Sophos’ latest report shows that compromised identities are now the most common route of entry for ransomware attacks. At the same time, the proportion of attacks where data is encrypted is increasing, even though both ransom demands and ransom amounts continue to decrease.
Sophos has published the seventh edition of its annual report State of Ransomware, based on a survey of IT and cybersecurity leaders in 17 countries. The report shows that four out of five ransomware attacks in the past year, or 79 percent, began with compromised identities, making identity-based breaches the most common initial attack vector for ransomware.
According to Sophos The development reflects a clear shift in attackers’ methods. For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware attacks. Instead, malicious emails (26 percent) and phishing (24 percent) dominate, indicating that cybercriminals are increasingly focusing on obtaining user login credentials rather than exploiting technical security flaws.
At the same time, the report shows that attacks that exploit vulnerabilities in firewalls, for example, are still particularly costly. In 59 percent of these cases, the ransom demand was at least $1 million, compared to 48 percent for all ransomware attacks.
The report also shows that 56 percent of organizations affected by ransomware had their data encrypted, an increase from the previous year and breaking the downward trend seen over the past two years.

Key findings in the report
- Two-thirds of ransomware victims (67 percent) say that the ransomware attack was also their most serious identity incident, further highlighting that compromised identities have become a key attack method.
- In 56 percent of ransomware attacks, attackers managed to encrypt an organization’s data. Of these incidents, 16 percent involved both data encryption and data theft. This is up from 50 percent in 2025, but is still below the peak of 75 percent seen in 2023.
- When data was encrypted, 48 percent of organizations chose to pay the ransom, bringing the average payment rate over the past four years to around 50 percent.
- Only 34 percent of organizations with 100 to 250 employees were able to stop the attack before encryption or extortion was carried out, compared to 46 percent of organizations with 3,001 to 5,000 employees.
- In 97 percent of ransomware attacks that began with compromised login credentials, some form of multi-factor authentication (MFA) was enabled. According to Sophos This shows that MFA is still an important security measure, but that it is not enough on its own if it is not properly implemented and covers all access points.
- The UK had the highest median ransom demand value in the survey, at $2.5 million.
Faster recovery despite increased costs
The report also shows that organizations have become better at recovering from a ransomware attack. Improved backups and more efficient recovery procedures mean that 55 percent were able to recover within a week, while 16 percent managed to do so in less than 24 hours.
Meanwhile, many organizations continue to negotiate with the attackers. Of those who chose to pay the ransom, 51 percent were able to negotiate the ransom down to an amount below the attackers’ original demands. The median ransom demand has also decreased by 65 percent over the past two years. The percentage of organizations paying ransoms has fallen to 48 percent, the second lowest level since Sophos began tracking the trend.
Despite this, overall recovery costs continue to rise, with the average cost of recovering from a ransomware attack now standing at $1.7 million per incident.
Sophos recommends
To reduce the risk of ransomware, Sophos recommends that organizations:
- Treat identity as a central part of security efforts by implementing advanced identity threat monitoring, using phishing-resistant multi-factor authentication, and regularly reviewing both human and machine identities,
- Strengthen backup and recovery by testing backups regularly, storing them offline or in immutable formats, and integrating them into the organization's incident management plan.,
- systematically working on exposure management through continuous patching, prioritizing internet-exposed systems, and using AI-supported tools to identify and remediate vulnerabilities faster,
- Reduces firewall exposure by ensuring timely security updates, limiting internet-exposed management interfaces, and connecting firewalls to XDR and MDR platforms for faster detection and response to attacks.








