Ransomware has always been about getting in. For years, the conventional wisdom was clear: keep your software patched, and you'd close the most dangerous door. That wisdom is now dangerously outdated. Attackers have moved on — and the data proves it. Identity-based attacks have overtaken software exploits as the single biggest driver of ransomware, and organisations still anchored to a vulnerability-patching mindset are leaving their front door wide open.
Here's what the numbers look like in 2026, and — more importantly — exactly what you can do about it.
The Tipping Point: Identity Is Now the Primary Ransomware Entry Point
The evidence is stark.
Sophos' State of Ransomware 2026 report reveals that identity is the dominant initial access vector, with four in five (79%) of ransomware attacks starting with compromised identities.
This marks a defining shift in the threat landscape.
For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware attacks, with malicious email (26%) and phishing (24%) taking the top spot.
Malicious email and phishing have dethroned the three-year reign of vulnerabilities (now at just 18%, down from 32%) as the top root cause of ransomware attacks.
The third most common root cause? Also identity-related.
Compromised credentials were the root cause in 23% of cases.
Identity-based attacks, including session hijacking, accounted for 64% of all incidents in 2024.
The message is clear: the battleground has shifted from patching servers to protecting people and their credentials.
Why Attackers Prefer to "Log In" Rather Than "Break In"
The shift isn't accidental — it's strategic.
Attackers are increasingly logging in rather than breaking in, then using legitimate access and built-in tools to deepen compromise and extort victims.
Valid credentials are stealthier, cheaper to acquire, and far harder to detect than noisy exploitation techniques.
Credential theft is now the primary way attackers gain initial access to enterprise networks, and the speed, scale, and sophistication with which they are weaponising stolen credentials is outpacing the ability of defenders to block them.
Infostealers are the fuel powering this shift.
Infostealer malware remains one of the most pervasive enablers of identity-based threats — quietly extracting credentials, cookies, and sensitive data from infected devices while evading traditional defences.
The downstream effect is devastating:
the Verizon DBIR 2025 report revealed that 54% of victims listed on ransomware extortion sites had evidence of infostealer logs containing their domain credentials, suggesting infostealers are a precursor in over half of ransomware cases.
Once credentials are stolen, they move quickly.
The window between a stolen log and a ransomware incident is shrinking — sometimes under 48 hours — as initial access brokers quickly sell verified logins to ransomware crews.
The MFA Myth: Why Multi-Factor Authentication Alone Isn't Enough
Most organisations reading this will think: "We have MFA — we're protected." The latest data tells a very different story.
Multi-factor authentication (MFA) was deployed in some capacity for 97% of incidents where compromised credentials were the root cause of ransomware attacks, making clear that MFA alone is not enough to stop ransomware, and that coverage gaps create exposure.
How are attackers getting around it?
These attacks increasingly leverage phishing-as-a-service (PhaaS) platforms like Tycoon 2FA, FlowerStorm, and Darcula, which use adversary-in-the-middle (AiTM) techniques to steal MFA tokens and session cookies.
MFA fatigue is equally dangerous —
MFA fatigue attacks appear in 14% of security incidents analysed in the 2025 Verizon Data Breach Investigations Report, making it the dominant MFA bypass method.
The high percentage of ransomware victims that had MFA deployed at the time of the attack indicates it may not have been fully deployed across all relevant systems, creating gaps for attackers to exploit. It also suggests that while MFA remains essential, it is not sufficient on its own as bypass techniques continue to evolve.
The Phishing-as-a-Service Economy Is Democratising Attack Capability
What's making identity attacks so pervasive isn't just sophistication — it's accessibility. Commoditised toolkits have lowered the barrier to entry for even low-skill criminals.
The growth of commoditised tactics like PhaaS has made these capabilities available to even low-skill threat actors, which is why we're seeing such a sharp spike in ransomware incidents tied directly to phishing.
Generative AI has supercharged phishing — IBM observed an 84% year-over-year spike in infostealer malware delivered via phishing emails.
Meanwhile,
Dataminr's 2026 Cyber Threat Landscape Report characterised 2025 as a structural shift toward accelerated identity-based intrusions, citing that a significant share of intrusions leveraged valid credentials, alongside growth in infostealer malware and AI-enabled social engineering.
The consequences are severe.
The average cost of a data breach hit a record $4.88 million, with identity-focused campaigns often causing longer dwell times.
And recovery doesn't guarantee data restoration —
the fastest 25% of intrusions reached data exfiltration in just 72 minutes in 2025 — down from 285 minutes in 2024.
What Identity Threat Detection and Response (ITDR) Actually Does
Closing the identity security gap requires moving beyond perimeter and endpoint defences alone, toward purpose-built tools that watch the identity layer in real time. This is the domain of Identity Threat Detection and Response (ITDR).
ITDR encompasses a suite of security practices and technologies dedicated to detecting, investigating, and responding to threats that target digital identities. As identity-related attacks such as compromised credentials, privilege escalation, and unauthorised access become increasingly common, ITDR solutions play a pivotal role — working by continuously monitoring identity activities, analysing behavioural patterns, and identifying anomalies that may signal malicious intent.
ITDR tools close the visibility gap that EDR and MFA leave open, surfacing credential misuse, lateral movement, and Active Directory activity that appears legitimate to endpoint and perimeter defences.
For example,
when an attacker uses valid credentials stolen via an infostealer to log in from a new device, EDR sees a normal authentication event — but ITDR sees an anomalous login with a new geolocation, unfamiliar device fingerprint, and credentials flagged in known breach databases, and raises an alert.
Sophos specifically recommends that
organisations prioritise identity threat detection and response (ITDR), enforce multifactor authentication across all access points, and regularly audit both human and non-human identity credentials.
Practical Tips: How to Close the Identity Security Gap Right Now
The good news is that there are concrete, actionable steps you can take immediately to dramatically reduce your exposure to identity-based ransomware attacks.
1. Upgrade to Phishing-Resistant MFA
Standard push-based MFA is no longer sufficient.
CISA calls phishing-resistant MFA the "gold standard" for authentication, and many regulators and standards bodies have formalised that position.
FIDO2/WebAuthn and PKI-based authentication use asymmetric cryptography where private keys never leave the authenticator device and each authentication response binds cryptographically to the requesting domain — no credential crosses the network for an attacker to intercept.
The real-world results are compelling:
Google reported zero successful phishing attacks against its 85,000+ employees after deploying FIDO security keys.
2. Deploy ITDR Alongside Your Existing Stack
Don't rely solely on your EDR or IAM tools.
Advanced behaviour analytics form the core of identity threat detection — ITDR tools establish baselines for normal login activity, privilege changes, and session patterns, and when deviations occur (such as logins from unfamiliar locations or excessive privilege escalation), alerts are generated with contextual precision.
3. Monitor and Audit Non-Human Identities
Human accounts are just one part of the picture.
Non-human identities — API keys, service accounts, OAuth tokens, and AI agent credentials — now outnumber human identities by more than 10-to-1 in most enterprises, and they represent a rapidly expanding blind spot.
Ensure your ITDR coverage extends to these assets.
4. Hunt Dark Web Credential Exposure Proactively
Don't wait for an attack to discover your credentials are compromised.
A record-breaking leak in February 2026 exposed 16 billion compiled credentials on the dark web.
Use dark web monitoring services to get ahead of credential exposures before attackers weaponise them.
5. Enforce Email Security Protocols Immediately
Organisations should deploy advanced email filtering, implement DMARC/DKIM/SPF protocols, and invest in regular phishing awareness training
— steps that directly address the most common ransomware entry points identified in 2026.
6. Adopt a Zero Trust Posture
A Zero Trust model treats every request as potentially hostile, regardless of origin — requiring strict identity verification, device validation, and context-aware access policies, with identity validated through phishing-resistant methods like FIDO2 or hardware tokens.
Conclusion: The Patch-First Era Is Over — Identity Is the New Perimeter
The ransomware threat has evolved, and the organisations that survive will be those that evolve with it. Patching software vulnerabilities remains essential, but
the fight against ransomware is now moving from patch management to identity protection.
With 79% of ransomware attacks beginning with a compromised identity, the greatest risk in your environment isn't an unpatched server — it's a stolen password or a hijacked session cookie.
The gap between where most organisations are today and where they need to be is real, but it's closeable. The technology exists, the frameworks are mature, and the threat data is unambiguous. The only question is whether you act before attackers exploit your identity blind spots, or after.
Ready to take control of your identity security posture? Conduct an identity security audit this week, map your coverage gaps against the ITDR capabilities discussed above, and prioritise deploying phishing-resistant MFA across your most critical access points. Don't let a stolen credential become your organisation's most expensive mistake.



