Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Sophos: Compromised identities were behind 79% of this year's ransomware attacks

Sophos State of Ransomware 2026 with report cover, key statistics and cybersecurity themes showing that compromised identities have become the most common route of entry for ransomware attacks. Sophos State of Ransomware 2026 with report cover, key statistics and cybersecurity themes showing that compromised identities have become the most common route of entry for ransomware attacks.
Sophos rapport State of Ransomware 2026 visar att komprometterade identiteter nu är den vanligaste initiala attackvektorn vid ransomware-attacker mot företag.

Sophos’ latest report shows that compromised identities are now the most common route of entry for ransomware attacks. At the same time, the proportion of attacks where data is encrypted is increasing, even though both ransom demands and ransom amounts continue to decrease.

Sophos has published the seventh edition of its annual report State of Ransomware, based on a survey of IT and cybersecurity leaders in 17 countries. The report shows that four out of five ransomware attacks in the past year, or 79 percent, began with compromised identities, making identity-based breaches the most common initial attack vector for ransomware.

According to Sophos The development reflects a clear shift in attackers’ methods. For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware attacks. Instead, malicious emails (26 percent) and phishing (24 percent) dominate, indicating that cybercriminals are increasingly focusing on obtaining user login credentials rather than exploiting technical security flaws.

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

At the same time, the report shows that attacks that exploit vulnerabilities in firewalls, for example, are still particularly costly. In 59 percent of these cases, the ransom demand was at least $1 million, compared to 48 percent for all ransomware attacks.

The report also shows that 56 percent of organizations affected by ransomware had their data encrypted, an increase from the previous year and breaking the downward trend seen over the past two years.

State of Ransomware 2026

Key findings in the report

  • Two-thirds of ransomware victims (67 percent) say that the ransomware attack was also their most serious identity incident, further highlighting that compromised identities have become a key attack method.
  • In 56 percent of ransomware attacks, attackers managed to encrypt an organization’s data. Of these incidents, 16 percent involved both data encryption and data theft. This is up from 50 percent in 2025, but is still below the peak of 75 percent seen in 2023.
  • When data was encrypted, 48 percent of organizations chose to pay the ransom, bringing the average payment rate over the past four years to around 50 percent.
  • Only 34 percent of organizations with 100 to 250 employees were able to stop the attack before encryption or extortion was carried out, compared to 46 percent of organizations with 3,001 to 5,000 employees.
  • In 97 percent of ransomware attacks that began with compromised login credentials, some form of multi-factor authentication (MFA) was enabled. According to Sophos This shows that MFA is still an important security measure, but that it is not enough on its own if it is not properly implemented and covers all access points.
  • The UK had the highest median ransom demand value in the survey, at $2.5 million.

Faster recovery despite increased costs

The report also shows that organizations have become better at recovering from a ransomware attack. Improved backups and more efficient recovery procedures mean that 55 percent were able to recover within a week, while 16 percent managed to do so in less than 24 hours.

Meanwhile, many organizations continue to negotiate with the attackers. Of those who chose to pay the ransom, 51 percent were able to negotiate the ransom down to an amount below the attackers’ original demands. The median ransom demand has also decreased by 65 percent over the past two years. The percentage of organizations paying ransoms has fallen to 48 percent, the second lowest level since Sophos began tracking the trend.

Despite this, overall recovery costs continue to rise, with the average cost of recovering from a ransomware attack now standing at $1.7 million per incident.

Sophos recommends

To reduce the risk of ransomware, Sophos recommends that organizations:

  • Treat identity as a central part of security efforts by implementing advanced identity threat monitoring, using phishing-resistant multi-factor authentication, and regularly reviewing both human and machine identities,
  • Strengthen backup and recovery by testing backups regularly, storing them offline or in immutable formats, and integrating them into the organization's incident management plan.,
  • systematically working on exposure management through continuous patching, prioritizing internet-exposed systems, and using AI-supported tools to identify and remediate vulnerabilities faster,
  • Reduces firewall exposure by ensuring timely security updates, limiting internet-exposed management interfaces, and connecting firewalls to XDR and MDR platforms for faster detection and response to attacks.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT