Cybertech Europe 2026-IT Industry Official Media Partner

Sophos: Compromised identities were behind 79% of this year's ransomware attacks

Sophos State of Ransomware 2026 with report cover, key statistics and cybersecurity themes showing that compromised identities have become the most common route of entry for ransomware attacks. Sophos State of Ransomware 2026 with report cover, key statistics and cybersecurity themes showing that compromised identities have become the most common route of entry for ransomware attacks.
Sophos' State of Ransomware 2026 report shows that compromised identities are now the most common initial attack vector in ransomware attacks against businesses.

Looking for a Shorter Overview?

Key Moments

Identity-based breaches dominate

79% of ransomware attacks start with compromised identities and malicious emails are common.

Increased data encryption despite lower ransom demands

56 % of attacks lead to data encryption, an increase from the previous year.

More efficient recovery but increased costs

55 % restores operations within a week, but recovery costs average $1.7 million.

The importance of multi-factor authentication and identity management

97% of attacks with compromised credentials had MFA enabled, demonstrating the need for proper implementation.

Sophos’ latest report shows that compromised identities are now the most common route of entry for ransomware attacks. At the same time, the proportion of attacks where data is encrypted is increasing, even though both ransom demands and ransom amounts continue to decrease.

Sophos has published the seventh edition of its annual report State of Ransomware, based on a survey of IT and cybersecurity leaders in 17 countries. The report shows that four out of five ransomware attacks in the past year, or 79 percent, began with compromised identities, making identity-based breaches the most common initial attack vector for ransomware.

For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware attacks.

According to Sophos The development reflects a clear shift in attackers’ methods. For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware attacks. Instead, malicious emails (26 percent) and phishing (24 percent) dominate, indicating that cybercriminals are increasingly focusing on obtaining user login credentials rather than exploiting technical security flaws.

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

At the same time, the report shows that attacks that exploit vulnerabilities in firewalls, for example, are still particularly costly. In 59 percent of these cases, the ransom demand was at least $1 million, compared to 48 percent for all ransomware attacks.

The report also shows that 56 percent of organizations affected by ransomware had their data encrypted, an increase from the previous year and breaking the downward trend seen over the past two years.

State of Ransomware 2026

Key findings in the report

  • Two-thirds of ransomware victims (67 percent) say that the ransomware attack was also their most serious identity incident, further highlighting that compromised identities have become a key attack method.
  • In 56 percent of ransomware attacks, attackers managed to encrypt an organization’s data. Of these incidents, 16 percent involved both data encryption and data theft. This is up from 50 percent in 2025, but is still below the peak of 75 percent seen in 2023.
  • When data was encrypted, 48 percent of organizations chose to pay the ransom, bringing the average payment rate over the past four years to around 50 percent.
  • Only 34 percent of organizations with 100 to 250 employees were able to stop the attack before encryption or extortion was carried out, compared to 46 percent of organizations with 3,001 to 5,000 employees.
  • In 97 percent of ransomware attacks that began with compromised login credentials, some form of multi-factor authentication (MFA) was enabled. According to Sophos This shows that MFA is still an important security measure, but that it is not enough on its own if it is not properly implemented and covers all access points.
  • The UK had the highest median ransom demand value in the survey, at $2.5 million.

Faster recovery despite increased costs

The report also shows that organizations have become better at recovering from a ransomware attack. Improved backups and more efficient recovery procedures mean that 55 percent were able to recover within a week, while 16 percent managed to do so in less than 24 hours.

Meanwhile, many organizations continue to negotiate with the attackers. Of those who chose to pay the ransom, 51 percent were able to negotiate the ransom down to an amount below the attackers’ original demands. The median ransom demand has also decreased by 65 percent over the past two years. The percentage of organizations paying ransoms has fallen to 48 percent, the second lowest level since Sophos began tracking the trend.

Despite this, overall recovery costs continue to rise, with the average cost of recovering from a ransomware attack now standing at $1.7 million per incident.

Sophos recommends

To reduce the risk of ransomware, Sophos recommends that organizations:

  • Treat identity as a central part of security efforts by implementing advanced identity threat monitoring, using phishing-resistant multi-factor authentication, and regularly reviewing both human and machine identities,
  • Strengthen backup and recovery by testing backups regularly, storing them offline or in immutable formats, and integrating them into the organization's incident management plan.,
  • systematically working on exposure management through continuous patching, prioritizing internet-exposed systems, and using AI-supported tools to identify and remediate vulnerabilities faster,
  • Reduces firewall exposure by ensuring timely security updates, limiting internet-exposed management interfaces, and connecting firewalls to XDR and MDR platforms for faster detection and response to attacks.

Related Posts

Why ransomware attacks are returning

Ransomware continues to be a major threat to businesses worldwide. Attacks are becoming more sophisticated and many organizations are repeatedly affected with serious consequences such as

Barracuda warns: 79 % ransomware risk if late action on email breach

A new global study from Barracuda Networks shows that companies that take more than nine hours to respond to an email breach run 79

Ransomware 2025: AI drives new cyber threats – Acronis report reveals worrying trend

A new global report on Ransomware 2025 from cybersecurity firm Acronis shows that the threat continues to dominate globally. At the same time, AI is being used to amplify social engineering attacks such as

Questions Answered

What is the most common entry point for ransomware attacks today?

Compromised identities are behind 79 percent of attacks.

How have ransomware attack methods changed?

Malicious email and phishing have replaced vulnerabilities as the most common method.

How often is data encrypted in ransomware attacks?

56 percent of attacks result in data encryption, an increase from previous years.

What recommendations does Sophos make to reduce ransomware risk?

Focus on identity security, backup, patching and firewall strategies.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED