successfully negotiated a settlement below the initial demand.
AI: Accelerating the Threat
Ross McKerchar, Chief Information Security Officer at Sophos, warned that Artificial Intelligence is giving threat actors a massive advantage. “As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” McKerchar stated.
McKerchar noted that AI allows attackers to enumerate identity misconfigurations and network weak points far more cheaply and quickly than ever before, rendering security by obscurity completely obsolete.
Technical Fix Guide: Defending the Identity Perimeter
Perhaps the most alarming statistic from the report is this: Multi-factor authentication (MFA) was deployed in 97% of incidents where compromised credentials were the root cause. This proves that basic MFA is no longer enough. To build an AI-driven, resilient defense, organizations must implement the following Sophos-recommended best practices:
1. Treat Identity as a Foundational Layer
Basic push-notification MFA can be easily bypassed via MFA Fatigue or Adversary-in-the-Middle (AiTM) phishing. Organizations must prioritize Identity Threat Detection and Response (ITDR), enforce phishing-resistant MFA (such as FIDO2 security keys), and rigorously audit both human and non-human (API/Service) identities.
2. Leverage Firewall Telemetry & Reduce Exposure
Minimize internet-facing services like admin access panels and user portals. Ensure firewalls receive rapid, automated updates to prevent high-value vulnerability exploits. Crucially, connect firewalls to XDR (Extended Detection and Response) or MDR solutions so telemetry can detect early-stage ransomware activity before payloads are deployed.
3. Maintain Aggressive Exposure Management
Defenders cannot rely on patching alone to keep pace with AI-assisted vulnerability discovery. Maintain rigorous patching schedules but also utilize AI-assisted tools internally to accelerate vulnerability identification and remediation.
4. Invest in Immutable Backup Infrastructure
Backups must be tested regularly and stored completely offline or in immutable formats. The report noted that 55% of organizations managed to recover within one week due to increased investment in backup infrastructure, highlighting its importance in incident response.
The Path Forward: Zero Trust is Mandatory
The findings from Sophos make one thing abundantly clear: if attackers have your credentials, perimeter firewalls mean nothing. The only sustainable defense against identity-based ransomware is the strict adoption of continuous verification.
For a comprehensive roadmap on securing your identities and implementing continuous verification, read our complete guide on Zero Trust Architecture.
Frequently Asked Questions
What is the leading cause of ransomware attacks in 2026?
According to Sophos’ 2026 State of Ransomware report, compromised identities are now the leading cause, accounting for 79% of all ransomware attacks. This has overtaken exploited vulnerabilities for the first time in four years, with malicious emails and phishing now driving initial access.
Does having MFA guarantee protection against ransomware?
No. The report found that MFA was already deployed in 97% of incidents where compromised credentials were the root cause. Basic push-notification MFA can be bypassed through MFA fatigue attacks or Adversary-in-the-Middle (AiTM) phishing, which is why phishing-resistant MFA like FIDO2 security keys is now recommended.
How is AI changing ransomware attacks?
AI is not creating entirely new attack methods yet, but it is accelerating existing ones. Attackers are using AI to identify identity misconfigurations and network weaknesses faster and more cheaply, allowing them to scale attacks beyond their previous capability, according to Sophos CISO Ross McKerchar.
Reported by CyberUpdates365 Desk
Delivering the latest insights on enterprise security, federal AI directives, and the future of IT infrastructure. Follow us for daily updates on how technology is reshaping the corporate landscape.




